CVE
Info.com
  • Browse CVEs
  • Trends
  • Email Alerts
  • About

📊 CVE Trends & Statistics

Discover trending vulnerabilities and security insights

Last 7 Days Last 30 Days Last 90 Days Last Year
17,030
Total CVEs
1,637
Critical
6,050
High
6,534
Medium
745
Low
6.9
Avg CVSS Score

Severity Distribution

1,637
Critical
10%
Click to view
6,050
High
36%
Click to view
6,534
Medium
38%
Click to view
745
Low
4%
Click to view

Weekly CVE Trends

Feb 01
Feb 08
Feb 15
Feb 22
Mar 01
Mar 08
Mar 15
Mar 22
Mar 29
Apr 05
Apr 12
Apr 19
Apr 26

Top Affected Vendors

Linux
Click to view all CVEs
612
Npm
Click to view all CVEs
385
🔥 55
Go
Click to view all CVEs
334
🔥 41
Google
Click to view all CVEs
288
🔥 22
OpenClaw
Click to view all CVEs
277
🔥 25
Pip
Click to view all CVEs
242
🔥 36
Microsoft
Click to view all CVEs
203
🔥 9
Composer
Click to view all CVEs
203
🔥 16
Adobe
Click to view all CVEs
184
🔥 7
Apple
Click to view all CVEs
180
🔥 4

Top Affected Products

Linux
Linux
Click to view all CVEs
612
OpenClaw
OpenClaw
Click to view all CVEs
274
🔥 24
chrome
Google
Click to view all CVEs
203
🔥 10
Firefox
Mozilla
Click to view all CVEs
108
🔥 67
android
Google
Click to view all CVEs
83
🔥 11
windows_10_1607
Microsoft
Click to view all CVEs
82
🔥 1
discourse
Discourse
Click to view all CVEs
81
macOS
Apple
Click to view all CVEs
80
🔥 1
openemr
Openemr
Click to view all CVEs
73
🔥 6
chamilo-lms
Chamilo
Click to view all CVEs
69
🔥 12

🔥 Recently Published CVEs

CVE-2026-22754 HIGH - 7.5

Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a path matcher, then...

Vendor: Spring Product: Spring Security Published: Apr 22, 2026
CVE-2026-22753 HIGH - 7.5

Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMatcher.Builder bean to prepend a servlet path, matching requests to that filte...

Vendor: Spring Product: Spring Security Published: Apr 22, 2026
CVE-2026-22748 MEDIUM - 5.3

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately,...

Vendor: Spring Product: Spring Security Published: Apr 22, 2026
CVE-2026-22747 MEDIUM - 6.8

Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the us...

Vendor: Spring Product: Spring Security Published: Apr 22, 2026
CVE-2026-22746 LOW - 3.7

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then�...

Vendor: Spring Product: Spring Security Published: Apr 22, 2026
CVE-2026-40451 MEDIUM - 6.1

DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which allows an attacker to execute arbitrary script in a user's browser, and inject mali...

Vendor: DeepL Product: Chrome browser extension Published: Apr 22, 2026
CVE-2026-6835 MEDIUM - 6.1

The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload arbitrary files to any path, including HTML documents, which may result i...

Published: Apr 22, 2026
CVE-2026-6834 MEDIUM - 6.5

The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method....

Published: Apr 22, 2026
CVE-2026-6833 MEDIUM - 6.5

The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents....

Published: Apr 22, 2026
CVE-2026-6416 LOW - 2.7

Tanium addressed an uncontrolled resource consumption vulnerability in Interact....

Published: Apr 22, 2026

💬 Most Discussed CVEs

CVE-2026-24422
MEDIUM 💬 1 comment

phpMyFAQ is an open source FAQ web application. In versions 4.0.16 and below, multiple public API endpoints improperly expose sensitive user information due to insufficient access controls. The OpenQu...

CVE-2026-1302
MEDIUM 💬 1 comment

The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and out...

CVE-2026-1680
💬 1 comment

Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via...

Browse CVEs Trends Email Alerts About

© 2026 CVEInfo.com - Aggregating CVE Information from Multiple Sources

Data sources: NVD, MITRE, GitHub Security Advisories