| CVE | 설명 | 제출 | 모더레이션 | 항목 |
|---|
| CVE-2026-6911 | Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT to ... | 2026. 04. 24. | | |
| CVE-2026-40609 | This CVE is a duplicate of another CVE. | 2026. 04. 24. | 2026. 04. 24. | |
| CVE-2026-39920 | BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administ ... | 2026. 04. 24. | | |
| CVE-2026-30368 | A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated at ... | 2026. 04. 24. | | |
| CVE-2026-31672 | In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00usb: fix devres lif ... | 2026. 04. 24. | | |
| CVE-2026-31671 | In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in bui ... | 2026. 04. 24. | | |
| CVE-2026-31670 | In the Linux kernel, the following vulnerability has been resolved: net: rfkill: prevent unlimited ... | 2026. 04. 24. | | |
| CVE-2026-31669 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free ... | 2026. 04. 24. | | |
| CVE-2026-31668 | In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for in ... | 2026. 04. 24. | | |
| CVE-2026-31667 | In the Linux kernel, the following vulnerability has been resolved: Input: uinput - fix circular lo ... | 2026. 04. 24. | | |
| CVE-2026-31666 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix incorrect return val ... | 2026. 04. 24. | | |
| CVE-2026-31665 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix use-afte ... | 2026. 04. 24. | | |
| CVE-2026-31664 | In the Linux kernel, the following vulnerability has been resolved: xfrm: clear trailing padding in ... | 2026. 04. 24. | | |
| CVE-2026-31663 | In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after ... | 2026. 04. 24. | | |
| CVE-2026-31662 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix bc_ackers underflow o ... | 2026. 04. 24. | | |
| CVE-2026-31661 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmsmac: Fix dma_free_co ... | 2026. 04. 24. | | |
| CVE-2026-31660 | In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: allocate rx skb bef ... | 2026. 04. 24. | | |
| CVE-2026-31659 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized gl ... | 2026. 04. 24. | | |
| CVE-2026-31658 | In the Linux kernel, the following vulnerability has been resolved: net: altera-tse: fix skb leak o ... | 2026. 04. 24. | | |
| CVE-2026-31657 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone ... | 2026. 04. 24. | 2026. 04. 24. | 359413 |
| CVE-2026-31656 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: fix refcount under ... | 2026. 04. 24. | 2026. 04. 24. | 359412 |
| CVE-2026-31655 | In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8mp-blk-ctrl: Keep ... | 2026. 04. 24. | | |
| CVE-2026-31654 | In the Linux kernel, the following vulnerability has been resolved: mm/vma: fix memory leak in __mm ... | 2026. 04. 24. | 2026. 04. 24. | 359399 |
| CVE-2026-31653 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: dealloc repeat_ ... | 2026. 04. 24. | 2026. 04. 24. | 359414 |
| CVE-2026-31652 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/stat: deallocate damon ... | 2026. 04. 24. | 2026. 04. 24. | 359411 |
| CVE-2026-31651 | In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix NULL-deref on ... | 2026. 04. 24. | 2026. 04. 24. | 359410 |
| CVE-2026-31650 | In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix use-after-free ... | 2026. 04. 24. | | |
| CVE-2026-31649 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underf ... | 2026. 04. 24. | | |
| CVE-2026-31648 | In the Linux kernel, the following vulnerability has been resolved: mm: filemap: fix nr_pages calcu ... | 2026. 04. 24. | | |
| CVE-2026-31647 | In the Linux kernel, the following vulnerability has been resolved: idpf: fix PREEMPT_RT raw/bh spi ... | 2026. 04. 24. | | |
| CVE-2026-31646 | In the Linux kernel, the following vulnerability has been resolved: net: lan966x: fix page_pool err ... | 2026. 04. 24. | | |
| CVE-2026-31645 | In the Linux kernel, the following vulnerability has been resolved: net: lan966x: fix page pool lea ... | 2026. 04. 24. | | |
| CVE-2026-31644 | In the Linux kernel, the following vulnerability has been resolved: net: lan966x: fix use-after-fre ... | 2026. 04. 24. | | |
| CVE-2026-31643 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix key parsing memleak ... | 2026. 04. 24. | | |
| CVE-2026-31642 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix call removal to use ... | 2026. 04. 24. | 2026. 04. 24. | 359416 |
| CVE-2026-31641 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading t ... | 2026. 04. 24. | 2026. 04. 24. | 359418 |
| CVE-2026-31640 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix use of wrong skb whe ... | 2026. 04. 24. | | |
| CVE-2026-31639 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix key reference count ... | 2026. 04. 24. | | |
| CVE-2026-31638 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Only put the call ref if ... | 2026. 04. 24. | | |
| CVE-2026-31637 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: reject undecryptable rxk ... | 2026. 04. 24. | 2026. 04. 24. | 359409 |
| CVE-2026-31636 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticat ... | 2026. 04. 24. | 2026. 04. 24. | 359408 |
| CVE-2026-31635 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE a ... | 2026. 04. 24. | 2026. 04. 24. | 359407 |
| CVE-2026-31634 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix reference count leak ... | 2026. 04. 24. | | |
| CVE-2026-31633 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in ... | 2026. 04. 24. | 2026. 04. 24. | 359406 |
| CVE-2026-31632 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix leak of rxgk context ... | 2026. 04. 24. | | |
| CVE-2026-31631 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in r ... | 2026. 04. 24. | 2026. 04. 24. | 359446 |
| CVE-2026-31630 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: proc: size address buffe ... | 2026. 04. 24. | | |
| CVE-2026-31629 | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return a ... | 2026. 04. 24. | 2026. 04. 24. | 359405 |
| CVE-2026-31628 | In the Linux kernel, the following vulnerability has been resolved: x86/CPU: Fix FPDSS on Zen1 Zen ... | 2026. 04. 24. | 2026. 04. 24. | 359404 |
| CVE-2026-31627 | In the Linux kernel, the following vulnerability has been resolved: i2c: s3c24xx: check the size of ... | 2026. 04. 24. | 2026. 04. 24. | 359403 |
| CVE-2026-31626 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: initialize ... | 2026. 04. 24. | 2026. 04. 24. | 359444 |
| CVE-2026-31625 | In the Linux kernel, the following vulnerability has been resolved: HID: alps: fix NULL pointer der ... | 2026. 04. 24. | 2026. 04. 24. | 359359 |
| CVE-2026-31624 | In the Linux kernel, the following vulnerability has been resolved: HID: core: clamp report_size in ... | 2026. 04. 24. | 2026. 04. 24. | 359401 |
| CVE-2026-31623 | In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc-phonet: fix skb f ... | 2026. 04. 24. | 2026. 04. 24. | 359400 |
| CVE-2026-31622 | In the Linux kernel, the following vulnerability has been resolved: NFC: digital: Bounds check NFC- ... | 2026. 04. 24. | 2026. 04. 24. | 359369 |
| CVE-2026-31621 | In the Linux kernel, the following vulnerability has been resolved: bnge: return after auxiliary_de ... | 2026. 04. 24. | 2026. 04. 24. | 359447 |
| CVE-2026-31620 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: us144mkii: fix NUL ... | 2026. 04. 24. | 2026. 04. 24. | 359445 |
| CVE-2026-31619 | In the Linux kernel, the following vulnerability has been resolved: ALSA: fireworks: bound device-s ... | 2026. 04. 24. | 2026. 04. 24. | 359442 |
| CVE-2026-31618 | In the Linux kernel, the following vulnerability has been resolved: fbdev: tdfxfb: avoid divide-by- ... | 2026. 04. 24. | 2026. 04. 24. | 359402 |
| CVE-2026-31617 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate mi ... | 2026. 04. 24. | 2026. 04. 24. | 359368 |
| CVE-2026-31616 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_phonet: fix skb ... | 2026. 04. 24. | 2026. 04. 24. | 359396 |
| CVE-2026-31615 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: renesas_usb3: vali ... | 2026. 04. 24. | 2026. 04. 24. | 359395 |
| CVE-2026-31614 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix off-by-8 bound ... | 2026. 04. 24. | 2026. 04. 24. | 359443 |
| CVE-2026-31613 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB reads pars ... | 2026. 04. 24. | 2026. 04. 24. | 359439 |
| CVE-2026-31612 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate EaNameLength in ... | 2026. 04. 24. | 2026. 04. 24. | 359440 |
| CVE-2026-31611 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authoritie ... | 2026. 04. 24. | 2026. 04. 24. | 359441 |
| CVE-2026-31610 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix mechToken leak when ... | 2026. 04. 24. | 2026. 04. 24. | 359448 |
| CVE-2026-31609 | In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free ... | 2026. 04. 24. | 2026. 04. 24. | 359438 |
| CVE-2026-31608 | In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free ... | 2026. 04. 24. | 2026. 04. 24. | 359437 |
| CVE-2026-31607 | In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packe ... | 2026. 04. 24. | 2026. 04. 24. | 359367 |
| CVE-2026-31606 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: don't call ... | 2026. 04. 24. | 2026. 04. 24. | 359436 |
| CVE-2026-31605 | In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: avoid divide-by-z ... | 2026. 04. 24. | 2026. 04. 24. | 359398 |
| CVE-2026-31604 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: fix device leak on ... | 2026. 04. 24. | 2026. 04. 24. | 359393 |
| CVE-2026-31603 | In the Linux kernel, the following vulnerability has been resolved: staging: sm750fb: fix division ... | 2026. 04. 24. | 2026. 04. 24. | 359435 |
| CVE-2026-31602 | In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Limit PTP to a sin ... | 2026. 04. 24. | 2026. 04. 24. | 359366 |
| CVE-2026-31601 | In the Linux kernel, the following vulnerability has been resolved: vfio/xe: Reorganize the init to ... | 2026. 04. 24. | 2026. 04. 24. | 359392 |
| CVE-2026-31600 | In the Linux kernel, the following vulnerability has been resolved: arm64: mm: Handle invalid large ... | 2026. 04. 24. | 2026. 04. 24. | 359391 |
| CVE-2026-31599 | In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix NULL pointer ... | 2026. 04. 24. | 2026. 04. 24. | 359434 |
| CVE-2026-31598 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix possible deadlock be ... | 2026. 04. 24. | 2026. 04. 24. | 359394 |
| CVE-2026-31597 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix use-after-free in oc ... | 2026. 04. 24. | 2026. 04. 24. | 359433 |
| CVE-2026-31596 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: handle invalid dinode in ... | 2026. 04. 24. | 2026. 04. 24. | 359397 |
| CVE-2026-31595 | In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-epf-vntb: St ... | 2026. 04. 24. | 2026. 04. 24. | 359390 |
| CVE-2026-31594 | In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-epf-vntb: Re ... | 2026. 04. 24. | 2026. 04. 24. | 359389 |
| CVE-2026-31593 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Reject attempts to sy ... | 2026. 04. 24. | 2026. 04. 24. | 359388 |
| CVE-2026-31592 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Protect *all* of sev_ ... | 2026. 04. 24. | 2026. 04. 24. | 359365 |
| CVE-2026-31591 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Lock all vCPUs when s ... | 2026. 04. 24. | 2026. 04. 24. | 359432 |
| CVE-2026-31590 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Drop WARN on large si ... | 2026. 04. 24. | 2026. 04. 24. | 359431 |
| CVE-2026-31589 | In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directl ... | 2026. 04. 24. | 2026. 04. 24. | 359430 |
| CVE-2026-31588 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Use scratch field in ... | 2026. 04. 24. | | |
| CVE-2026-31587 | In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6apm: move compone ... | 2026. 04. 24. | 2026. 04. 24. | 359429 |
| CVE-2026-31586 | In the Linux kernel, the following vulnerability has been resolved: mm: blk-cgroup: fix use-after-f ... | 2026. 04. 24. | 2026. 04. 24. | 359386 |
| CVE-2026-31585 | In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix nfeeds state ... | 2026. 04. 24. | 2026. 04. 24. | 359385 |
| CVE-2026-31584 | In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: fix us ... | 2026. 04. 24. | 2026. 04. 24. | 359364 |
| CVE-2026-31583 | In the Linux kernel, the following vulnerability has been resolved: media: em28xx: fix use-after-fr ... | 2026. 04. 24. | 2026. 04. 24. | 359428 |
| CVE-2026-31582 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (powerz) Fix use-after-f ... | 2026. 04. 24. | 2026. 04. 24. | 359383 |
| CVE-2026-31581 | In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: fix use-after-free ... | 2026. 04. 24. | 2026. 04. 24. | 359361 |
| CVE-2026-31580 | In the Linux kernel, the following vulnerability has been resolved: bcache: fix cached_dev.sb_bio u ... | 2026. 04. 24. | 2026. 04. 24. | 359427 |
| CVE-2026-31579 | In the Linux kernel, the following vulnerability has been resolved: wireguard: device: use exit_rtn ... | 2026. 04. 24. | 2026. 04. 24. | 359363 |
| CVE-2026-31578 | In the Linux kernel, the following vulnerability has been resolved: media: as102: fix to not free m ... | 2026. 04. 24. | 2026. 04. 24. | 359384 |
| CVE-2026-31577 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix NULL i_assoc_inode ... | 2026. 04. 24. | 2026. 04. 24. | 359382 |
| CVE-2026-31576 | In the Linux kernel, the following vulnerability has been resolved: media: hackrf: fix to not free ... | 2026. 04. 24. | 2026. 04. 24. | 359426 |
| CVE-2026-31575 | In the Linux kernel, the following vulnerability has been resolved: mm/userfaultfd: fix hugetlb fau ... | 2026. 04. 24. | 2026. 04. 24. | 359425 |
| CVE-2026-31574 | In the Linux kernel, the following vulnerability has been resolved: clockevents: Add missing resets ... | 2026. 04. 24. | 2026. 04. 24. | 359381 |
| CVE-2026-31573 | In the Linux kernel, the following vulnerability has been resolved: media: verisilicon: Fix kernel ... | 2026. 04. 24. | 2026. 04. 24. | 359360 |
| CVE-2026-31572 | In the Linux kernel, the following vulnerability has been resolved: i2c: designware: amdisp: Fix re ... | 2026. 04. 24. | 2026. 04. 24. | 359387 |
| CVE-2026-31571 | In the Linux kernel, the following vulnerability has been resolved: drm/i915: Unlink NV12 planes ea ... | 2026. 04. 24. | 2026. 04. 24. | 359380 |
| CVE-2026-31570 | In the Linux kernel, the following vulnerability has been resolved: can: gw: fix OOB heap access in ... | 2026. 04. 24. | 2026. 04. 24. | 359424 |
| CVE-2026-31569 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Handle the case ... | 2026. 04. 24. | 2026. 04. 24. | 359423 |
| CVE-2026-31568 | In the Linux kernel, the following vulnerability has been resolved: s390/mm: Add missing secure sto ... | 2026. 04. 24. | 2026. 04. 24. | 359422 |
| CVE-2026-31567 | In the Linux kernel, the following vulnerability has been resolved: PM: sleep: Drop spurious WARN_O ... | 2026. 04. 24. | 2026. 04. 24. | 359379 |
| CVE-2026-31566 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix fence put befor ... | 2026. 04. 24. | 2026. 04. 24. | 359378 |
| CVE-2026-31565 | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix deadlock during ... | 2026. 04. 24. | 2026. 04. 24. | 359421 |
| CVE-2026-31564 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix base addres ... | 2026. 04. 24. | 2026. 04. 24. | 359420 |
| CVE-2026-31563 | In the Linux kernel, the following vulnerability has been resolved: net: macb: Use dev_consume_skb_ ... | 2026. 04. 24. | | |
| CVE-2026-31562 | In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: dsi: Store driver ... | 2026. 04. 24. | 2026. 04. 24. | 359376 |
| CVE-2026-31561 | In the Linux kernel, the following vulnerability has been resolved: x86/cpu: Remove X86_CR4_FRED fr ... | 2026. 04. 24. | 2026. 04. 24. | 359374 |
| CVE-2026-31560 | In the Linux kernel, the following vulnerability has been resolved: spi: spi-dw-dma: fix print erro ... | 2026. 04. 24. | 2026. 04. 24. | 359419 |
| CVE-2026-31559 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix missing NULL che ... | 2026. 04. 24. | 2026. 04. 24. | 359373 |
| CVE-2026-31558 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vc ... | 2026. 04. 24. | 2026. 04. 24. | 359415 |
| CVE-2026-31557 | In the Linux kernel, the following vulnerability has been resolved: nvmet: move async event work of ... | 2026. 04. 24. | 2026. 04. 24. | 359375 |
| CVE-2026-31556 | In the Linux kernel, the following vulnerability has been resolved: xfs: scrub: unlock dquot before ... | 2026. 04. 24. | 2026. 04. 24. | 359372 |
| CVE-2026-31555 | In the Linux kernel, the following vulnerability has been resolved: futex: Clear stale exiting poin ... | 2026. 04. 24. | | |
| CVE-2026-31554 | In the Linux kernel, the following vulnerability has been resolved: futex: Require sys_futex_requeu ... | 2026. 04. 24. | 2026. 04. 24. | 359377 |
| CVE-2026-31553 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor ... | 2026. 04. 24. | 2026. 04. 24. | 359417 |
| CVE-2026-31552 | In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: Return -ENOMEM in ... | 2026. 04. 24. | 2026. 04. 24. | 359371 |
| CVE-2026-31551 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Fix static_bran ... | 2026. 04. 24. | 2026. 04. 24. | 359362 |
| CVE-2026-31550 | In the Linux kernel, the following vulnerability has been resolved: pmdomain: bcm: bcm2835-power: I ... | 2026. 04. 24. | 2026. 04. 24. | 359370 |
| CVE-2026-31549 | In the Linux kernel, the following vulnerability has been resolved: i2c: cp2615: fix serial string ... | 2026. 04. 24. | 2026. 04. 24. | 359358 |
| CVE-2026-31548 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel pmsr_fre ... | 2026. 04. 24. | 2026. 04. 24. | 359354 |
| CVE-2026-31547 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix missing runtime PM ... | 2026. 04. 24. | 2026. 04. 24. | 359353 |
| CVE-2026-31546 | In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL deref in ... | 2026. 04. 24. | 2026. 04. 24. | 359352 |
| CVE-2026-31545 | In the Linux kernel, the following vulnerability has been resolved: NFC: nxp-nci: allow GPIOs to sl ... | 2026. 04. 24. | 2026. 04. 24. | 359351 |
| CVE-2026-31544 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix NULL de ... | 2026. 04. 24. | 2026. 04. 24. | 359350 |
| CVE-2026-31543 | In the Linux kernel, the following vulnerability has been resolved: crash_dump: don't log dm-crypt ... | 2026. 04. 24. | 2026. 04. 24. | 359357 |
| CVE-2026-31542 | In the Linux kernel, the following vulnerability has been resolved: x86/platform/uv: Handle deconfi ... | 2026. 04. 24. | 2026. 04. 24. | 359356 |
| CVE-2026-31541 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix trace_marker copy ... | 2026. 04. 24. | 2026. 04. 24. | 359355 |
| CVE-2026-31540 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Check set_default_ ... | 2026. 04. 24. | 2026. 04. 24. | 359349 |
| CVE-2026-31539 | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: introduce smbdi ... | 2026. 04. 24. | 2026. 04. 24. | 359343 |
| CVE-2026-31538 | In the Linux kernel, the following vulnerability has been resolved: smb: server: make use of smbdir ... | 2026. 04. 24. | 2026. 04. 24. | 359342 |
| CVE-2026-31537 | In the Linux kernel, the following vulnerability has been resolved: smb: server: make use of smbdir ... | 2026. 04. 24. | 2026. 04. 24. | 359339 |
| CVE-2026-31536 | In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done hand ... | 2026. 04. 24. | 2026. 04. 24. | 359341 |
| CVE-2026-31535 | In the Linux kernel, the following vulnerability has been resolved: smb: client: make use of smbdir ... | 2026. 04. 24. | 2026. 04. 24. | 359340 |
| CVE-2026-31534 | In the Linux kernel, the following vulnerability has been resolved: smb: client: let send_done hand ... | 2026. 04. 24. | 2026. 04. 24. | 359338 |
| CVE-2026-31052 | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of servi ... | 2026. 04. 24. | 2026. 04. 24. | 359345 |
| CVE-2026-31051 | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of servi ... | 2026. 04. 24. | 2026. 04. 24. | 359344 |
| CVE-2026-31050 | Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker ... | 2026. 04. 24. | 2026. 04. 24. | 359348 |
| CVE-2026-42095 | bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by ... | 2026. 04. 24. | 2026. 04. 24. | 359346 |
| CVE-2026-25660 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyz ... | 2026. 04. 24. | 2026. 04. 24. | 359337 |
| CVE-2026-5367 | A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynami ... | 2026. 04. 24. | 2026. 04. 24. | 358489 |
| CVE-2026-5265 | When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a por ... | 2026. 04. 24. | 2026. 04. 24. | 358488 |
| CVE-2026-40690 | The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with ... | 2026. 04. 24. | 2026. 04. 24. | 359336 |
| CVE-2026-38743 | The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the ... | 2026. 04. 24. | 2026. 04. 24. | 359335 |
| CVE-2026-21515 | Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized ... | 2026. 04. 24. | 2026. 04. 24. | 359319 |
| CVE-2026-6043 | P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed ... | 2026. 04. 24. | 2026. 04. 24. | 359333 |
| CVE-2026-4313 | AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacke ... | 2026. 04. 24. | 2026. 04. 24. | 359334 |
| CVE-2026-23902 | Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with sys ... | 2026. 04. 24. | 2026. 04. 24. | 359321 |
| CVE-2026-41044 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i ... | 2026. 04. 24. | 2026. 04. 24. | 359176 |
| CVE-2026-41043 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach ... | 2026. 04. 24. | 2026. 04. 24. | 359175 |
| CVE-2026-40466 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i ... | 2026. 04. 24. | 2026. 04. 24. | 359174 |
| CVE-2026-6272 | A client holding only a read JWT scope can still register itself as a signal provider through the pr ... | 2026. 04. 24. | 2026. 04. 24. | 359332 |
| CVE-2026-21728 | Tempo queries with large limits can cause large memory allocations which can impact the availability ... | 2026. 04. 24. | 2026. 04. 24. | 359331 |
| CVE-2026-4078 | The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes ... | 2026. 04. 24. | 2026. 04. 24. | 359328 |
| CVE-2026-3569 | The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions u ... | 2026. 04. 24. | 2026. 04. 24. | 359329 |
| CVE-2026-3565 | The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a ... | 2026. 04. 24. | 2026. 04. 24. | 359330 |
| CVE-2026-1952 | Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability. | 2026. 04. 24. | 2026. 04. 24. | 359325 |
| CVE-2026-1951 | Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulne ... | 2026. 04. 24. | 2026. 04. 24. | 359324 |
| CVE-2026-1950 | Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerabili ... | 2026. 04. 24. | 2026. 04. 24. | 359323 |
| CVE-2026-6810 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Refer ... | 2026. 04. 24. | 2026. 04. 24. | 359312 |
| CVE-2026-5428 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ima ... | 2026. 04. 24. | 2026. 04. 24. | 359314 |
| CVE-2026-5364 | The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary fil ... | 2026. 04. 24. | 2026. 04. 24. | 359307 |
| CVE-2026-5347 | The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to a ... | 2026. 04. 24. | 2026. 04. 24. | 359310 |
| CVE-2026-1949 | Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT re ... | 2026. 04. 24. | 2026. 04. 24. | 359313 |
| CVE-2026-6947 | DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, al ... | 2026. 04. 24. | 2026. 04. 24. | 359268 |
| CVE-2026-41317 | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace ... | 2026. 04. 24. | 2026. 04. 24. | 359274 |
| CVE-2026-41316 | ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) int ... | 2026. 04. 24. | 2026. 04. 24. | 359267 |
| CVE-2026-6393 | The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and inc ... | 2026. 04. 24. | 2026. 04. 24. | 359259 |
| CVE-2026-5488 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to ... | 2026. 04. 24. | 2026. 04. 24. | 359257 |
| CVE-2026-41485 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1 ... | 2026. 04. 24. | 2026. 04. 24. | 359260 |
| CVE-2026-41430 | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace ... | 2026. 04. 24. | 2026. 04. 24. | 359266 |
| CVE-2026-41324 | basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service ... | 2026. 04. 24. | 2026. 04. 24. | 359261 |
| CVE-2026-41323 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1 ... | 2026. 04. 24. | 2026. 04. 24. | 359264 |
| CVE-2026-41319 | MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injecti ... | 2026. 04. 24. | 2026. 04. 24. | 359263 |
| CVE-2026-41318 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as refe ... | 2026. 04. 24. | 2026. 04. 24. | 359265 |
| CVE-2026-41068 | Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2 ... | 2026. 04. 24. | 2026. 04. 24. | 359262 |
| CVE-2026-2028 | The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to in ... | 2026. 04. 24. | 2026. 04. 24. | 359258 |
| CVE-2026-41309 | Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versio ... | 2026. 04. 24. | 2026. 04. 24. | 359248 |
| CVE-2026-41305 | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul ... | 2026. 04. 24. | 2026. 04. 24. | 359256 |
| CVE-2026-40254 | FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an of ... | 2026. 04. 24. | 2026. 04. 24. | 359253 |
| CVE-2026-33318 | Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (incl ... | 2026. 04. 24. | 2026. 04. 24. | 359255 |
| CVE-2026-33317 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel r ... | 2026. 04. 24. | 2026. 04. 24. | 359249 |
| CVE-2026-33208 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to vers ... | 2026. 04. 24. | 2026. 04. 24. | 359250 |
| CVE-2026-33078 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prio ... | 2026. 04. 24. | 2026. 04. 24. | 359247 |
| CVE-2026-33077 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to vers ... | 2026. 04. 24. | 2026. 04. 24. | 359252 |
| CVE-2026-33076 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to vers ... | 2026. 04. 24. | 2026. 04. 24. | 359251 |
| CVE-2026-32952 | go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0 ... | 2026. 04. 24. | 2026. 04. 24. | 359254 |
| CVE-2026-41325 | Kirby is an open-source content management system. Kirby's user permissions control which user role ... | 2026. 04. 24. | 2026. 04. 24. | 359273 |
| CVE-2026-40099 | Kirby is an open-source content management system. Kirby's user permissions control which user role ... | 2026. 04. 24. | 2026. 04. 24. | 359272 |
| CVE-2026-34587 | Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user p ... | 2026. 04. 24. | 2026. 04. 24. | 359271 |
| CVE-2026-32870 | Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handlin ... | 2026. 04. 24. | 2026. 04. 24. | 359270 |
| CVE-2026-31956 | Xibo is an open source digital signage platform with a web content management system and Windows dis ... | 2026. 04. 24. | 2026. 04. 24. | 359269 |
| CVE-2026-31955 | Xibo is an open source digital signage platform with a web content management system and Windows dis ... | 2026. 04. 24. | 2026. 04. 24. | 359276 |
| CVE-2026-31953 | Xibo is an open source digital signage platform with a web content management system and Windows dis ... | 2026. 04. 24. | 2026. 04. 24. | 359275 |
| CVE-2026-40630 | A vulnerability in SenseLive X3050’s web management interface allows unauthorized access to ce ... | 2026. 04. 24. | 2026. 04. 24. | 359283 |
| CVE-2026-40623 | A vulnerability in SenseLive X3050's web management interface allows critical system and network c ... | 2026. 04. 24. | 2026. 04. 24. | 359277 |
| CVE-2026-40620 | A vulnerability in SenseLive X3050’s embedded management service allows full administrative cont ... | 2026. 04. 24. | 2026. 04. 24. | 359280 |
| CVE-2026-29197 | In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the end ... | 2026. 04. 24. | 2026. 04. 24. | 359286 |
| CVE-2026-25720 | A vulnerability exists in SenseLive X3050’s web management interface due to improper session lif ... | 2026. 04. 24. | 2026. 04. 24. | 359282 |
| CVE-2026-1789 | A vulnerability in the browser-based remote management interface may allow an administrator to acces ... | 2026. 04. 24. | 2026. 04. 24. | 359281 |
| CVE-2026-40431 | A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unen ... | 2026. 04. 24. | 2026. 04. 24. | 359238 |
| CVE-2026-39462 | A vulnerability exists in SenseLive X3050’s web management interface in which password updates ar ... | 2026. 04. 24. | 2026. 04. 24. | 359243 |
| CVE-2026-35503 | A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be p ... | 2026. 04. 24. | 2026. 04. 24. | 359246 |
| CVE-2026-35064 | A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of de ... | 2026. 04. 24. | 2026. 04. 24. | 359242 |
| CVE-2026-31952 | Xibo is an open source digital signage platform with a web content management system and Windows dis ... | 2026. 04. 24. | 2026. 04. 24. | 359244 |
| CVE-2026-29051 | melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 a ... | 2026. 04. 24. | 2026. 04. 24. | 359240 |
| CVE-2026-29050 | melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 a ... | 2026. 04. 24. | 2026. 04. 24. | 359237 |
| CVE-2026-27843 | A vulnerability exists in SenseLive X3050's web management interface that allows critical configura ... | 2026. 04. 24. | 2026. 04. 24. | 359245 |
| CVE-2026-27841 | A vulnerability in SenseLive X3050's web management interface allows state-changing operations to ... | 2026. 04. 24. | 2026. 04. 24. | 359241 |
| CVE-2026-25775 | A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and upd ... | 2026. 04. 24. | 2026. 04. 24. | 359239 |
| CVE-2026-6732 | A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafte ... | 2026. 04. 24. | 2026. 04. 24. | 359284 |
| CVE-2026-41361 | OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 ... | 2026. 04. 24. | 2026. 04. 24. | 359317 |
| CVE-2026-41360 | OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind ... | 2026. 04. 24. | 2026. 04. 24. | 359318 |
| CVE-2026-41359 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated opera ... | 2026. 04. 24. | 2026. 04. 24. | 359311 |
| CVE-2026-41358 | OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allo ... | 2026. 04. 24. | 2026. 04. 24. | 359316 |
| CVE-2026-41357 | OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbo ... | 2026. 04. 24. | 2026. 04. 24. | 359308 |
| CVE-2026-41356 | OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. ... | 2026. 04. 24. | 2026. 04. 24. | 359315 |
| CVE-2026-41355 | OpenShell before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that co ... | 2026. 04. 24. | 2026. 04. 24. | 359309 |
| CVE-2026-41354 | OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe ... | 2026. 04. 24. | 2026. 04. 24. | 359304 |
| CVE-2026-41353 | OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles featu ... | 2026. 04. 24. | 2026. 04. 24. | 359297 |
| CVE-2026-41352 | OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node ... | 2026. 04. 24. | 2026. 04. 24. | 359293 |
| CVE-2026-41351 | OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature hand ... | 2026. 04. 24. | 2026. 04. 24. | 359303 |
| CVE-2026-41350 | OpenClaw before 2026.3.31 contains a session visibility bypass vulnerability where the session_statu ... | 2026. 04. 24. | 2026. 04. 24. | 359299 |
| CVE-2026-41349 | OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to si ... | 2026. 04. 24. | 2026. 04. 24. | 359292 |
| CVE-2026-41348 | OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command an ... | 2026. 04. 24. | 2026. 04. 24. | 359291 |
| CVE-2026-41347 | OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating ... | 2026. 04. 24. | 2026. 04. 24. | 359301 |
| CVE-2026-41346 | OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead o ... | 2026. 04. 24. | 2026. 04. 24. | 359287 |
| CVE-2026-41345 | OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionali ... | 2026. 04. 24. | 2026. 04. 24. | 359296 |
| CVE-2026-41344 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint th ... | 2026. 04. 24. | 2026. 04. 24. | 359300 |
| CVE-2026-41343 | OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path ... | 2026. 04. 24. | 2026. 04. 24. | 359290 |
| CVE-2026-41342 | OpenClaw before 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding c ... | 2026. 04. 24. | 2026. 04. 24. | 359289 |
| CVE-2026-41341 | OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that miscl ... | 2026. 04. 24. | 2026. 04. 24. | 359288 |
| CVE-2026-41340 | OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy al ... | 2026. 04. 24. | 2026. 04. 24. | 359302 |
| CVE-2026-41339 | OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapsho ... | 2026. 04. 24. | 2026. 04. 24. | 359306 |
| CVE-2026-41338 | OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operati ... | 2026. 04. 24. | 2026. 04. 24. | 359295 |
| CVE-2026-41337 | OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call repl ... | 2026. 04. 24. | 2026. 04. 24. | 359305 |
| CVE-2026-41336 | OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_HOOKS_DIR env ... | 2026. 04. 24. | 2026. 04. 24. | 359298 |
| CVE-2026-41335 | OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface ... | 2026. 04. 24. | 2026. 04. 24. | 359294 |
| CVE-2026-41334 | OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails ... | 2026. 04. 24. | 2026. 04. 24. | 359279 |
| CVE-2026-41333 | OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows ... | 2026. 04. 24. | 2026. 04. 24. | 359278 |
| CVE-2026-41332 | OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMP ... | 2026. 04. 24. | 2026. 04. 24. | 359285 |
| CVE-2026-41274 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 24. | 2026. 04. 24. | 359235 |
| CVE-2026-26210 | KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve ba ... | 2026. 04. 24. | 2026. 04. 24. | 359234 |
| CVE-2026-35431 | Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthoriz ... | 2026. 04. 24. | 2026. 04. 24. | 359231 |
| CVE-2026-33819 | Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code ... | 2026. 04. 24. | 2026. 04. 24. | 359230 |
| CVE-2026-33102 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker ... | 2026. 04. 24. | 2026. 04. 24. | 359236 |
| CVE-2026-32210 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacke ... | 2026. 04. 24. | 2026. 04. 24. | 359233 |
| CVE-2026-32172 | Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute ... | 2026. 04. 24. | 2026. 04. 24. | 359228 |
| CVE-2026-2708 | A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_ ... | 2026. 04. 24. | 2026. 04. 24. | 347007 |
| CVE-2026-26150 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate p ... | 2026. 04. 24. | 2026. 04. 24. | 359232 |
| CVE-2026-24303 | Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privile ... | 2026. 04. 24. | 2026. 04. 24. | 359229 |
| CVE-2026-6942 | radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows rem ... | 2026. 04. 23. | 2026. 04. 23. | 359227 |
| CVE-2026-28525 | SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_mult ... | 2026. 04. 23. | 2026. 04. 23. | 359226 |
| CVE-2026-6941 | radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that al ... | 2026. 04. 23. | 2026. 04. 23. | 359218 |
| CVE-2026-6940 | radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local ... | 2026. 04. 23. | 2026. 04. 23. | 359225 |
| CVE-2026-6376 | A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to b ... | 2026. 04. 23. | 2026. 04. 23. | 359221 |
| CVE-2026-6375 | A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name rec ... | 2026. 04. 23. | 2026. 04. 23. | 359224 |
| CVE-2026-41275 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359217 |
| CVE-2026-41279 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359223 |
| CVE-2026-41278 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359222 |
| CVE-2026-41277 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359220 |
| CVE-2026-41276 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359216 |
| CVE-2026-41265 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359215 |
| CVE-2026-41264 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359214 |
| CVE-2026-25874 | LeRobot contains an unsafe deserialization vulnerability in the async inference pipeline where pickl ... | 2026. 04. 23. | 2026. 04. 23. | 359219 |
| CVE-2026-41273 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359210 |
| CVE-2026-41272 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359213 |
| CVE-2026-41271 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359212 |
| CVE-2026-41270 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359211 |
| CVE-2026-41269 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359209 |
| CVE-2026-41268 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359205 |
| CVE-2026-41267 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359208 |
| CVE-2026-41266 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359207 |
| CVE-2026-41138 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359204 |
| CVE-2026-41137 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 23. | 2026. 04. 23. | 359206 |
| CVE-2026-6074 | A path traversal condition in Intrado 911 Emergency Gateway could allow an attacker with existing ne ... | 2026. 04. 23. | 2026. 04. 23. | 359203 |
| CVE-2026-41241 | pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backen ... | 2026. 04. 23. | 2026. 04. 23. | 359202 |
| CVE-2026-41213 | @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchan ... | 2026. 04. 23. | 2026. 04. 23. | 359199 |
| CVE-2026-41173 | The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from A ... | 2026. 04. 23. | 2026. 04. 23. | 359200 |
| CVE-2026-41078 | OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Expor ... | 2026. 04. 23. | 2026. 04. 23. | 359201 |
| CVE-2026-41259 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16 ... | 2026. 04. 23. | 2026. 04. 23. | 359198 |
| CVE-2026-41247 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1 ... | 2026. 04. 23. | 2026. 04. 23. | 359197 |
| CVE-2026-41246 | Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32. ... | 2026. 04. 23. | 2026. 04. 23. | 359196 |
| CVE-2026-41205 | Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vuln ... | 2026. 04. 23. | 2026. 04. 23. | 359195 |
| CVE-2026-40894 | OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 an ... | 2026. 04. 23. | 2026. 04. 23. | 359187 |
| CVE-2026-40886 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on ... | 2026. 04. 23. | 2026. 04. 23. | 359186 |
| CVE-2026-33694 | This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files ... | 2026. 04. 23. | 2026. 04. 23. | 359185 |
| CVE-2026-31173 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359193 |
| CVE-2026-31169 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359192 |
| CVE-2026-31168 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359194 |
| CVE-2026-31167 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359191 |
| CVE-2026-31166 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359190 |
| CVE-2026-31163 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359189 |
| CVE-2026-31162 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359188 |
| CVE-2026-41909 | OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing ... | 2026. 04. 23. | 2026. 04. 23. | 359178 |
| CVE-2026-41908 | OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media r ... | 2026. 04. 23. | 2026. 04. 23. | 359177 |
| CVE-2026-40891 | OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting t ... | 2026. 04. 23. | 2026. 04. 23. | 359180 |
| CVE-2026-40182 | OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting t ... | 2026. 04. 23. | 2026. 04. 23. | 359179 |
| CVE-2026-31175 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359184 |
| CVE-2026-31174 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359183 |
| CVE-2026-31172 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359182 |
| CVE-2026-31171 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359181 |
| CVE-2026-6921 | Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potenti ... | 2026. 04. 23. | 2026. 04. 23. | 359169 |
| CVE-2026-31165 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359171 |
| CVE-2026-31164 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359172 |
| CVE-2026-31160 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359170 |
| CVE-2026-6920 | Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attac ... | 2026. 04. 23. | 2026. 04. 23. | 359159 |
| CVE-2026-6919 | Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who ha ... | 2026. 04. 23. | 2026. 04. 23. | 359166 |
| CVE-2026-5039 | TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key ... | 2026. 04. 23. | 2026. 04. 23. | 359163 |
| CVE-2026-31533 | In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in ... | 2026. 04. 23. | 2026. 04. 23. | 359162 |
| CVE-2026-31179 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359165 |
| CVE-2026-31181 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359164 |
| CVE-2026-31178 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359168 |
| CVE-2026-31177 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359161 |
| CVE-2026-31176 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359167 |
| CVE-2026-31159 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to ex ... | 2026. 04. 23. | 2026. 04. 23. | 359160 |
| CVE-2026-41240 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to ... | 2026. 04. 23. | 2026. 04. 23. | 359153 |
| CVE-2026-41239 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in versio ... | 2026. 04. 23. | 2026. 04. 23. | 359156 |
| CVE-2026-41238 | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions 3.0.1 thr ... | 2026. 04. 23. | 2026. 04. 23. | 359062 |
| CVE-2026-40472 | In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes ... | 2026. 04. 23. | 2026. 04. 23. | 359158 |
| CVE-2026-40471 | hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on ... | 2026. 04. 23. | 2026. 04. 23. | 359155 |
| CVE-2026-40470 | A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript f ... | 2026. 04. 23. | 2026. 04. 23. | 359152 |
| CVE-2026-39087 | An issue in Ntfy ntfy.sh before v.2.21 allows a remote attacker to execute arbitrary code via the pa ... | 2026. 04. 23. | 2026. 04. 23. | 359154 |
| CVE-2026-34003 | A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could se ... | 2026. 04. 23. | 2026. 04. 23. | 359151 |
| CVE-2026-34001 | A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence ... | 2026. 04. 23. | 2026. 04. 23. | 359149 |
| CVE-2026-33999 | A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XK ... | 2026. 04. 23. | 2026. 04. 23. | 359150 |
| CVE-2026-23751 | Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) ... | 2026. 04. 23. | 2026. 04. 23. | 359148 |
| CVE-2026-41461 | SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in t ... | 2026. 04. 23. | 2026. 04. 23. | 359145 |
| CVE-2026-41460 | SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/g ... | 2026. 04. 23. | 2026. 04. 23. | 359143 |
| CVE-2026-35225 | An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS E ... | 2026. 04. 23. | 2026. 04. 23. | 359144 |
| CVE-2026-39440 | Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFor ... | 2026. 04. 23. | 2026. 04. 23. | 359141 |
| CVE-2026-31532 | In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-afte ... | 2026. 04. 23. | 2026. 04. 23. | 359131 |
| CVE-2026-31531 | In the Linux kernel, the following vulnerability has been resolved: ipv4: nexthop: allocate skb dyn ... | 2026. 04. 23. | 2026. 04. 23. | 359129 |
| CVE-2026-28040 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i ... | 2026. 04. 23. | 2026. 04. 23. | 359138 |
| CVE-2026-6903 | The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in ... | 2026. 04. 23. | 2026. 04. 23. | 359130 |
| CVE-2026-6887 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vu ... | 2026. 04. 23. | 2026. 04. 23. | 359136 |
| CVE-2026-6886 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication B ... | 2026. 04. 23. | 2026. 04. 23. | 359135 |
| CVE-2026-6885 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File U ... | 2026. 04. 23. | 2026. 04. 23. | 359134 |
| CVE-2026-5464 | The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for Word ... | 2026. 04. 23. | 2026. 04. 23. | 359132 |
| CVE-2026-3960 | A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/I ... | 2026. 04. 23. | 2026. 04. 23. | 359128 |
| CVE-2026-3259 | A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized Vie ... | 2026. 04. 23. | 2026. 04. 23. | 359133 |
| CVE-2026-41564 | CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking. The Cry ... | 2026. 04. 23. | 2026. 04. 23. | 359125 |
| CVE-2026-41040 | GROWI provided by GROWI, Inc. is vulnerable to a regular expression denial of service (ReDoS) via a ... | 2026. 04. 23. | 2026. 04. 23. | 359127 |
| CVE-2026-4512 | The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key se ... | 2026. 04. 23. | 2026. 04. 23. | 359122 |
| CVE-2026-4106 | The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX act ... | 2026. 04. 23. | 2026. 04. 23. | 359121 |
| CVE-2026-34488 | IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading ... | 2026. 04. 23. | 2026. 04. 23. | 359123 |
| CVE-2026-41990 | Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check b ... | 2026. 04. 23. | 2026. 04. 23. | 359120 |
| CVE-2026-41989 | Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via craf ... | 2026. 04. 23. | 2026. 04. 23. | 359119 |
| CVE-2026-41988 | uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID ve ... | 2026. 04. 23. | 2026. 04. 23. | 359111 |
| CVE-2026-41233 | Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, t ... | 2026. 04. 23. | 2026. 04. 23. | 359109 |
| CVE-2026-41232 | Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add( ... | 2026. 04. 23. | 2026. 04. 23. | 359115 |
| CVE-2026-40529 | CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in ... | 2026. 04. 23. | 2026. 04. 23. | 359114 |
| CVE-2026-41231 | Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` cons ... | 2026. 04. 23. | 2026. 04. 23. | 359098 |
| CVE-2026-41230 | Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` ... | 2026. 04. 23. | 2026. 04. 23. | 359104 |
| CVE-2026-41229 | Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArra ... | 2026. 04. 23. | 2026. 04. 23. | 359066 |
| CVE-2026-41228 | Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpo ... | 2026. 04. 23. | 2026. 04. 23. | 359065 |
| CVE-2026-3361 | The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl ... | 2026. 04. 23. | 2026. 04. 23. | 359110 |
| CVE-2026-3007 | Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attack ... | 2026. 04. 23. | 2026. 04. 23. | 359118 |
| CVE-2026-3844 | The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty ... | 2026. 04. 23. | 2026. 04. 23. | 359090 |
| CVE-2026-2951 | The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vuln ... | 2026. 04. 23. | 2026. 04. 23. | 359095 |
| CVE-2026-41679 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. ... | 2026. 04. 23. | 2026. 04. 23. | 359106 |
| CVE-2026-41243 | OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0 ... | 2026. 04. 23. | 2026. 04. 23. | 359105 |
| CVE-2026-41211 | Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `download ... | 2026. 04. 23. | 2026. 04. 23. | 359107 |
| CVE-2026-41208 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. ... | 2026. 04. 23. | 2026. 04. 23. | 359093 |
| CVE-2026-41206 | PySpector is a static analysis security testing (SAST) Framework engineered for modern Python develo ... | 2026. 04. 23. | 2026. 04. 23. | 359089 |
| CVE-2026-41200 | STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) ... | 2026. 04. 23. | 2026. 04. 23. | 359097 |
| CVE-2026-41197 | Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compat ... | 2026. 04. 23. | 2026. 04. 23. | 359092 |
| CVE-2026-41196 | Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 ... | 2026. 04. 23. | 2026. 04. 23. | 359094 |
| CVE-2026-41182 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0. ... | 2026. 04. 23. | 2026. 04. 23. | 359072 |
| CVE-2026-41180 | PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload ... | 2026. 04. 23. | 2026. 04. 23. | 359091 |
| CVE-2026-1923 | The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site ... | 2026. 04. 23. | 2026. 04. 23. | 359096 |
| CVE-2026-6874 | A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function ... | 2026. 04. 23. | 2026. 04. 23. | 359039 |
| CVE-2026-5935 | IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow ... | 2026. 04. 23. | 2026. 04. 23. | 359101 |
| CVE-2026-5926 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10 ... | 2026. 04. 23. | 2026. 04. 23. | 359100 |
| CVE-2026-4919 | IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows a ... | 2026. 04. 23. | 2026. 04. 23. | 359103 |
| CVE-2026-4918 | IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability a ... | 2026. 04. 23. | 2026. 04. 23. | 359102 |
| CVE-2026-4917 | IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the ... | 2026. 04. 23. | 2026. 04. 23. | 359099 |
| CVE-2026-3621 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Serve ... | 2026. 04. 23. | 2026. 04. 23. | 359064 |
| CVE-2026-29198 | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injec ... | 2026. 04. 23. | 2026. 04. 23. | 359117 |
| CVE-2026-1726 | IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 | 2026. 04. 23. | 2026. 04. 23. | 359086 |
| CVE-2026-1352 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 C ... | 2026. 04. 23. | 2026. 04. 23. | 359063 |
| CVE-2026-1274 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerabi ... | 2026. 04. 23. | 2026. 04. 23. | 359085 |
| CVE-2026-1272 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnera ... | 2026. 04. 23. | 2026. 04. 23. | 359083 |
| CVE-2026-6878 | A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of ... | 2026. 04. 23. | 2026. 04. 23. | 359040 |
| CVE-2026-41179 | Rclone is a command-line program to sync files and directories to and from different cloud storage p ... | 2026. 04. 23. | 2026. 04. 23. | 359082 |
| CVE-2026-41176 | Rclone is a command-line program to sync files and directories to and from different cloud storage p ... | 2026. 04. 23. | 2026. 04. 23. | 359084 |
| CVE-2026-40062 | A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated ... | 2026. 04. 23. | 2026. 04. 23. | 359088 |
| CVE-2026-32679 | The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerF ... | 2026. 04. 23. | 2026. 04. 23. | 359087 |
| CVE-2026-4049 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 2026. 04. 23. | 2026. 04. 23. | |
| CVE-2026-41177 | Squidex is an open source headless content management system and content management hub. Prior to ve ... | 2026. 04. 23. | 2026. 04. 23. | 359116 |
| CVE-2026-41175 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and ... | 2026. 04. 23. | 2026. 04. 23. | 359113 |
| CVE-2026-41172 | Squidex is an open source headless content management system and content management hub. Prior to ve ... | 2026. 04. 23. | 2026. 04. 23. | 359112 |
| CVE-2026-40517 | radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() ... | 2026. 04. 23. | 2026. 04. 23. | 359108 |
| CVE-2026-41168 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability presen ... | 2026. 04. 22. | 2026. 04. 23. | 359070 |
| CVE-2026-41167 | Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple A ... | 2026. 04. 22. | 2026. 04. 23. | 359081 |
| CVE-2026-41455 | WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL h ... | 2026. 04. 22. | 2026. 04. 23. | 359076 |
| CVE-2026-41454 | WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoi ... | 2026. 04. 22. | 2026. 04. 23. | 359074 |
| CVE-2026-41314 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability presen ... | 2026. 04. 22. | 2026. 04. 23. | 359069 |
| CVE-2026-41313 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability presen ... | 2026. 04. 22. | 2026. 04. 23. | 359068 |
| CVE-2026-41312 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability presen ... | 2026. 04. 22. | 2026. 04. 23. | 359067 |
| CVE-2026-41171 | Squidex is an open source headless content management system and content management hub. Versions pr ... | 2026. 04. 22. | 2026. 04. 23. | 359077 |
| CVE-2026-41170 | Squidex is an open source headless content management system and content management hub. Prior to ve ... | 2026. 04. 22. | 2026. 04. 23. | 359075 |
| CVE-2026-41166 | OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `w ... | 2026. 04. 22. | 2026. 04. 23. | 359080 |
| CVE-2026-41134 | Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.31.1 are affected by a cod ... | 2026. 04. 22. | 2026. 04. 23. | 359073 |
| CVE-2026-40937 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notif ... | 2026. 04. 22. | 2026. 04. 23. | 359078 |
| CVE-2026-40882 | OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset ... | 2026. 04. 22. | 2026. 04. 23. | 359079 |
| CVE-2026-3837 | An authenticated attacker can persist crafted values in multiple field types and trigger client-side ... | 2026. 04. 22. | 2026. 04. 22. | 359061 |
| CVE-2026-34068 | nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prio ... | 2026. 04. 22. | 2026. 04. 22. | 359058 |
| CVE-2026-34067 | nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prio ... | 2026. 04. 22. | 2026. 04. 22. | 359057 |
| CVE-2026-33733 | EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the ... | 2026. 04. 22. | 2026. 04. 22. | 359056 |
| CVE-2026-33656 | EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, Espo ... | 2026. 04. 22. | 2026. 04. 22. | 359055 |
| CVE-2026-6019 | http.cookies.Morsel.js_output() returns an inline snippet and only escapes " for JavaScript string ... | 2026. 04. 22. | 2026. 04. 22. | 359054 |
| CVE-2026-3673 | An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript executi ... | 2026. 04. 22. | 2026. 04. 22. | 359060 |
| CVE-2026-34066 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version ... | 2026. 04. 22. | 2026. 04. 22. | 359050 |
| CVE-2026-34065 | nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust ... | 2026. 04. 22. | 2026. 04. 22. | 359053 |
| CVE-2026-34064 | nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to versio ... | 2026. 04. 22. | 2026. 04. 22. | 359052 |
| CVE-2026-34063 | Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `n ... | 2026. 04. 22. | 2026. 04. 22. | 359047 |
| CVE-2026-34062 | nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCode ... | 2026. 04. 22. | 2026. 04. 22. | 359051 |
| CVE-2026-41459 | Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that ... | 2026. 04. 22. | 2026. 04. 22. | 359046 |
| CVE-2026-34415 | Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability ... | 2026. 04. 22. | 2026. 04. 22. | 359049 |
| CVE-2026-34414 | Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in t ... | 2026. 04. 22. | 2026. 04. 22. | 359048 |
| CVE-2026-34413 | Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in th ... | 2026. 04. 22. | 2026. 04. 22. | 359045 |
| CVE-2026-33471 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the A ... | 2026. 04. 22. | 2026. 04. 22. | 359059 |
| CVE-2026-41469 | Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loadin ... | 2026. 04. 22. | 2026. 04. 22. | 359041 |
| CVE-2026-41468 | Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbo ... | 2026. 04. 22. | 2026. 04. 22. | 359042 |
| CVE-2026-28950 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.8 and iP ... | 2026. 04. 22. | 2026. 04. 22. | 359044 |
| CVE-2026-26354 | Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1 ... | 2026. 04. 22. | 2026. 04. 22. | 359043 |
| CVE-2026-32885 | DDEV is an open-source tool for running local web development environments for PHP and Node.js. Vers ... | 2026. 04. 22. | 2026. 04. 22. | 359038 |
| CVE-2026-4922 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 ... | 2026. 04. 22. | 2026. 04. 22. | 359034 |
| CVE-2026-3254 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that ... | 2026. 04. 22. | 2026. 04. 22. | 359027 |
| CVE-2026-6515 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 ... | 2026. 04. 22. | 2026. 04. 22. | 359026 |
| CVE-2026-5816 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and ... | 2026. 04. 22. | 2026. 04. 22. | 359025 |
| CVE-2026-5377 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that ... | 2026. 04. 22. | 2026. 04. 22. | 359024 |
| CVE-2026-5262 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18. ... | 2026. 04. 22. | 2026. 04. 22. | 359023 |
| CVE-2026-35382 | Voluntarily withdrawn | 2026. 04. 22. | 2026. 04. 22. | |
| CVE-2026-35381 | A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delim ... | 2026. 04. 22. | 2026. 04. 22. | 358988 |
| CVE-2026-35380 | A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the ... | 2026. 04. 22. | 2026. 04. 22. | 359016 |
| CVE-2026-35379 | A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:g ... | 2026. 04. 22. | 2026. 04. 22. | 358992 |
| CVE-2026-35378 | A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized s ... | 2026. 04. 22. | 2026. 04. 22. | 358987 |
| CVE-2026-35377 | A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-lin ... | 2026. 04. 22. | 2026. 04. 22. | 358997 |
| CVE-2026-35376 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the chcon utility of uutils coreutil ... | 2026. 04. 22. | 2026. 04. 22. | 359031 |
| CVE-2026-35375 | A logic error in the split utility of uutils coreutils causes the corruption of output filenames whe ... | 2026. 04. 22. | 2026. 04. 22. | 358991 |
| CVE-2026-35374 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the split utility of uutils coreutil ... | 2026. 04. 22. | 2026. 04. 22. | 359037 |
| CVE-2026-35373 | A logic error in the ln utility of uutils coreutils causes the program to reject source paths contai ... | 2026. 04. 22. | 2026. 04. 22. | 358995 |
| CVE-2026-35372 | A logic error in the ln utility of uutils coreutils allows the utility to dereference a symbolic lin ... | 2026. 04. 22. | 2026. 04. 22. | 359030 |
| CVE-2026-35371 | The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the ... | 2026. 04. 22. | 2026. 04. 22. | 359022 |
| CVE-2026-35370 | The id utility in uutils coreutils miscalculates the groups= section of its output. The implementati ... | 2026. 04. 22. | 2026. 04. 22. | 358986 |
| CVE-2026-35369 | An argument parsing error in the kill utility of uutils coreutils incorrectly interprets kill -1 as ... | 2026. 04. 22. | 2026. 04. 22. | 358984 |
| CVE-2026-35368 | A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. T ... | 2026. 04. 22. | 2026. 04. 22. | 359015 |
| CVE-2026-35367 | The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying ... | 2026. 04. 22. | 2026. 04. 22. | 358990 |
| CVE-2026-35366 | The printenv utility in uutils coreutils fails to display environment variables containing invalid U ... | 2026. 04. 22. | 2026. 04. 22. | 359014 |
| CVE-2026-35365 | The mv utility in uutils coreutils improperly handles directory trees containing symbolic links duri ... | 2026. 04. 22. | 2026. 04. 22. | 359012 |
| CVE-2026-35364 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mv utility of uutils coreutils ... | 2026. 04. 22. | 2026. 04. 22. | 359029 |
| CVE-2026-35363 | A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms inte ... | 2026. 04. 22. | 2026. 04. 22. | 359017 |
| CVE-2026-35362 | The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Ti ... | 2026. 04. 22. | 2026. 04. 22. | 358985 |
| CVE-2026-35361 | The mknod utility in uutils coreutils fails to handle security labels atomically by creating device ... | 2026. 04. 22. | 2026. 04. 22. | 359013 |
| CVE-2026-35360 | The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race ... | 2026. 04. 22. | 2026. 04. 22. | 359018 |
| CVE-2026-35359 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows a ... | 2026. 04. 22. | 2026. 04. 22. | 359011 |
| CVE-2026-35358 | The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats charac ... | 2026. 04. 22. | 2026. 04. 22. | 359010 |
| CVE-2026-35357 | The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destin ... | 2026. 04. 22. | 2026. 04. 22. | 359035 |
| CVE-2026-35356 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreut ... | 2026. 04. 22. | 2026. 04. 22. | 359009 |
| CVE-2026-35355 | The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) rac ... | 2026. 04. 22. | 2026. 04. 22. | 359033 |
| CVE-2026-35354 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv utility of uutils coreutils d ... | 2026. 04. 22. | 2026. 04. 22. | 359028 |
| CVE-2026-35353 | The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by crea ... | 2026. 04. 22. | 2026. 04. 22. | 359019 |
| CVE-2026-35352 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreut ... | 2026. 04. 22. | 2026. 04. 22. | 359032 |
| CVE-2026-35351 | The mv utility in uutils coreutils fails to preserve file ownership during moves across different fi ... | 2026. 04. 22. | 2026. 04. 22. | 358998 |
| CVE-2026-35350 | The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership pr ... | 2026. 04. 22. | 2026. 04. 22. | 358994 |
| CVE-2026-35349 | A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protect ... | 2026. 04. 22. | 2026. 04. 22. | 359007 |
| CVE-2026-35348 | The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from o ... | 2026. 04. 22. | 2026. 04. 22. | 358996 |
| CVE-2026-35347 | The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before p ... | 2026. 04. 22. | 2026. 04. 22. | 359008 |
| CVE-2026-35346 | The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on ... | 2026. 04. 22. | 2026. 04. 22. | 358989 |
| CVE-2026-35345 | A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive fil ... | 2026. 04. 22. | 2026. 04. 22. | 358993 |
| CVE-2026-35344 | The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditio ... | 2026. 04. 22. | 2026. 04. 22. | 358983 |
| CVE-2026-35343 | The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newlin ... | 2026. 04. 22. | 2026. 04. 22. | 359006 |
| CVE-2026-35342 | The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable ... | 2026. 04. 22. | 2026. 04. 22. | 358982 |
| CVE-2026-35341 | A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions o ... | 2026. 04. 22. | 2026. 04. 22. | 359005 |
| CVE-2026-35340 | A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return ... | 2026. 04. 22. | 2026. 04. 22. | 359004 |
| CVE-2026-35339 | The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when ... | 2026. 04. 22. | 2026. 04. 22. | 359003 |
| CVE-2026-35338 | A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root ... | 2026. 04. 22. | 2026. 04. 22. | 359002 |
| CVE-2026-1660 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 ... | 2026. 04. 22. | 2026. 04. 22. | 359021 |
| CVE-2026-30139 | A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpe ... | 2026. 04. 22. | 2026. 04. 22. | 358981 |
| CVE-2026-35548 | An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 ... | 2026. 04. 22. | 2026. 04. 22. | 358953 |
| CVE-2026-6862 | A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fai ... | 2026. 04. 22. | 2026. 04. 22. | 358961 |
| CVE-2026-6861 | A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs proc ... | 2026. 04. 22. | 2026. 04. 22. | 358952 |
| CVE-2026-33611 | An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS ... | 2026. 04. 22. | 2026. 04. 22. | 358958 |
| CVE-2026-33610 | A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when ... | 2026. 04. 22. | 2026. 04. 22. | 358966 |
| CVE-2026-33609 | Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queri ... | 2026. 04. 22. | 2026. 04. 22. | 358967 |
| CVE-2026-33608 | An attacker can send a notify request that causes a new secondary domain to be added to the bind bac ... | 2026. 04. 22. | 2026. 04. 22. | 358957 |
| CVE-2026-33602 | A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum co ... | 2026. 04. 22. | 2026. 04. 22. | 358964 |
| CVE-2026-33599 | A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, whe ... | 2026. 04. 22. | 2026. 04. 22. | 358956 |
| CVE-2026-33598 | A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAd ... | 2026. 04. 22. | 2026. 04. 22. | 358965 |
| CVE-2026-33597 | PRSD detection denial of service | 2026. 04. 22. | 2026. 04. 22. | 358963 |
| CVE-2026-33596 | A client might theoretically be able to cause a mismatch between queries sent to a backend and the r ... | 2026. 04. 22. | 2026. 04. 22. | 358960 |
| CVE-2026-33595 | A client can trigger excessive memory allocation by generating a lot of errors responses over a sing ... | 2026. 04. 22. | 2026. 04. 22. | 358955 |
| CVE-2026-33594 | A client can trigger excessive memory allocation by generating a lot of queries that are routed to a ... | 2026. 04. 22. | 2026. 04. 22. | 358959 |
| CVE-2026-33593 | A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query. | 2026. 04. 22. | 2026. 04. 22. | 358962 |
| CVE-2026-33254 | An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memor ... | 2026. 04. 22. | 2026. 04. 22. | 358954 |
| CVE-2026-31530 | In the Linux kernel, the following vulnerability has been resolved: cxl/port: Fix use after free of ... | 2026. 04. 22. | 2026. 04. 22. | 358861 |
| CVE-2026-31529 | In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix leakage in __co ... | 2026. 04. 22. | 2026. 04. 22. | 358903 |
| CVE-2026-31528 | In the Linux kernel, the following vulnerability has been resolved: perf: Make sure to use pmu_ctx- ... | 2026. 04. 22. | 2026. 04. 22. | 358944 |
| CVE-2026-31527 | In the Linux kernel, the following vulnerability has been resolved: driver core: platform: use gene ... | 2026. 04. 22. | 2026. 04. 22. | 358941 |
| CVE-2026-31526 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix exception exit lock ch ... | 2026. 04. 22. | 2026. 04. 22. | 358901 |
| CVE-2026-31525 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix undefined behavior in ... | 2026. 04. 22. | 2026. 04. 22. | 358873 |
| CVE-2026-31524 | In the Linux kernel, the following vulnerability has been resolved: HID: asus: avoid memory leak in ... | 2026. 04. 22. | 2026. 04. 22. | 358900 |
| CVE-2026-31523 | In the Linux kernel, the following vulnerability has been resolved: nvme-pci: ensure we're polling ... | 2026. 04. 22. | 2026. 04. 22. | 358945 |
| CVE-2026-31522 | In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: avoid memory l ... | 2026. 04. 22. | 2026. 04. 22. | 358899 |
| CVE-2026-31521 | In the Linux kernel, the following vulnerability has been resolved: module: Fix kernel panic when a ... | 2026. 04. 22. | 2026. 04. 22. | 358898 |
| CVE-2026-31520 | In the Linux kernel, the following vulnerability has been resolved: HID: apple: avoid memory leak i ... | 2026. 04. 22. | 2026. 04. 22. | 358859 |
| CVE-2026-31519 | In the Linux kernel, the following vulnerability has been resolved: btrfs: set BTRFS_ROOT_ORPHAN_CL ... | 2026. 04. 22. | 2026. 04. 22. | 358872 |
| CVE-2026-31518 | In the Linux kernel, the following vulnerability has been resolved: esp: fix skb leak with espintcp ... | 2026. 04. 22. | 2026. 04. 22. | 358948 |
| CVE-2026-31517 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix skb_put() pani ... | 2026. 04. 22. | 2026. 04. 22. | 358950 |
| CVE-2026-31516 | In the Linux kernel, the following vulnerability has been resolved: xfrm: prevent policy_hthresh.wo ... | 2026. 04. 22. | 2026. 04. 22. | 358939 |
| CVE-2026-31515 | In the Linux kernel, the following vulnerability has been resolved: af_key: validate families in pf ... | 2026. 04. 22. | 2026. 04. 22. | 358946 |
| CVE-2026-31514 | In the Linux kernel, the following vulnerability has been resolved: erofs: set fileio bio failed in ... | 2026. 04. 22. | 2026. 04. 22. | 358897 |
| CVE-2026-31513 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix stack-out ... | 2026. 04. 22. | 2026. 04. 22. | 358942 |
| CVE-2026-31512 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate PDU ... | 2026. 04. 22. | 2026. 04. 22. | 358937 |
| CVE-2026-31511 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix dangling p ... | 2026. 04. 22. | 2026. 04. 22. | 358932 |
| CVE-2026-31510 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr- ... | 2026. 04. 22. | 2026. 04. 22. | 358896 |
| CVE-2026-31509 | In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix circular locking ... | 2026. 04. 22. | 2026. 04. 22. | 358934 |
| CVE-2026-31508 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Avoid releasi ... | 2026. 04. 22. | 2026. 04. 22. | 358871 |
| CVE-2026-31507 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix double-free of smc ... | 2026. 04. 22. | 2026. 04. 22. | 358895 |
| CVE-2026-31506 | In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix double free of ... | 2026. 04. 22. | 2026. 04. 22. | 358930 |
| CVE-2026-31505 | In the Linux kernel, the following vulnerability has been resolved: iavf: fix out-of-bounds writes ... | 2026. 04. 22. | 2026. 04. 22. | 358864 |
| CVE-2026-31504 | In the Linux kernel, the following vulnerability has been resolved: net: fix fanout UAF in packet_r ... | 2026. 04. 22. | 2026. 04. 22. | 321044 |
| CVE-2026-31503 | In the Linux kernel, the following vulnerability has been resolved: udp: Fix wildcard bind conflict ... | 2026. 04. 22. | 2026. 04. 22. | 358947 |
| CVE-2026-31502 | In the Linux kernel, the following vulnerability has been resolved: team: fix header_ops type confu ... | 2026. 04. 22. | 2026. 04. 22. | 358870 |
| CVE-2026-31501 | In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use- ... | 2026. 04. 22. | 2026. 04. 22. | 358936 |
| CVE-2026-31500 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: serialize b ... | 2026. 04. 22. | 2026. 04. 22. | 358933 |
| CVE-2026-31499 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix deadlock ... | 2026. 04. 22. | 2026. 04. 22. | 358931 |
| CVE-2026-31498 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix ERTM re-i ... | 2026. 04. 22. | 2026. 04. 22. | 358869 |
| CVE-2026-31497 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: clamp SCO alt ... | 2026. 04. 22. | 2026. 04. 22. | 358935 |
| CVE-2026-31496 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: ... | 2026. 04. 22. | 2026. 04. 22. | 358894 |
| CVE-2026-31495 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use netli ... | 2026. 04. 22. | 2026. 04. 22. | 358929 |
| CVE-2026-31494 | In the Linux kernel, the following vulnerability has been resolved: net: macb: use the current queu ... | 2026. 04. 22. | 2026. 04. 22. | 358951 |
| CVE-2026-31493 | In the Linux kernel, the following vulnerability has been resolved: RDMA/efa: Fix use of completion ... | 2026. 04. 22. | 2026. 04. 22. | 358928 |
| CVE-2026-31492 | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Initialize free_qp ... | 2026. 04. 22. | 2026. 04. 22. | 358927 |
| CVE-2026-31491 | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Harden depth calcul ... | 2026. 04. 22. | 2026. 04. 22. | 358926 |
| CVE-2026-31490 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix use-after-free i ... | 2026. 04. 22. | 2026. 04. 22. | 358868 |
| CVE-2026-31489 | In the Linux kernel, the following vulnerability has been resolved: spi: meson-spicc: Fix double-pu ... | 2026. 04. 22. | 2026. 04. 22. | 358925 |
| CVE-2026-31488 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not skip un ... | 2026. 04. 22. | 2026. 04. 22. | 358866 |
| CVE-2026-31487 | In the Linux kernel, the following vulnerability has been resolved: spi: use generic driver_overrid ... | 2026. 04. 22. | 2026. 04. 22. | 358893 |
| CVE-2026-31486 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/core) Protect reg ... | 2026. 04. 22. | 2026. 04. 22. | 358892 |
| CVE-2026-31485 | In the Linux kernel, the following vulnerability has been resolved: spi: spi-fsl-lpspi: fix teardow ... | 2026. 04. 22. | 2026. 04. 22. | 358924 |
| CVE-2026-31484 | In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: fix OOB read i ... | 2026. 04. 22. | 2026. 04. 22. | 358922 |
| CVE-2026-31483 | In the Linux kernel, the following vulnerability has been resolved: s390/syscalls: Add spectre boun ... | 2026. 04. 22. | 2026. 04. 22. | 358923 |
| CVE-2026-31482 | In the Linux kernel, the following vulnerability has been resolved: s390/entry: Scrub r12 register ... | 2026. 04. 22. | 2026. 04. 22. | 358891 |
| CVE-2026-31481 | In the Linux kernel, the following vulnerability has been resolved: tracing: Drain deferred trigger ... | 2026. 04. 22. | 2026. 04. 22. | 358921 |
| CVE-2026-31480 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix potential deadlock ... | 2026. 04. 22. | 2026. 04. 22. | 358920 |
| CVE-2026-31479 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: always keep track of re ... | 2026. 04. 22. | 2026. 04. 22. | 358890 |
| CVE-2026-31478 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_l ... | 2026. 04. 22. | 2026. 04. 22. | 358889 |
| CVE-2026-31477 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix memory leaks and NUL ... | 2026. 04. 22. | 2026. 04. 22. | 358919 |
| CVE-2026-31476 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on ... | 2026. 04. 22. | 2026. 04. 22. | 358887 |
| CVE-2026-31475 | In the Linux kernel, the following vulnerability has been resolved: ASoC: sma1307: fix double free ... | 2026. 04. 22. | 2026. 04. 22. | 358882 |
| CVE-2026-31474 | In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix tx.buf use-afte ... | 2026. 04. 22. | 2026. 04. 22. | 358884 |
| CVE-2026-31473 | In the Linux kernel, the following vulnerability has been resolved: media: mc, v4l2: serialize REIN ... | 2026. 04. 22. | 2026. 04. 22. | 358918 |
| CVE-2026-31472 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: validate inner IPv ... | 2026. 04. 22. | 2026. 04. 22. | 358917 |
| CVE-2026-31471 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: only publish mode_ ... | 2026. 04. 22. | 2026. 04. 22. | 358916 |
| CVE-2026-31470 | In the Linux kernel, the following vulnerability has been resolved: virt: tdx-guest: Fix handling o ... | 2026. 04. 22. | 2026. 04. 22. | 358943 |
| CVE-2026-31469 | In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix UAF on dst_ops ... | 2026. 04. 22. | 2026. 04. 22. | 358867 |
| CVE-2026-31468 | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Fix double free in dm ... | 2026. 04. 22. | 2026. 04. 22. | 358915 |
| CVE-2026-31467 | In the Linux kernel, the following vulnerability has been resolved: erofs: add GFP_NOIO in the bio ... | 2026. 04. 22. | 2026. 04. 22. | 358885 |
| CVE-2026-31466 | In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix folio isn't ... | 2026. 04. 22. | 2026. 04. 22. | 358862 |
| CVE-2026-31465 | In the Linux kernel, the following vulnerability has been resolved: writeback: don't block sync for ... | 2026. 04. 22. | 2026. 04. 22. | 358883 |
| CVE-2026-31464 | In the Linux kernel, the following vulnerability has been resolved: scsi: ibmvfc: Fix OOB access in ... | 2026. 04. 22. | 2026. 04. 22. | 358860 |
| CVE-2026-31463 | In the Linux kernel, the following vulnerability has been resolved: iomap: fix invalid folio access ... | 2026. 04. 22. | 2026. 04. 22. | 358888 |
| CVE-2026-31462 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: prevent immediate P ... | 2026. 04. 22. | 2026. 04. 22. | 358886 |
| CVE-2026-31461 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix drm_edid l ... | 2026. 04. 22. | 2026. 04. 22. | 358879 |
| CVE-2026-31460 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: check if ext_c ... | 2026. 04. 22. | 2026. 04. 22. | 358880 |
| CVE-2026-31459 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: fix param_ctx l ... | 2026. 04. 22. | 2026. 04. 22. | 358881 |
| CVE-2026-31458 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: check contexts- ... | 2026. 04. 22. | 2026. 04. 22. | 358914 |
| CVE-2026-31457 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: check contexts- ... | 2026. 04. 22. | 2026. 04. 22. | 358913 |
| CVE-2026-31456 | In the Linux kernel, the following vulnerability has been resolved: mm/pagewalk: fix race between c ... | 2026. 04. 22. | 2026. 04. 22. | 358878 |
| CVE-2026-31455 | In the Linux kernel, the following vulnerability has been resolved: xfs: stop reclaim before pushin ... | 2026. 04. 22. | 2026. 04. 22. | 358912 |
| CVE-2026-31454 | In the Linux kernel, the following vulnerability has been resolved: xfs: save ailp before dropping ... | 2026. 04. 22. | 2026. 04. 22. | 358949 |
| CVE-2026-31453 | In the Linux kernel, the following vulnerability has been resolved: xfs: avoid dereferencing log it ... | 2026. 04. 22. | 2026. 04. 22. | 358911 |
| CVE-2026-31452 | In the Linux kernel, the following vulnerability has been resolved: ext4: convert inline data to ex ... | 2026. 04. 22. | 2026. 04. 22. | 358865 |
| CVE-2026-31451 | In the Linux kernel, the following vulnerability has been resolved: ext4: replace BUG_ON with prope ... | 2026. 04. 22. | 2026. 04. 22. | 358910 |
| CVE-2026-31450 | In the Linux kernel, the following vulnerability has been resolved: ext4: publish jinode after init ... | 2026. 04. 22. | 2026. 04. 22. | 358863 |
| CVE-2026-31449 | In the Linux kernel, the following vulnerability has been resolved: ext4: validate p_idx bounds in ... | 2026. 04. 22. | 2026. 04. 22. | 358909 |
| CVE-2026-31448 | In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caus ... | 2026. 04. 22. | 2026. 04. 22. | 358940 |
| CVE-2026-31447 | In the Linux kernel, the following vulnerability has been resolved: ext4: reject mount if bigalloc ... | 2026. 04. 22. | 2026. 04. 22. | 358908 |
| CVE-2026-31446 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in upd ... | 2026. 04. 22. | 2026. 04. 22. | 358877 |
| CVE-2026-31445 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: avoid use of hal ... | 2026. 04. 22. | 2026. 04. 22. | 358876 |
| CVE-2026-31444 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and N ... | 2026. 04. 22. | 2026. 04. 22. | 358907 |
| CVE-2026-31443 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix crash when ... | 2026. 04. 22. | 2026. 04. 22. | 358906 |
| CVE-2026-31442 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix possible i ... | 2026. 04. 22. | 2026. 04. 22. | 358905 |
| CVE-2026-31441 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix memory lea ... | 2026. 04. 22. | 2026. 04. 22. | 358875 |
| CVE-2026-31440 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix leaking ev ... | 2026. 04. 22. | 2026. 04. 22. | 358904 |
| CVE-2026-31439 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx: xdma: Fix re ... | 2026. 04. 22. | 2026. 04. 22. | 358902 |
| CVE-2026-31438 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix kernel BUG in netfs_ ... | 2026. 04. 22. | 2026. 04. 22. | 358874 |
| CVE-2026-31437 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix NULL pointer derefer ... | 2026. 04. 22. | 2026. 04. 22. | 358857 |
| CVE-2026-31436 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible w ... | 2026. 04. 22. | 2026. 04. 22. | 358858 |
| CVE-2026-31435 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment dur ... | 2026. 04. 22. | 2026. 04. 22. | 358855 |
| CVE-2026-31434 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix leak of kobject name ... | 2026. 04. 22. | 2026. 04. 22. | 358854 |
| CVE-2026-31192 | Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6. ... | 2026. 04. 22. | 2026. 04. 22. | 358856 |
| CVE-2026-6859 | A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when ... | 2026. 04. 22. | 2026. 04. 22. | 358847 |
| CVE-2026-6356 | A vulnerability in the web application allows standard users to escalate their privileges to those o ... | 2026. 04. 22. | 2026. 04. 22. | 358851 |
| CVE-2026-6355 | A vulnerability in the web application allows unauthorized users to access and manipulate sensitive ... | 2026. 04. 22. | 2026. 04. 22. | 358850 |
| CVE-2026-5750 | An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process all ... | 2026. 04. 22. | 2026. 04. 22. | 358849 |
| CVE-2026-5749 | Inadequate access control in the registration process in Fullstep V5, which could allow unauthentica ... | 2026. 04. 22. | 2026. 04. 22. | 358848 |
| CVE-2026-41651 | PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way us ... | 2026. 04. 22. | 2026. 04. 22. | 358852 |
| CVE-2026-0539 | Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local att ... | 2026. 04. 22. | 2026. 04. 22. | 358853 |
| CVE-2026-6857 | A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the Prot ... | 2026. 04. 22. | 2026. 04. 22. | 358845 |
| CVE-2026-6855 | A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in th ... | 2026. 04. 22. | 2026. 04. 22. | 358846 |
| CVE-2026-33601 | If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zo ... | 2026. 04. 22. | 2026. 04. 22. | 358837 |
| CVE-2026-33262 | An attacker can send replies that result in a null pointer dereference, caused by a missing consiste ... | 2026. 04. 22. | 2026. 04. 22. | 358844 |
| CVE-2026-33261 | A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of s ... | 2026. 04. 22. | 2026. 04. 22. | 358843 |
| CVE-2026-33260 | An attacker can send a web request that causes unlimited memory allocation in the internal web serve ... | 2026. 04. 22. | 2026. 04. 22. | 358840 |
| CVE-2026-33259 | Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free a ... | 2026. 04. 22. | 2026. 04. 22. | 358836 |
| CVE-2026-33258 | By publishing and querying a crafted zone an attacker can cause allocation of large entries in the n ... | 2026. 04. 22. | 2026. 04. 22. | 358842 |
| CVE-2026-33257 | An attacker can send a web request that causes unlimited memory allocation in the internal web serve ... | 2026. 04. 22. | 2026. 04. 22. | 358839 |
| CVE-2026-33256 | An attacker can send a web request that causes unlimited memory allocation in the internal web serve ... | 2026. 04. 22. | 2026. 04. 22. | 358838 |
| CVE-2026-6848 | A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive ... | 2026. 04. 22. | 2026. 04. 22. | 358833 |
| CVE-2026-33600 | An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by ... | 2026. 04. 22. | 2026. 04. 22. | 358841 |
| CVE-2026-1930 | The Emailchef plugin for WordPress is vulnerable to unauthorized modification of data due to a missi ... | 2026. 04. 22. | 2026. 04. 22. | 358831 |
| CVE-2026-1913 | The Gallagher Website Design plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t ... | 2026. 04. 22. | 2026. 04. 22. | 358835 |
| CVE-2026-1395 | The Gutentools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Slider ... | 2026. 04. 22. | 2026. 04. 22. | 358834 |
| CVE-2026-6845 | A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a ... | 2026. 04. 22. | 2026. 04. 22. | 358830 |
| CVE-2026-6396 | The Fast & Fancy Filter – 3F plugin for WordPress is vulnerable to Cross-Site Request Forgery in v ... | 2026. 04. 22. | 2026. 04. 22. | 358829 |
| CVE-2026-6294 | The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in vers ... | 2026. 04. 22. | 2026. 04. 22. | 358832 |
| CVE-2026-6246 | The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... | 2026. 04. 22. | 2026. 04. 22. | 358828 |
| CVE-2026-6236 | The Posts map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' short ... | 2026. 04. 22. | 2026. 04. 22. | 358827 |
| CVE-2026-6235 | The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'ma ... | 2026. 04. 22. | 2026. 04. 22. | 358826 |
| CVE-2026-6041 | The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom ... | 2026. 04. 22. | 2026. 04. 22. | 358816 |
| CVE-2026-5820 | The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table o ... | 2026. 04. 22. | 2026. 04. 22. | 358819 |
| CVE-2026-5767 | The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin ... | 2026. 04. 22. | 2026. 04. 22. | 358818 |
| CVE-2026-5748 | The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... | 2026. 04. 22. | 2026. 04. 22. | 358820 |
| CVE-2026-4353 | The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' ... | 2026. 04. 22. | 2026. 04. 22. | 358821 |
| CVE-2026-4280 | The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up t ... | 2026. 04. 22. | 2026. 04. 22. | 358825 |
| CVE-2026-4279 | The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadb ... | 2026. 04. 22. | 2026. 04. 22. | 358817 |
| CVE-2026-6846 | A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a speciall ... | 2026. 04. 22. | 2026. 04. 22. | 358823 |
| CVE-2026-6844 | A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit tw ... | 2026. 04. 22. | 2026. 04. 22. | 358822 |
| CVE-2026-6843 | A flaw was found in nano. A local user could exploit a format string vulnerability in the `statuslin ... | 2026. 04. 22. | 2026. 04. 22. | 358824 |
| CVE-2026-4142 | The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cr ... | 2026. 04. 22. | 2026. 04. 22. | 358812 |
| CVE-2026-4140 | The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in ... | 2026. 04. 22. | 2026. 04. 22. | 358809 |
| CVE-2026-4139 | The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t ... | 2026. 04. 22. | 2026. 04. 22. | 358814 |
| CVE-2026-4138 | The DX Unanswered Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v ... | 2026. 04. 22. | 2026. 04. 22. | 358808 |
| CVE-2026-4133 | The TextP2P Texting Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v ... | 2026. 04. 22. | 2026. 04. 22. | 358815 |
| CVE-2026-4132 | The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading ... | 2026. 04. 22. | 2026. 04. 22. | 358783 |
| CVE-2026-4131 | The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in ... | 2026. 04. 22. | 2026. 04. 22. | 358806 |
| CVE-2026-4128 | The TP Restore Categories And Taxonomies plugin for WordPress is vulnerable to Missing Authorization ... | 2026. 04. 22. | 2026. 04. 22. | 358804 |
| CVE-2026-4126 | The Table Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio ... | 2026. 04. 22. | 2026. 04. 22. | 358807 |
| CVE-2026-4125 | The WPMK Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' sho ... | 2026. 04. 22. | 2026. 04. 22. | 358813 |
| CVE-2026-4121 | The Kcaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to ... | 2026. 04. 22. | 2026. 04. 22. | 358790 |
| CVE-2026-4119 | The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up t ... | 2026. 04. 22. | 2026. 04. 22. | 358795 |
| CVE-2026-4118 | The Call To Action Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve ... | 2026. 04. 22. | 2026. 04. 22. | 358803 |
| CVE-2026-4117 | The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and incl ... | 2026. 04. 22. | 2026. 04. 22. | 358785 |
| CVE-2026-4090 | The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ... | 2026. 04. 22. | 2026. 04. 22. | 358805 |
| CVE-2026-4089 | The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id ... | 2026. 04. 22. | 2026. 04. 22. | 358811 |
| CVE-2026-4088 | The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_c ... | 2026. 04. 22. | 2026. 04. 22. | 358810 |
| CVE-2026-4085 | The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... | 2026. 04. 22. | 2026. 04. 22. | 358798 |
| CVE-2026-4082 | The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swif ... | 2026. 04. 22. | 2026. 04. 22. | 358800 |
| CVE-2026-4076 | The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... | 2026. 04. 22. | 2026. 04. 22. | 358801 |
| CVE-2026-4074 | The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t ... | 2026. 04. 22. | 2026. 04. 22. | 358789 |
| CVE-2026-3362 | The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ' ... | 2026. 04. 22. | 2026. 04. 22. | 358797 |
| CVE-2026-31433 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get ... | 2026. 04. 22. | 2026. 04. 22. | 358788 |
| CVE-2026-31432 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_I ... | 2026. 04. 22. | 2026. 04. 22. | 358787 |
| CVE-2026-31431 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to ... | 2026. 04. 22. | 2026. 04. 22. | 358784 |
| CVE-2026-2719 | The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exce ... | 2026. 04. 22. | 2026. 04. 22. | 358796 |
| CVE-2026-2717 | The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and inc ... | 2026. 04. 22. | 2026. 04. 22. | 358782 |
| CVE-2026-2714 | The Institute Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ' ... | 2026. 04. 22. | 2026. 04. 22. | 358799 |
| CVE-2026-1845 | The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin sett ... | 2026. 04. 22. | 2026. 04. 22. | 358793 |
| CVE-2026-1379 | The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting ... | 2026. 04. 22. | 2026. 04. 22. | 358802 |
| CVE-2026-6842 | A flaw was found in nano. In environments with permissive umask settings, a local attacker can explo ... | 2026. 04. 22. | 2026. 04. 22. | 358794 |
| CVE-2026-6023 | In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control i ... | 2026. 04. 22. | 2026. 04. 22. | 358791 |
| CVE-2026-6022 | In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled res ... | 2026. 04. 22. | 2026. 04. 22. | 358792 |
| CVE-2026-40542 | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the cli ... | 2026. 04. 22. | 2026. 04. 22. | 358786 |
| CVE-2026-6840 | Missing bounds validation for operator could allow out of range operator-code lookup during model l ... | 2026. 04. 22. | 2026. 04. 22. | 358781 |
| CVE-2026-6839 | Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out o ... | 2026. 04. 22. | 2026. 04. 22. | 358776 |
| CVE-2026-41667 | Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause inc ... | 2026. 04. 22. | 2026. 04. 22. | 358775 |
| CVE-2026-41666 | Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bou ... | 2026. 04. 22. | 2026. 04. 22. | 358774 |
| CVE-2026-41665 | Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause ... | 2026. 04. 22. | 2026. 04. 22. | 358773 |
| CVE-2026-41664 | Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid me ... | 2026. 04. 22. | 2026. 04. 22. | 358769 |
| CVE-2026-40450 | Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incor ... | 2026. 04. 22. | 2026. 04. 22. | 358772 |
| CVE-2026-40449 | Integer overflow in buffer size calculation could result in out of bounds memory access when handlin ... | 2026. 04. 22. | 2026. 04. 22. | 358771 |
| CVE-2026-40448 | Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory a ... | 2026. 04. 22. | 2026. 04. 22. | 358770 |
| CVE-2026-22754 | Vulnerability in Spring Spring Security. If an application uses to define the servlet path for co ... | 2026. 04. 22. | 2026. 04. 22. | 358777 |
| CVE-2026-22753 | Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a ... | 2026. 04. 22. | 2026. 04. 22. | 358768 |
| CVE-2026-22748 | Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwt ... | 2026. 04. 22. | 2026. 04. 22. | 358780 |
| CVE-2026-22747 | Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle c ... | 2026. 04. 22. | 2026. 04. 22. | 358779 |
| CVE-2026-22746 | Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #is ... | 2026. 04. 22. | 2026. 04. 22. | 358778 |
| CVE-2026-40451 | DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vuln ... | 2026. 04. 22. | 2026. 04. 22. | 358757 |
| CVE-2026-6416 | Tanium addressed an uncontrolled resource consumption vulnerability in Interact. | 2026. 04. 22. | 2026. 04. 22. | 358764 |
| CVE-2026-6408 | Tanium addressed an information disclosure vulnerability in Tanium Server. | 2026. 04. 22. | 2026. 04. 22. | 358763 |
| CVE-2026-6392 | Tanium addressed an information disclosure vulnerability in Threat Response. | 2026. 04. 22. | 2026. 04. 22. | 358767 |
| CVE-2026-6386 | In order to apply a particular protection key to an address range, the kernel must update the corres ... | 2026. 04. 22. | 2026. 04. 22. | 358762 |
| CVE-2026-5398 | The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the c ... | 2026. 04. 22. | 2026. 04. 22. | 358766 |
| CVE-2026-41458 | OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login h ... | 2026. 04. 22. | 2026. 04. 22. | 358758 |
| CVE-2026-41457 | OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and fi ... | 2026. 04. 22. | 2026. 04. 22. | 358761 |
| CVE-2026-6835 | The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated ... | 2026. 04. 22. | 2026. 04. 22. | 358759 |
| CVE-2026-6834 | The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated rem ... | 2026. 04. 22. | 2026. 04. 22. | 358760 |
| CVE-2026-6833 | The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote atta ... | 2026. 04. 22. | 2026. 04. 22. | 358765 |
| CVE-2026-41304 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` ... | 2026. 04. 22. | 2026. 04. 22. | 358619 |
| CVE-2026-41064 | WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fi ... | 2026. 04. 22. | 2026. 04. 22. | 358618 |
| CVE-2026-41059 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 ... | 2026. 04. 22. | 2026. 04. 22. | 358622 |
| CVE-2026-40575 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 ... | 2026. 04. 22. | 2026. 04. 22. | 358624 |
| CVE-2026-41130 | Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the ... | 2026. 04. 22. | 2026. 04. 22. | 358626 |
| CVE-2026-41129 | Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5. ... | 2026. 04. 22. | 2026. 04. 22. | 358627 |
| CVE-2026-41128 | Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePer ... | 2026. 04. 22. | 2026. 04. 22. | 358625 |
| CVE-2026-41127 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authoriza ... | 2026. 04. 22. | 2026. 04. 22. | 358623 |
| CVE-2026-41126 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect th ... | 2026. 04. 22. | 2026. 04. 22. | 358616 |
| CVE-2026-41135 | free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th gene ... | 2026. 04. 22. | 2026. 04. 22. | 358612 |
| CVE-2026-41133 | pyLoad is a free and open-source download manager written in Python. Versions up to and including 0. ... | 2026. 04. 22. | 2026. 04. 22. | 358608 |
| CVE-2026-41131 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in spec ... | 2026. 04. 22. | 2026. 04. 22. | 358617 |
| CVE-2026-40343 | free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generat ... | 2026. 04. 22. | 2026. 04. 22. | 358615 |
| CVE-2026-41144 | F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedd ... | 2026. 04. 22. | 2026. 04. 22. | 358613 |
| CVE-2026-41136 | free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source proj ... | 2026. 04. 22. | 2026. 04. 22. | 358614 |
| CVE-2026-41145 | MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prio ... | 2026. 04. 22. | 2026. 04. 22. | 358610 |
| CVE-2026-40344 | MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prio ... | 2026. 04. 22. | 2026. 04. 22. | 358609 |
| CVE-2026-41146 | facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a9 ... | 2026. 04. 22. | 2026. 04. 22. | 358611 |
| CVE-2026-5921 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that a ... | 2026. 04. 22. | 2026. 04. 22. | 358754 |
| CVE-2026-5512 | An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an a ... | 2026. 04. 22. | 2026. 04. 22. | 358741 |
| CVE-2026-4872 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 2026. 04. 22. | 2026. 04. 22. | |
| CVE-2026-4821 | An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Ser ... | 2026. 04. 22. | 2026. 04. 22. | 358742 |
| CVE-2026-4296 | An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowe ... | 2026. 04. 22. | 2026. 04. 22. | 358740 |
| CVE-2026-41063 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete XSS fix in ... | 2026. 04. 22. | 2026. 04. 22. | 358751 |
| CVE-2026-41062 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fi ... | 2026. 04. 22. | 2026. 04. 22. | 358621 |
| CVE-2026-41061 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` re ... | 2026. 04. 22. | 2026. 04. 22. | 358620 |
| CVE-2026-41055 | WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in ... | 2026. 04. 22. | 2026. 04. 22. | 358732 |
| CVE-2026-6832 | Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint t ... | 2026. 04. 22. | 2026. 04. 22. | 358744 |
| CVE-2026-6830 | nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching ... | 2026. 04. 22. | 2026. 04. 22. | 358747 |
| CVE-2026-6829 | nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated atta ... | 2026. 04. 22. | 2026. 04. 22. | 358735 |
| CVE-2026-6799 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unkno ... | 2026. 04. 22. | 2026. 04. 22. | 358492 |
| CVE-2026-41527 | KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra u ... | 2026. 04. 22. | 2026. 04. 22. | 358755 |
| CVE-2026-40946 | Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider ... | 2026. 04. 22. | 2026. 04. 22. | 358746 |
| CVE-2026-40945 | Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, t ... | 2026. 04. 22. | 2026. 04. 22. | 358745 |
| CVE-2026-40944 | Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in ... | 2026. 04. 22. | 2026. 04. 22. | 358734 |
| CVE-2026-40943 | Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session ... | 2026. 04. 22. | 2026. 04. 22. | 358750 |
| CVE-2026-40942 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and F ... | 2026. 04. 22. | 2026. 04. 22. | 358752 |
| CVE-2026-40939 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and F ... | 2026. 04. 22. | 2026. 04. 22. | 358748 |
| CVE-2026-40933 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3. ... | 2026. 04. 22. | 2026. 04. 22. | 358753 |
| CVE-2026-40931 | Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch fo ... | 2026. 04. 22. | 2026. 04. 22. | 344438 |
| CVE-2026-40706 | In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix ... | 2026. 04. 22. | 2026. 04. 22. | 358544 |
| CVE-2026-1354 | Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with t ... | 2026. 04. 22. | 2026. 04. 22. | 358733 |
| CVE-2026-6823 | HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerabil ... | 2026. 04. 22. | 2026. 04. 22. | 358731 |
| CVE-2026-6797 | A vulnerability was identified in Sanluan PublicCMS up to 6.202506.d. Affected by this vulnerability ... | 2026. 04. 22. | 2026. 04. 22. | 358491 |
| CVE-2026-40938 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 1.0. ... | 2026. 04. 22. | 2026. 04. 22. | 358743 |
| CVE-2026-40927 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving ... | 2026. 04. 22. | 2026. 04. 22. | 358739 |
| CVE-2026-40924 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to ... | 2026. 04. 22. | 2026. 04. 22. | 358730 |
| CVE-2026-40923 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to ... | 2026. 04. 22. | 2026. 04. 22. | 358737 |
| CVE-2026-35252 | Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: C Oracl ... | 2026. 04. 22. | 2026. 04. 22. | 358689 |
| CVE-2026-35251 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The ... | 2026. 04. 22. | 2026. 04. 22. | 358720 |
| CVE-2026-35250 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The ... | 2026. 04. 22. | 2026. 04. 22. | 358728 |
| CVE-2026-35249 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The ... | 2026. 04. 22. | 2026. 04. 22. | 358725 |
| CVE-2026-35248 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The ... | 2026. 04. 22. | 2026. 04. 22. | 358722 |
| CVE-2026-35247 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The ... | 2026. 04. 22. | 2026. 04. 22. | 358721 |
| CVE-2026-35246 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The ... | 2026. 04. 22. | 2026. 04. 22. | 358719 |
| CVE-2026-35245 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The ... | 2026. 04. 22. | 2026. 04. 22. | 358703 |
| CVE-2026-35244 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component ... | 2026. 04. 22. | 2026. 04. 22. | 358723 |
| CVE-2026-35243 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middlew ... | 2026. 04. 22. | 2026. 04. 22. | 358718 |
| CVE-2026-35242 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The ... | 2026. 04. 22. | 2026. 04. 22. | 358717 |
| CVE-2026-35241 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (componen ... | 2026. 04. 22. | 2026. 04. 22. | 358691 |
| CVE-2026-35240 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358702 |
| CVE-2026-35239 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versi ... | 2026. 04. 22. | 2026. 04. 22. | 358699 |
| CVE-2026-35238 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t ... | 2026. 04. 22. | 2026. 04. 22. | 358701 |
| CVE-2026-35237 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t ... | 2026. 04. 22. | 2026. 04. 22. | 358700 |
| CVE-2026-35236 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t ... | 2026. 04. 22. | 2026. 04. 22. | 358698 |
| CVE-2026-35235 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS). Supported versi ... | 2026. 04. 22. | 2026. 04. 22. | 358706 |
| CVE-2026-35234 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358697 |
| CVE-2026-35232 | Vulnerability in Oracle Fusion Middleware (component: Dynamic Monitoring Service). Supported versio ... | 2026. 04. 22. | 2026. 04. 22. | 358692 |
| CVE-2026-35231 | Vulnerability in the Oracle Financial Services Transaction Filtering product of Oracle Financial Ser ... | 2026. 04. 22. | 2026. 04. 22. | 358695 |
| CVE-2026-35230 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The ... | 2026. 04. 22. | 2026. 04. 22. | 358716 |
| CVE-2026-35229 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec ... | 2026. 04. 22. | 2026. 04. 22. | 358688 |
| CVE-2026-34325 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora ... | 2026. 04. 22. | 2026. 04. 22. | 358729 |
| CVE-2026-34324 | Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (compon ... | 2026. 04. 22. | 2026. 04. 22. | 358714 |
| CVE-2026-34323 | Vulnerability in the Oracle Life Sciences InForm product of Oracle Life Science Applications (compon ... | 2026. 04. 22. | 2026. 04. 22. | 358715 |
| CVE-2026-34321 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora ... | 2026. 04. 22. | 2026. 04. 22. | 358713 |
| CVE-2026-34320 | Vulnerability in the Oracle Financial Services Customer Screening product of Oracle Financial Servic ... | 2026. 04. 22. | 2026. 04. 22. | 358696 |
| CVE-2026-34319 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358727 |
| CVE-2026-34318 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358694 |
| CVE-2026-34317 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358724 |
| CVE-2026-34315 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv ... | 2026. 04. 22. | 2026. 04. 22. | 358653 |
| CVE-2026-34314 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora ... | 2026. 04. 22. | 2026. 04. 22. | 358693 |
| CVE-2026-34313 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora ... | 2026. 04. 22. | 2026. 04. 22. | 358690 |
| CVE-2026-34312 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affecte ... | 2026. 04. 22. | 2026. 04. 22. | 358726 |
| CVE-2026-34310 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora ... | 2026. 04. 22. | 2026. 04. 22. | 358687 |
| CVE-2026-34309 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Secu ... | 2026. 04. 22. | 2026. 04. 22. | 358646 |
| CVE-2026-34308 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported vers ... | 2026. 04. 22. | 2026. 04. 22. | 358685 |
| CVE-2026-34307 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Work ... | 2026. 04. 22. | 2026. 04. 22. | 358652 |
| CVE-2026-34306 | Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (compone ... | 2026. 04. 22. | 2026. 04. 22. | 358645 |
| CVE-2026-34305 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv ... | 2026. 04. 22. | 2026. 04. 22. | 358644 |
| CVE-2026-34304 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t ... | 2026. 04. 22. | 2026. 04. 22. | 358684 |
| CVE-2026-34303 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358686 |
| CVE-2026-34302 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader) ... | 2026. 04. 22. | 2026. 04. 22. | 358665 |
| CVE-2026-34301 | Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft ( ... | 2026. 04. 22. | 2026. 04. 22. | 358642 |
| CVE-2026-34300 | Vulnerability in the PeopleSoft Enterprise FIN Contracts product of Oracle PeopleSoft (component: Co ... | 2026. 04. 22. | 2026. 04. 22. | 358641 |
| CVE-2026-34299 | Vulnerability in the PeopleSoft Enterprise FIN Maintenance Management product of Oracle PeopleSoft ( ... | 2026. 04. 22. | 2026. 04. 22. | 358643 |
| CVE-2026-34298 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Pe ... | 2026. 04. 22. | 2026. 04. 22. | 358664 |
| CVE-2026-34297 | Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: K ... | 2026. 04. 22. | 2026. 04. 22. | 358662 |
| CVE-2026-34296 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply ... | 2026. 04. 22. | 2026. 04. 22. | 358712 |
| CVE-2026-34295 | Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: P ... | 2026. 04. 22. | 2026. 04. 22. | 358639 |
| CVE-2026-34294 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen ... | 2026. 04. 22. | 2026. 04. 22. | 358649 |
| CVE-2026-34293 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versi ... | 2026. 04. 22. | 2026. 04. 22. | 358682 |
| CVE-2026-34292 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). ... | 2026. 04. 22. | 2026. 04. 22. | 358637 |
| CVE-2026-34291 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supp ... | 2026. 04. 22. | 2026. 04. 22. | 358663 |
| CVE-2026-34290 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen ... | 2026. 04. 22. | 2026. 04. 22. | 358681 |
| CVE-2026-34289 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen ... | 2026. 04. 22. | 2026. 04. 22. | 358659 |
| CVE-2026-34288 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen ... | 2026. 04. 22. | 2026. 04. 22. | 358660 |
| CVE-2026-34287 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen ... | 2026. 04. 22. | 2026. 04. 22. | 358661 |
| CVE-2026-34286 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen ... | 2026. 04. 22. | 2026. 04. 22. | 358658 |
| CVE-2026-34285 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen ... | 2026. 04. 22. | 2026. 04. 22. | 358657 |
| CVE-2026-34284 | Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (c ... | 2026. 04. 22. | 2026. 04. 22. | 358670 |
| CVE-2026-34283 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identit ... | 2026. 04. 22. | 2026. 04. 22. | 358669 |
| CVE-2026-34282 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ ... | 2026. 04. 22. | 2026. 04. 22. | 358632 |
| CVE-2026-34281 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported v ... | 2026. 04. 22. | 2026. 04. 22. | 358710 |
| CVE-2026-34280 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (compone ... | 2026. 04. 22. | 2026. 04. 22. | 358636 |
| CVE-2026-34279 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (c ... | 2026. 04. 22. | 2026. 04. 22. | 358655 |
| CVE-2026-34278 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358683 |
| CVE-2026-34277 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Flui ... | 2026. 04. 22. | 2026. 04. 22. | 358640 |
| CVE-2026-34276 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug ... | 2026. 04. 22. | 2026. 04. 22. | 358709 |
| CVE-2026-34275 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component ... | 2026. 04. 22. | 2026. 04. 22. | 358654 |
| CVE-2026-34274 | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interfa ... | 2026. 04. 22. | 2026. 04. 22. | 358668 |
| CVE-2026-34273 | Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are ... | 2026. 04. 22. | 2026. 04. 22. | 358711 |
| CVE-2026-34272 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358679 |
| CVE-2026-34271 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug ... | 2026. 04. 22. | 2026. 04. 22. | 358708 |
| CVE-2026-34270 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug ... | 2026. 04. 22. | 2026. 04. 22. | 358704 |
| CVE-2026-34269 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Port ... | 2026. 04. 22. | 2026. 04. 22. | 358651 |
| CVE-2026-34268 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ ... | 2026. 04. 22. | 2026. 04. 22. | 358634 |
| CVE-2026-34267 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358680 |
| CVE-2026-34266 | Vulnerability in the PeopleSoft Enterprise HCM Absence Management product of Oracle PeopleSoft (comp ... | 2026. 04. 22. | 2026. 04. 22. | 358638 |
| CVE-2026-33519 | An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Win ... | 2026. 04. 22. | 2026. 04. 22. | 358738 |
| CVE-2026-33518 | An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and ... | 2026. 04. 22. | 2026. 04. 22. | 358736 |
| CVE-2026-22021 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ ... | 2026. 04. 22. | 2026. 04. 22. | 358628 |
| CVE-2026-22019 | Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (compo ... | 2026. 04. 22. | 2026. 04. 22. | 358650 |
| CVE-2026-22018 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ ... | 2026. 04. 22. | 2026. 04. 22. | 358630 |
| CVE-2026-22017 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358678 |
| CVE-2026-22016 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ ... | 2026. 04. 22. | 2026. 04. 22. | 358629 |
| CVE-2026-22015 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). ... | 2026. 04. 22. | 2026. 04. 22. | 358705 |
| CVE-2026-22014 | Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow ... | 2026. 04. 22. | 2026. 04. 22. | 358656 |
| CVE-2026-22013 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ ... | 2026. 04. 22. | 2026. 04. 22. | 358631 |
| CVE-2026-22011 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch) ... | 2026. 04. 22. | 2026. 04. 22. | 358666 |
| CVE-2026-22010 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora ... | 2026. 04. 22. | 2026. 04. 22. | 358677 |
| CVE-2026-22009 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358676 |
| CVE-2026-22008 | Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is ... | 2026. 04. 22. | 2026. 04. 22. | 358647 |
| CVE-2026-22007 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition produ ... | 2026. 04. 22. | 2026. 04. 22. | 358633 |
| CVE-2026-22006 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (compone ... | 2026. 04. 22. | 2026. 04. 22. | 358648 |
| CVE-2026-22005 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358675 |
| CVE-2026-22004 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t ... | 2026. 04. 22. | 2026. 04. 22. | 358674 |
| CVE-2026-22003 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co ... | 2026. 04. 22. | 2026. 04. 22. | 358635 |
| CVE-2026-22002 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358671 |
| CVE-2026-22001 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). ... | 2026. 04. 22. | 2026. 04. 22. | 358707 |
| CVE-2026-21999 | Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are ... | 2026. 04. 22. | 2026. 04. 22. | 358667 |
| CVE-2026-21998 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported ... | 2026. 04. 22. | 2026. 04. 22. | 358673 |
| CVE-2026-21997 | Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Application ... | 2026. 04. 22. | 2026. 04. 22. | 358672 |
| CVE-2026-40935 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` a ... | 2026. 04. 22. | 2026. 04. 22. | 358601 |
| CVE-2026-40929 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.jso ... | 2026. 04. 22. | 2026. 04. 22. | 358603 |
| CVE-2026-40928 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpo ... | 2026. 04. 22. | 2026. 04. 22. | 358602 |
| CVE-2026-40926 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endp ... | 2026. 04. 22. | 2026. 04. 22. | 358604 |
| CVE-2026-3307 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an att ... | 2026. 04. 22. | 2026. 04. 22. | 358607 |
| CVE-2026-5845 | An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHu ... | 2026. 04. 22. | 2026. 04. 22. | 358606 |
| CVE-2026-41060 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` func ... | 2026. 04. 22. | 2026. 04. 22. | 358599 |
| CVE-2026-41058 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVi ... | 2026. 04. 22. | 2026. 04. 22. | 358605 |
| CVE-2026-41057 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation ... | 2026. 04. 22. | 2026. 04. 22. | 358600 |
| CVE-2026-41056 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll ... | 2026. 04. 22. | 2026. 04. 22. | 358598 |
| CVE-2026-6796 | A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_l ... | 2026. 04. 21. | 2026. 04. 21. | 358490 |
| CVE-2026-40925 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpda ... | 2026. 04. 21. | 2026. 04. 21. | 358575 |
| CVE-2026-40911 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's Web ... | 2026. 04. 21. | 2026. 04. 21. | 358592 |
| CVE-2026-40910 | frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTT ... | 2026. 04. 21. | 2026. 04. 21. | 358588 |
| CVE-2026-40906 | Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the Elect ... | 2026. 04. 21. | 2026. 04. 21. | 358576 |
| CVE-2026-40905 | LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, a password reset poisonin ... | 2026. 04. 21. | 2026. 04. 21. | 358580 |
| CVE-2026-40895 | follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that a ... | 2026. 04. 21. | 2026. 04. 21. | 358584 |
| CVE-2026-40892 | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, ... | 2026. 04. 21. | 2026. 04. 21. | 358583 |
| CVE-2026-6819 | HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin i ... | 2026. 04. 21. | 2026. 04. 21. | 358593 |
| CVE-2026-41320 | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 an ... | 2026. 04. 21. | 2026. 04. 21. | 358577 |
| CVE-2026-40888 | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 an ... | 2026. 04. 21. | 2026. 04. 21. | 358590 |
| CVE-2026-40887 | Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to version ... | 2026. 04. 21. | 2026. 04. 21. | 358581 |
| CVE-2026-40881 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network vers ... | 2026. 04. 21. | 2026. 04. 21. | 358191 |
| CVE-2026-40880 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus ve ... | 2026. 04. 21. | 2026. 04. 21. | 358192 |
| CVE-2026-40879 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when a ... | 2026. 04. 21. | 2026. 04. 21. | 358591 |
| CVE-2026-40878 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 20 ... | 2026. 04. 21. | 2026. 04. 21. | 358586 |
| CVE-2026-40875 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 20 ... | 2026. 04. 21. | 2026. 04. 21. | 358594 |
| CVE-2026-40874 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 20 ... | 2026. 04. 21. | 2026. 04. 21. | 358589 |
| CVE-2026-40873 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 20 ... | 2026. 04. 21. | 2026. 04. 21. | 358587 |
| CVE-2026-40872 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 20 ... | 2026. 04. 21. | 2026. 04. 21. | 358579 |
| CVE-2026-40871 | mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026- ... | 2026. 04. 21. | 2026. 04. 21. | 358585 |
| CVE-2026-40870 | Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30 ... | 2026. 04. 21. | 2026. 04. 21. | 358578 |
| CVE-2026-40869 | Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.3 ... | 2026. 04. 21. | 2026. 04. 21. | 358582 |
| CVE-2026-40372 | Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to ... | 2026. 04. 21. | 2026. 04. 21. | 358597 |
| CVE-2026-33813 | Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. | 2026. 04. 21. | 2026. 04. 21. | 358596 |
| CVE-2026-33812 | Parsing a malicious font file can cause excessive memory allocation. | 2026. 04. 21. | 2026. 04. 21. | 358595 |
| CVE-2026-40909 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint ( ... | 2026. 04. 21. | 2026. 04. 21. | 358567 |
| CVE-2026-40908 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at ... | 2026. 04. 21. | 2026. 04. 21. | 358565 |
| CVE-2026-40907 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/ ... | 2026. 04. 21. | 2026. 04. 21. | 358566 |
| CVE-2026-40903 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerabil ... | 2026. 04. 21. | 2026. 04. 21. | 358572 |
| CVE-2026-40890 | The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering ... | 2026. 04. 21. | 2026. 04. 21. | 358570 |
| CVE-2026-40889 | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 an ... | 2026. 04. 21. | 2026. 04. 21. | 358568 |
| CVE-2026-40885 | goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ... | 2026. 04. 21. | 2026. 04. 21. | 358571 |
| CVE-2026-40884 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authenticat ... | 2026. 04. 21. | 2026. 04. 21. | 358573 |
| CVE-2026-40883 | goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross ... | 2026. 04. 21. | 2026. 04. 21. | 358574 |
| CVE-2026-40876 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape ... | 2026. 04. 21. | 2026. 04. 21. | 358569 |
| CVE-2026-6745 | A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown ... | 2026. 04. 21. | 2026. 04. 21. | 358436 |
| CVE-2026-6744 | A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Do ... | 2026. 04. 21. | 2026. 04. 21. | 358435 |
| CVE-2026-41456 | Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the se ... | 2026. 04. 21. | 2026. 04. 21. | 358564 |
| CVE-2026-40868 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, ky ... | 2026. 04. 21. | 2026. 04. 21. | 358561 |
| CVE-2026-40867 | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access ... | 2026. 04. 21. | 2026. 04. 21. | 358558 |
| CVE-2026-40866 | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure dir ... | 2026. 04. 21. | 2026. 04. 21. | 358557 |
| CVE-2026-40865 | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure dir ... | 2026. 04. 21. | 2026. 04. 21. | 358556 |
| CVE-2026-40614 | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, ... | 2026. 04. 21. | 2026. 04. 21. | 358555 |
| CVE-2026-40613 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN ... | 2026. 04. 21. | 2026. 04. 21. | 358551 |
| CVE-2026-22751 | Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login ... | 2026. 04. 21. | 2026. 04. 21. | 358560 |
| CVE-2026-40611 | Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 cha ... | 2026. 04. 21. | 2026. 04. 21. | 358553 |
| CVE-2026-40608 | Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. ... | 2026. 04. 21. | 2026. 04. 21. | 358552 |
| CVE-2026-40606 | mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software ... | 2026. 04. 21. | 2026. 04. 21. | 358549 |
| CVE-2026-40604 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. ... | 2026. 04. 21. | 2026. 04. 21. | 358548 |
| CVE-2026-40602 | The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up t ... | 2026. 04. 21. | 2026. 04. 21. | 358547 |
| CVE-2026-40599 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. ... | 2026. 04. 21. | 2026. 04. 21. | 358545 |
| CVE-2026-41194 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox ... | 2026. 04. 21. | 2026. 04. 21. | 358562 |
| CVE-2026-41193 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's ... | 2026. 04. 21. | 2026. 04. 21. | 358559 |
| CVE-2026-41192 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply an ... | 2026. 04. 21. | 2026. 04. 21. | 358554 |
| CVE-2026-40594 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set ... | 2026. 04. 21. | 2026. 04. 21. | 358546 |
| CVE-2026-40588 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at ... | 2026. 04. 21. | 2026. 04. 21. | 358563 |
| CVE-2026-40587 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their pa ... | 2026. 04. 21. | 2026. 04. 21. | 358550 |
| CVE-2026-41191 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesCo ... | 2026. 04. 21. | 2026. 04. 21. | 358543 |
| CVE-2026-41190 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SH ... | 2026. 04. 21. | 2026. 04. 21. | 358542 |
| CVE-2026-41189 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thr ... | 2026. 04. 21. | 2026. 04. 21. | 358540 |
| CVE-2026-41183 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned ... | 2026. 04. 21. | 2026. 04. 21. | 358539 |
| CVE-2026-40592 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-sen ... | 2026. 04. 21. | 2026. 04. 21. | 358541 |
| CVE-2026-40591 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-co ... | 2026. 04. 21. | 2026. 04. 21. | 358537 |
| CVE-2026-40590 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change C ... | 2026. 04. 21. | 2026. 04. 21. | 358538 |
| CVE-2026-40589 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privil ... | 2026. 04. 21. | 2026. 04. 21. | 358536 |
| CVE-2026-40586 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler perfo ... | 2026. 04. 21. | 2026. 04. 21. | 358531 |
| CVE-2026-40585 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a password reset is ini ... | 2026. 04. 21. | 2026. 04. 21. | 358535 |
| CVE-2026-40584 | RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1. ... | 2026. 04. 21. | 2026. 04. 21. | 358530 |
| CVE-2026-40583 | UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit ... | 2026. 04. 21. | 2026. 04. 21. | 358529 |
| CVE-2026-40570 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_cu ... | 2026. 04. 21. | 2026. 04. 21. | 358534 |
| CVE-2026-40569 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass ... | 2026. 04. 21. | 2026. 04. 21. | 358526 |
| CVE-2026-40050 | CrowdStrike has released security updates to address a critical unauthenticated path traversal vulne ... | 2026. 04. 21. | 2026. 04. 21. | 358528 |
| CVE-2026-38835 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSB ... | 2026. 04. 21. | 2026. 04. 21. | 358533 |
| CVE-2026-38834 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_ac ... | 2026. 04. 21. | 2026. 04. 21. | 358532 |
| CVE-2026-21571 | This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, ... | 2026. 04. 21. | 2026. 04. 21. | 358527 |
| CVE-2026-40568 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a store ... | 2026. 04. 21. | 2026. 04. 21. | 358517 |
| CVE-2026-40567 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthent ... | 2026. 04. 21. | 2026. 04. 21. | 358524 |
| CVE-2026-6743 | A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the ... | 2026. 04. 21. | 2026. 04. 21. | 358434 |
| CVE-2026-5652 | An insecure direct object reference vulnerability in the Users API component of Crafty Controller al ... | 2026. 04. 21. | 2026. 04. 21. | 358523 |
| CVE-2026-40576 | excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vu ... | 2026. 04. 21. | 2026. 04. 21. | 358521 |
| CVE-2026-40574 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2 ... | 2026. 04. 21. | 2026. 04. 21. | 358522 |
| CVE-2026-40279 | BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, ... | 2026. 04. 21. | 2026. 04. 21. | 358520 |
| CVE-2026-40161 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 1.0. ... | 2026. 04. 21. | 2026. 04. 21. | 358519 |
| CVE-2026-35451 | Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exi ... | 2026. 04. 21. | 2026. 04. 21. | 358525 |
| CVE-2026-30452 | Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management syste ... | 2026. 04. 21. | 2026. 04. 21. | 358518 |
| CVE-2026-40566 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Serve ... | 2026. 04. 21. | 2026. 04. 21. | 358507 |
| CVE-2026-29179 | October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grai ... | 2026. 04. 21. | 2026. 04. 21. | 358508 |
| CVE-2026-27937 | October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflect ... | 2026. 04. 21. | 2026. 04. 21. | 358516 |
| CVE-2026-26274 | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnera ... | 2026. 04. 21. | 2026. 04. 21. | 358509 |