CVEs from 2026
Total
14,539
critical
critical 1,284
high
high 4,929
medium
medium 4,658
low
low 502
% Critical
8.8%
% with KEV
0.4%
% with exploit
0.7%
Top vendors
Top products
- chrome 558
- firepower_threat_defense_software 310
- gcp 299
- firepower_threat_defense 298
- openclaw 172
- commerce 104
- netweaver_application_server_abap 102
- commerce_b2b 89
Top packages
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-6457 | medium | 6.5 | 6.5 | 1mo ago | The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' parameter in all versions up to, and including, 1.13.19 due to insufficient escapi… | |||
| CVE-2026-42474 | medium | 6.5 | 6.5 | 1mo ago | MixPHP Framework has an SQL injection vulnerability via crafted `data` array | |||
| CVE-2026-42475 | medium | 6.5 | 6.5 | 1mo ago | MixPHP Framework has an SQL injection vulnerability | |||
| CVE-2026-26461 | medium | 6.5 | 6.5 | 1mo ago | A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticated attacker to execute arbitrary commands via a crafted web request. | |||
| CVE-2026-23863 | medium | 6.5 | 6.5 | 1mo ago | An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the a… | |||
| CVE-2026-43505 | medium | 6.5 | 6.5 | 1mo ago | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activation scenario, relayin… | |||
| CVE-2026-43504 | medium | 6.5 | 6.5 | 1mo ago | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused scenario, relaying of u… | |||
| CVE-2026-28909 | medium | 6.5 | 6.5 | 1mo ago | Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3. | |||
| CVE-2026-1577 | medium | 6.5 | 6.5 | 1mo ago | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr… | |||
| CVE-2026-4502 | medium | 6.5 | 6.5 | 1mo ago | IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot d… | |||
| CVE-2026-40950 | medium | 6.5 | 6.5 | 1mo ago | CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially crafted message to the server and caus… | |||
| CVE-2026-3340 | medium | 6.5 | 6.5 | 1mo ago | IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, pote… | |||
| CVE-2026-28532 | medium | 6.5 | 6.5 | 1mo ago | FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t … | |||
| CVE-2026-3345 | medium | 6.5 | 6.5 | 1mo ago | IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../)… | |||
| CVE-2026-42137 | medium | 6.5 | 6.5 | 1mo ago | Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API | |||
| CVE-2026-40603 | medium | 6.5 | 6.5 | 1mo ago | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes a legacy dashboard route that return… | |||
| CVE-2026-35514 | medium | 6.5 | 6.5 | 1mo ago | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any … | |||
| CVE-2026-3833 | medium | 6.5 | 6.5 | 1mo ago | RHSA-2026:20612: gnutls security update (Important) | |||
| CVE-2026-36759 | medium | 6.5 | 6.5 | 1mo ago | A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request. | |||
| CVE-2026-7382 | medium | 6.5 | 6.5 | 1mo ago | Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation.… | |||
| CVE-2026-41658 | medium | 6.5 | 6.5 | 1mo ago | Admidio's Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items | |||
| CVE-2026-41655 | medium | 6.5 | 6.5 | 1mo ago | Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials | |||
| CVE-2026-7425 | medium | 6.5 | 6.5 | 1mo ago | Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash… | |||
| CVE-2026-7423 | medium | 6.5 | 6.5 | 1mo ago | Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing pi… | |||
| CVE-2026-7422 | medium | 6.5 | 6.5 | 1mo ago | Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC ad… | |||
| CVE-2026-41499 | medium | 6.5 | 6.5 | 1mo ago | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, multiple heap-based out-of-bounds WRITE vulnerabilities exis… | |||
| CVE-2026-26206 | medium | 6.5 | 6.5 | 1mo ago | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security… | |||
| CVE-2026-38993 | medium | 6.5 | 6.5 | 1mo ago | Cockpit is vulnerable to directory traversal | |||
| CVE-2026-42521 | medium | 6.5 | 6.5 | 1mo ago | Jenkins Matrix Authorization Strategy Plugin: Unsafe deserialization allows invocation of parameterless constructors | |||
| CVE-2026-22740 | medium | 6.5 | 6.5 | 1mo ago | Spring Framework DoS with Multipart Temp Files in WebFlux | |||
| CVE-2026-42412 | medium | 6.5 | 6.5 | 1mo ago | Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP User Frontend: from n/a through 4.3.1. | |||
| CVE-2026-6238 | medium | 6.5 | 6.5 | 1mo ago | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing… | |||
| CVE-2026-42430 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable | |||
| CVE-2026-42420 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks | |||
| CVE-2026-41911 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw: Feishu docx upload_file/upload_image Bypasses Workspace-Only Filesystem Policy (GHSA-qf48-qfv4-jjm9 Incomplete Fix) | |||
| CVE-2026-41408 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw: Tlon media downloads can bypass core safety limits and exhaust disk | |||
| CVE-2026-41388 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw: Tlon Startup Migration Rehydrates Empty-Array Revocations From File Config | |||
| CVE-2026-41385 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw Nostr privateKey config redaction bypass leaks plaintext signing key via config.get | |||
| CVE-2026-41376 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw: Matrix thread root and reply context bypass sender allowlist | |||
| CVE-2026-41375 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw: `/phone arm`/`/phone disarm` Bypasses `operator.admin` Scope Check for External Channels | |||
| CVE-2026-24204 | medium | 6.5 | 6.5 | 1mo ago | NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead to information disclosure. | |||
| CVE-2026-6706 | medium | 6.5 | 6.5 | 1mo ago | Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults via a crafted API request. … | |||
| CVE-2026-41607 | medium | 6.5 | 6.5 | 1mo ago | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | |||
| CVE-2026-40980 | medium | 6.5 | 6.5 | 1mo ago | Spring AI Vulnerable to OOM by attacker-controlled PDF | |||
| CVE-2026-41525 | medium | 6.5 | 6.5 | 1mo ago | KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of … | |||
| CVE-2026-41370 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can … | |||
| CVE-2026-41369 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables | |||
| CVE-2026-41368 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the $ENV filter. Attackers can bypass safe-bin restrictions by using … | |||
| CVE-2026-41363 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw: Feishu extension resolveUploadInput bypasses file-system sandbox and allows arbitrary file reads via upload_image | |||
| CVE-2026-41465 | medium | 6.5 | 6.5 | 1mo ago | ProjeQtor versions 7.0 through 12.4.3 contain a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against directory traversal seque… | |||
| CVE-2026-41081 | medium | 6.5 | 6.5 | 1mo ago | Apache Storm's Improper Handling of TLS Client Authentication Failure Leads to Anonymous Principal Assignment | |||
| CVE-2026-42255 | medium | 6.5 | 6.5 | 1mo ago | Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation. | |||
| CVE-2026-41481 | medium | 6.5 | 6.5 | 1mo ago | LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using valid… | |||
| CVE-2026-6968 | medium | 6.5 | 6.5 | 1mo ago | Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute… | |||
| CVE-2026-6967 | medium | 6.5 | 6.5 | 1mo ago | awslabs/tough is Missing Delegated Metadata Validation | |||
| CVE-2026-6966 | medium | 6.5 | 6.5 | 1mo ago | awslabs/tough Delegated Roles have a Signature Threshold Bypass | |||
| CVE-2026-41427 | medium | 6.5 | 6.5 | 1mo ago | OAuth 2.1 Provider: Unprivileged users can register OAuth clients | |||
| CVE-2026-42041 | medium | 6.5 | 6.5 | 1mo ago | Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy | |||
| CVE-2026-42202 | medium | 6.5 | 6.5 | 1mo ago | nova-toggle-5: Improper authorization on toggle endpoint allowed non-Nova users to modify boolean fields | |||
| CVE-2026-5265 | medium | 6.5 | 6.5 | 1mo ago | When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original packet into the ICMP error body using the IP header's self-declared total leng… | |||
| CVE-2026-41340 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration incorrectly fans default-account trust into all named accounts. Attackers can exp… | |||
| CVE-2026-41334 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce pixel-limit guards on sips. Attackers can exploit this by uploading oversized … | |||
| CVE-2026-41908 | medium | 6.5 | 6.5 | 1mo ago | OpenClaw: Assistant media route missed scope enforcement for trusted-proxy authorization | |||
| CVE-2026-5926 | medium | 6.5 | 6.5 | 1mo ago | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Acce… | |||
| CVE-2026-41314 | medium | 6.5 | 6.5 | 1mo ago | pypdf: Manipulated FlateDecode image dimensions can exhaust RAM | |||
| CVE-2026-6355 | medium | 6.5 | 6.5 | 1mo ago | A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to u… | |||
| CVE-2026-31192 | medium | 6.5 | 6.5 | 1mo ago | Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attackers to obtain sensitive user data via a crafted request. | |||
| CVE-2026-6834 | medium | 6.5 | 6.5 | 2mo ago | The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arbitrarily read database contents through a specific API method. | |||
| CVE-2026-6833 | medium | 6.5 | 6.5 | 2mo ago | The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | |||
| CVE-2026-40924 | medium | 6.5 | 6.5 | 2mo ago | Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion | |||
| CVE-2026-41320 | medium | 6.5 | 6.5 | 2mo ago | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a specially crafted request made to a certain endpoint could result in SQL injection, al… | |||
| CVE-2026-40889 | medium | 6.5 | 6.5 | 2mo ago | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain api endpoint. Ver… | |||
| CVE-2026-40888 | medium | 6.5 | 6.5 | 2mo ago | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized information by exploiting… | |||
| CVE-2026-40161 | medium | 6.5 | 6.5 | 2mo ago | Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL | |||
| CVE-2026-30452 | medium | 6.5 | 6.5 | 2mo ago | Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authenticated users with low privileges to modify articles owned by users with higher… | |||
| CVE-2026-25542 | medium | 6.5 | 6.5 | 2mo ago | Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching | |||
| CVE-2026-39396 | medium | 6.5 | 6.5 | 2mo ago | OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS) | |||
| CVE-2026-6588 | medium | 6.5 | 6.5 | 2mo ago | A weakness has been identified in serge-chat serge up to 1.4TB. The impacted element is the function download_model/delete_model of the file api/src/serge/routers/model.py of the component Model API … | |||
| CVE-2026-6579 | medium | 6.5 | 6.5 | 2mo ago | A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. This manipulation causes missing a… | |||
| CVE-2026-6437 | medium | 6.5 | 6.5 | 2mo ago | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) before v3.0.1 allows remote authenticated users with PersistentVolume creati… | |||
| CVE-2026-40346 | medium | 6.5 | 6.5 | 2mo ago | NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins | |||
| CVE-2026-40293 | medium | 6.5 | 6.5 | 2mo ago | OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML response | |||
| CVE-2026-33569 | medium | 6.5 | 6.5 | 2mo ago | Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used to compromise the device. | |||
| CVE-2026-23777 | medium | 6.5 | 6.5 | 2mo ago | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.1… | |||
| CVE-2026-41313 | medium | 6.5 | 6.5 | 2mo ago | pypdf: Possible long runtimes for wrong size values in incremental mode | |||
| CVE-2026-41312 | medium | 6.5 | 6.5 | 2mo ago | pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM | |||
| CVE-2026-3861 | medium | 6.5 | 6.5 | 2mo ago | LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards whe… | |||
| CVE-2026-6364 | medium | 6.5 | 6.5 | 2mo ago | Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security se… | |||
| CVE-2026-20081 | medium | 6.5 | 6.5 | 2mo ago | Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attack… | |||
| CVE-2026-20078 | medium | 6.5 | 6.5 | 2mo ago | Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attack… | |||
| CVE-2026-20061 | medium | 6.5 | 6.5 | 2mo ago | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit… | |||
| CVE-2026-32151 | medium | 6.5 | 6.5 | 2mo ago | Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. | |||
| CVE-2026-27925 | medium | 6.5 | 6.5 | 2mo ago | Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network. | |||
| CVE-2026-26155 | medium | 6.5 | 6.5 | 2mo ago | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | |||
| CVE-2026-38533 | medium | 6.5 | 6.5 | 2mo ago | An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and acco… | |||
| CVE-2026-22576 | medium | 6.5 | 6.5 | 2mo ago | A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all v… | |||
| CVE-2026-22574 | medium | 6.5 | 6.5 | 2mo ago | A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all v… | |||
| CVE-2026-22573 | medium | 6.5 | 6.5 | 2mo ago | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all… | |||
| CVE-2026-21742 | medium | 6.5 | 6.5 | 2mo ago | A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3… | |||
| CVE-2026-34264 | medium | 6.5 | 6.5 | 2mo ago | During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the… |