Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

23,162 CVEs

CVEs (23,162, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 23,162 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-7309 MEDIUM 4.3 2026-04-28 A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `h…
CVE-2026-40550 NONE — 2026-04-28 mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the application. An attacker with access to any running ap…
CVE-2026-40551 NONE — 2026-04-28 mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process…
CVE-2026-40552 NONE — 2026-04-28 mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command …
CVE-2026-5944 HIGH Patched 8.2 2026-04-28 An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP p…
CVE-2026-6706 MEDIUM Patched 6.5 2026-04-28 Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults …
CVE-2026-7272 HIGH 7.3 2026-04-28 A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_…
CVE-2026-7281 LOW 2.4 2026-04-28 A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function supplier of the file /index.php?page=supplier…
CVE-2025-67223 HIGH Patched 7.5 2026-04-28 The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible direc…
CVE-2026-27760 HIGH 8.1 2026-04-28 OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code …
CVE-2026-40556 NONE — 2026-04-28 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-40968 MEDIUM Patched 4.2 2026-04-28 When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unau…
CVE-2026-40969 LOW Patched 3.7 2026-04-28 The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obt…
CVE-2026-7282 MEDIUM 4.7 2026-04-28 A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expir…
CVE-2026-7283 MEDIUM 4.7 2026-04-28 A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function save_expired of the file /ajax.php?action=save_expi…
CVE-2026-7288 HIGH 8.8 2026-04-28 A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the…
CVE-2026-7289 HIGH 8.8 2026-04-28 A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument sub…
CVE-2026-7320 HIGH Patched 7.5 2026-04-28 Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR…
CVE-2026-7321 CRITICAL Patched 9.6 2026-04-28 Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1,…
CVE-2026-7322 HIGH Patched 7.3 2026-04-28 Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effo…
CVE-2026-7323 HIGH Patched 7.3 2026-04-28 Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effo…
CVE-2026-7324 HIGH Patched 7.3 2026-04-28 Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have b…
CVE-2025-60887 MEDIUM 5.3 2026-04-28 An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may…
CVE-2025-60889 CRITICAL Patched 9.8 2026-04-28 Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.
CVE-2026-38651 HIGH Patched 8.2 2026-04-28 Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verif…