Search
23,162 CVEs
CVEs (23,162, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 23,162 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-7309 | MEDIUM | 4.3 | 2026-04-28 | A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `h… | |
| CVE-2026-40550 | NONE | — | 2026-04-28 | mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the application. An attacker with access to any running ap… | |
| CVE-2026-40551 | NONE | — | 2026-04-28 | mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process… | |
| CVE-2026-40552 | NONE | — | 2026-04-28 | mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command … | |
| CVE-2026-5944 | HIGH | Patched | 8.2 | 2026-04-28 | An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP p… |
| CVE-2026-6706 | MEDIUM | Patched | 6.5 | 2026-04-28 | Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content from unauthorized vaults … |
| CVE-2026-7272 | HIGH | 7.3 | 2026-04-28 | A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected element is the function generate_matlab_code/execute_… | |
| CVE-2026-7281 | LOW | 2.4 | 2026-04-28 | A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function supplier of the file /index.php?page=supplier… | |
| CVE-2025-67223 | HIGH | Patched | 7.5 | 2026-04-28 | The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible direc… |
| CVE-2026-27760 | HIGH | 8.1 | 2026-04-28 | OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code … | |
| CVE-2026-40556 | NONE | — | 2026-04-28 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-40968 | MEDIUM | Patched | 4.2 | 2026-04-28 | When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unau… |
| CVE-2026-40969 | LOW | Patched | 3.7 | 2026-04-28 | The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obt… |
| CVE-2026-7282 | MEDIUM | 4.7 | 2026-04-28 | A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function delete_expired of the file /ajax.php?action=delete_expir… | |
| CVE-2026-7283 | MEDIUM | 4.7 | 2026-04-28 | A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function save_expired of the file /ajax.php?action=save_expi… | |
| CVE-2026-7288 | HIGH | 8.8 | 2026-04-28 | A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file /boafrm/formVpnConfigSetup. The manipulation of the… | |
| CVE-2026-7289 | HIGH | 8.8 | 2026-04-28 | A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/formWanConfigSetup. The manipulation of the argument sub… | |
| CVE-2026-7320 | HIGH | Patched | 7.5 | 2026-04-28 | Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR… |
| CVE-2026-7321 | CRITICAL | Patched | 9.6 | 2026-04-28 | Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1,… |
| CVE-2026-7322 | HIGH | Patched | 7.3 | 2026-04-28 | Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effo… |
| CVE-2026-7323 | HIGH | Patched | 7.3 | 2026-04-28 | Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effo… |
| CVE-2026-7324 | HIGH | Patched | 7.3 | 2026-04-28 | Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have b… |
| CVE-2025-60887 | MEDIUM | 5.3 | 2026-04-28 | An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may… | |
| CVE-2025-60889 | CRITICAL | Patched | 9.8 | 2026-04-28 | Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts. |
| CVE-2026-38651 | HIGH | Patched | 8.2 | 2026-04-28 | Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verif… |