Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

29528
Total
2302
Critical
8845
High
9186
Medium
CVE ID Severity Score Description Published
CVE-2026-40493 CRITICAL 9.8 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999eca3bc979, the PSD codec … Apr 18, 2026
CVE-2026-40492 CRITICAL 9.8 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, the XWD codec … Apr 18, 2026
CVE-2026-40491 MEDIUM 6.5 gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting … Apr 18, 2026
CVE-2026-40490 MEDIUM 6.8 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect following is enabled (followRedirect(true)), versions of … Apr 18, 2026
CVE-2026-40489 UNKNOWN editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in … Apr 18, 2026
CVE-2026-40487 HIGH 8.9 Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, … Apr 18, 2026
CVE-2026-35582 HIGH 8.8 Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file … Apr 18, 2026
CVE-2026-1838 MEDIUM 6.1 The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to … Apr 18, 2026
CVE-2026-1559 MEDIUM 6.4 The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to … Apr 18, 2026
CVE-2026-40572 CRITICAL 9.0 NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode … Apr 18, 2026
CVE-2026-40350 HIGH 8.8 Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access … Apr 18, 2026
CVE-2026-40317 CRITICAL 9.3 NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry … Apr 18, 2026
CVE-2026-35465 HIGH 7.5 SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, … Apr 18, 2026
CVE-2026-40593 MEDIUM 4.8 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value … Apr 18, 2026
CVE-2026-40582 UNKNOWN ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's … Apr 18, 2026
CVE-2026-40581 HIGH 8.1 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records … Apr 18, 2026
CVE-2026-40485 MEDIUM 5.3 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on … Apr 18, 2026
CVE-2026-40484 CRITICAL 9.1 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from … Apr 18, 2026
CVE-2026-40483 MEDIUM 5.4 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes … Apr 18, 2026
CVE-2026-40482 UNKNOWN ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue … Apr 18, 2026
CVE-2026-40480 UNKNOWN ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorization … Apr 18, 2026
CVE-2026-40349 HIGH 8.8 Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate … Apr 18, 2026
CVE-2026-40348 HIGH 7.7 Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger … Apr 18, 2026
CVE-2026-40347 MEDIUM 5.3 Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large … Apr 18, 2026
CVE-2026-40346 UNKNOWN NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request … Apr 18, 2026