Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29528
Total
2302
Critical
8845
High
9186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40493 | CRITICAL | 9.8 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999eca3bc979, the PSD codec … | Apr 18, 2026 |
| CVE-2026-40492 | CRITICAL | 9.8 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, the XWD codec … | Apr 18, 2026 |
| CVE-2026-40491 | MEDIUM | 6.5 | gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting … | Apr 18, 2026 |
| CVE-2026-40490 | MEDIUM | 6.8 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect following is enabled (followRedirect(true)), versions of … | Apr 18, 2026 |
| CVE-2026-40489 | UNKNOWN | — | editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in … | Apr 18, 2026 |
| CVE-2026-40487 | HIGH | 8.9 | Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, … | Apr 18, 2026 |
| CVE-2026-35582 | HIGH | 8.8 | Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file … | Apr 18, 2026 |
| CVE-2026-1838 | MEDIUM | 6.1 | The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to … | Apr 18, 2026 |
| CVE-2026-1559 | MEDIUM | 6.4 | The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to … | Apr 18, 2026 |
| CVE-2026-40572 | CRITICAL | 9.0 | NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode … | Apr 18, 2026 |
| CVE-2026-40350 | HIGH | 8.8 | Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access … | Apr 18, 2026 |
| CVE-2026-40317 | CRITICAL | 9.3 | NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry … | Apr 18, 2026 |
| CVE-2026-35465 | HIGH | 7.5 | SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, … | Apr 18, 2026 |
| CVE-2026-40593 | MEDIUM | 4.8 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value … | Apr 18, 2026 |
| CVE-2026-40582 | UNKNOWN | — | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's … | Apr 18, 2026 |
| CVE-2026-40581 | HIGH | 8.1 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records … | Apr 18, 2026 |
| CVE-2026-40485 | MEDIUM | 5.3 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on … | Apr 18, 2026 |
| CVE-2026-40484 | CRITICAL | 9.1 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from … | Apr 18, 2026 |
| CVE-2026-40483 | MEDIUM | 5.4 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes … | Apr 18, 2026 |
| CVE-2026-40482 | UNKNOWN | — | ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue … | Apr 18, 2026 |
| CVE-2026-40480 | UNKNOWN | — | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorization … | Apr 18, 2026 |
| CVE-2026-40349 | HIGH | 8.8 | Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate … | Apr 18, 2026 |
| CVE-2026-40348 | HIGH | 7.7 | Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger … | Apr 18, 2026 |
| CVE-2026-40347 | MEDIUM | 5.3 | Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large … | Apr 18, 2026 |
| CVE-2026-40346 | UNKNOWN | — | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request … | Apr 18, 2026 |