Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

29528
Total
2302
Critical
8845
High
9186
Medium
CVE ID Severity Score Description Published
CVE-2026-40321 HIGH 8.0 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially … Apr 17, 2026
CVE-2026-40306 UNKNOWN DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the … Apr 17, 2026
CVE-2026-40305 MEDIUM 4.3 DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in … Apr 17, 2026
CVE-2026-40304 MEDIUM 5.3 zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (controller/unaccess.go) contains a logical error in its … Apr 17, 2026
CVE-2026-40258 CRITICAL 9.1 The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip … Apr 17, 2026
CVE-2026-29013 UNKNOWN libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which is … Apr 17, 2026
CVE-2026-40527 HIGH 7.8 radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ELF binaries can embed malicious r2 command sequences … Apr 17, 2026
CVE-2026-40303 HIGH 7.5 zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls make([]string, … Apr 17, 2026
CVE-2026-40302 MEDIUM 6.1 zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine uses Go's text/template (which performs no … Apr 17, 2026
CVE-2026-40301 MEDIUM 4.7 DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style> elements in SVG content but never inspects their text content. … Apr 17, 2026
CVE-2026-40299 UNKNOWN next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.1with `localePrefix: 'as-needed'` could construct URLs where path handling and the WHATWG … Apr 17, 2026
CVE-2026-40293 MEDIUM 6.5 OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is configured to use preshared-key authentication with the built-in playground … Apr 17, 2026
CVE-2026-40286 HIGH 7.5 WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' … Apr 17, 2026
CVE-2026-40285 HIGH 8.8 WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. The cpf_usuario POST parameter overwrites the … Apr 17, 2026
CVE-2026-40284 MEDIUM 6.8 WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject … Apr 17, 2026
CVE-2026-40282 UNKNOWN WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject … Apr 17, 2026
CVE-2026-40196 HIGH 8.1 HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user … Apr 17, 2026
CVE-2026-40155 MEDIUM 5.4 The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce … Apr 17, 2026
CVE-2026-35603 UNKNOWN Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide default configuration from C:\ProgramData\ClaudeCode\managed-settings.json without validating … Apr 17, 2026
CVE-2026-35512 UNKNOWN xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to … Apr 17, 2026
CVE-2026-35402 UNKNOWN mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read_only mode enforcement can be bypassed using … Apr 17, 2026
CVE-2026-33689 UNKNOWN xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated … Apr 17, 2026
CVE-2026-33436 LOW 3.1 Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints render user-supplied filenames … Apr 17, 2026
CVE-2026-33145 MEDIUM 6.3 xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary commands on the server due to unsafe … Apr 17, 2026
CVE-2026-23500 UNKNOWN Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion … Apr 17, 2026