Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28561
Total
2193
Critical
8548
High
8866
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-1952 | CRITICAL | 9.8 | Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability. | Apr 24, 2026 |
| CVE-2026-1951 | CRITICAL | 9.8 | Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability. | Apr 24, 2026 |
| CVE-2026-1950 | CRITICAL | 9.8 | Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability. | Apr 24, 2026 |
| CVE-2026-6810 | MEDIUM | 5.3 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the … | Apr 24, 2026 |
| CVE-2026-5428 | MEDIUM | 6.4 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to … | Apr 24, 2026 |
| CVE-2026-5364 | HIGH | 8.1 | The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, … | Apr 24, 2026 |
| CVE-2026-5347 | MEDIUM | 5.3 | The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence … | Apr 24, 2026 |
| CVE-2026-1949 | CRITICAL | 9.8 | Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service. | Apr 24, 2026 |
| CVE-2026-6947 | HIGH | 7.5 | DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform … | Apr 24, 2026 |
| CVE-2026-6393 | MEDIUM | 4.3 | The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check … | Apr 24, 2026 |
| CVE-2026-5488 | MEDIUM | 5.3 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is … | Apr 24, 2026 |
| CVE-2026-41485 | HIGH | 7.7 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` … | Apr 24, 2026 |
| CVE-2026-41430 | UNKNOWN | — | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect parameter on login page is vulnerable to reflected … | Apr 24, 2026 |
| CVE-2026-41324 | HIGH | 7.5 | basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings … | Apr 24, 2026 |
| CVE-2026-41323 | HIGH | 8.1 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically … | Apr 24, 2026 |
| CVE-2026-41319 | MEDIUM | 6.5 | MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle … | Apr 24, 2026 |
| CVE-2026-41318 | MEDIUM | 5.4 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, AnythingLLM's … | Apr 24, 2026 |
| CVE-2026-41068 | HIGH | 7.7 | Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's `apiCall` context by … | Apr 24, 2026 |
| CVE-2026-2028 | MEDIUM | 5.3 | The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi_remove_custom_image_size' AJAX action in … | Apr 24, 2026 |
| CVE-2026-41317 | UNKNOWN | — | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is prone to CSRF-like exploits. This endpoint writes to … | Apr 24, 2026 |
| CVE-2026-41316 | HIGH | 8.1 | ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and … | Apr 24, 2026 |
| CVE-2026-41309 | HIGH | 8.2 | Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can … | Apr 24, 2026 |
| CVE-2026-41305 | MEDIUM | 6.1 | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions … | Apr 24, 2026 |
| CVE-2026-40254 | MEDIUM | 4.2 | FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/drive_file.c`. The … | Apr 24, 2026 |
| CVE-2026-33318 | HIGH | 8.8 | Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from … | Apr 24, 2026 |