Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29082
Total
2258
Critical
8681
High
9062
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-41145 | UNKNOWN | — | MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's `STREAMING-UNSIGNED-PAYLOAD-TRAILER` code path allows any … | Apr 22, 2026 |
| CVE-2026-40344 | UNKNOWN | — | MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's Snowball auto-extract handler (`PutObjectExtractHandler`) allows … | Apr 22, 2026 |
| CVE-2026-41304 | UNKNOWN | — | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled … | Apr 22, 2026 |
| CVE-2026-41144 | NONE | — | F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check … | Apr 22, 2026 |
| CVE-2026-41136 | UNKNOWN | — | free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version … | Apr 22, 2026 |
| CVE-2026-41135 | HIGH | 7.5 | free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. A memory leak vulnerability … | Apr 22, 2026 |
| CVE-2026-41133 | HIGH | 8.8 | pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at … | Apr 22, 2026 |
| CVE-2026-41131 | MEDIUM | 5.0 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two … | Apr 22, 2026 |
| CVE-2026-41130 | UNKNOWN | — | Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint … | Apr 22, 2026 |
| CVE-2026-41129 | UNKNOWN | — | Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side … | Apr 22, 2026 |
| CVE-2026-41128 | UNKNOWN | — | Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove … | Apr 22, 2026 |
| CVE-2026-41127 | MEDIUM | 6.5 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions … | Apr 22, 2026 |
| CVE-2026-41126 | MEDIUM | 4.3 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling … | Apr 22, 2026 |
| CVE-2026-41064 | CRITICAL | 9.3 | WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget … | Apr 22, 2026 |
| CVE-2026-41059 | HIGH | 8.2 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when … | Apr 22, 2026 |
| CVE-2026-40575 | CRITICAL | 9.1 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is … | Apr 22, 2026 |
| CVE-2026-40343 | UNKNOWN | — | free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to … | Apr 22, 2026 |
| CVE-2026-5921 | UNKNOWN | — | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through … | Apr 21, 2026 |
| CVE-2026-5845 | UNKNOWN | — | An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended … | Apr 21, 2026 |
| CVE-2026-5512 | UNKNOWN | — | An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric … | Apr 21, 2026 |
| CVE-2026-4872 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Apr 21, 2026 |
| CVE-2026-4821 | UNKNOWN | — | An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Management Console administrator to execute arbitrary OS commands … | Apr 21, 2026 |
| CVE-2026-4296 | UNKNOWN | — | An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge … | Apr 21, 2026 |
| CVE-2026-41063 | MEDIUM | 5.4 | WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw … | Apr 21, 2026 |
| CVE-2026-41062 | MEDIUM | 6.5 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVideoEncoderReceiveImage.json.php` only checks … | Apr 21, 2026 |