Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

29082
Total
2258
Critical
8681
High
9062
Medium
CVE ID Severity Score Description Published
CVE-2026-41145 UNKNOWN MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's `STREAMING-UNSIGNED-PAYLOAD-TRAILER` code path allows any … Apr 22, 2026
CVE-2026-40344 UNKNOWN MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's Snowball auto-extract handler (`PutObjectExtractHandler`) allows … Apr 22, 2026
CVE-2026-41304 UNKNOWN WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled … Apr 22, 2026
CVE-2026-41144 NONE F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check … Apr 22, 2026
CVE-2026-41136 UNKNOWN free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version … Apr 22, 2026
CVE-2026-41135 HIGH 7.5 free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. A memory leak vulnerability … Apr 22, 2026
CVE-2026-41133 HIGH 8.8 pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at … Apr 22, 2026
CVE-2026-41131 MEDIUM 5.0 OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, models using conditions with caching enabled can result in two … Apr 22, 2026
CVE-2026-41130 UNKNOWN Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint … Apr 22, 2026
CVE-2026-41129 UNKNOWN Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side … Apr 22, 2026
CVE-2026-41128 UNKNOWN Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove … Apr 22, 2026
CVE-2026-41127 MEDIUM 6.5 BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions … Apr 22, 2026
CVE-2026-41126 MEDIUM 4.3 BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling … Apr 22, 2026
CVE-2026-41064 CRITICAL 9.3 WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget … Apr 22, 2026
CVE-2026-41059 HIGH 8.2 OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when … Apr 22, 2026
CVE-2026-40575 CRITICAL 9.1 OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is … Apr 22, 2026
CVE-2026-40343 UNKNOWN free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. In versions up to … Apr 22, 2026
CVE-2026-5921 UNKNOWN A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract sensitive environment variables from the instance through … Apr 21, 2026
CVE-2026-5845 UNKNOWN An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attacker to access private repositories outside the intended … Apr 21, 2026
CVE-2026-5512 UNKNOWN An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to determine the names of private repositories by their numeric … Apr 21, 2026
CVE-2026-4872 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Apr 21, 2026
CVE-2026-4821 UNKNOWN An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Management Console administrator to execute arbitrary OS commands … Apr 21, 2026
CVE-2026-4296 UNKNOWN An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth redirect URI validation. An attacker with knowledge … Apr 21, 2026
CVE-2026-41063 MEDIUM 5.4 WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw … Apr 21, 2026
CVE-2026-41062 MEDIUM 6.5 WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVideoEncoderReceiveImage.json.php` only checks … Apr 21, 2026