Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

29232
Total
2268
Critical
8711
High
9096
Medium
CVE ID Severity Score Description Published
CVE-2026-40903 CRITICAL 9.1 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow … Apr 21, 2026
CVE-2026-40890 HIGH 7.5 The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is … Apr 21, 2026
CVE-2026-40889 MEDIUM 6.5 Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authenticated users can access unauthorized files by exploiting certain … Apr 21, 2026
CVE-2026-40888 MEDIUM 6.5 Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authenticated user with default role can access unauthorized … Apr 21, 2026
CVE-2026-40887 CRITICAL 9.1 Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists … Apr 21, 2026
CVE-2026-40885 UNKNOWN goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is … Apr 21, 2026
CVE-2026-40884 CRITICAL 9.8 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If … Apr 21, 2026
CVE-2026-40883 UNKNOWN goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An … Apr 21, 2026
CVE-2026-40881 UNKNOWN ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which … Apr 21, 2026
CVE-2026-40880 UNKNOWN ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification … Apr 21, 2026
CVE-2026-40879 HIGH 7.5 Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends many small, valid JSON messages in one TCP … Apr 21, 2026
CVE-2026-40878 UNKNOWN mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow web interface passes the raw `$_SERVER['REQUEST_URI']` to … Apr 21, 2026
CVE-2026-40876 UNKNOWN goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user … Apr 21, 2026
CVE-2026-40875 UNKNOWN mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful connections" (login history) renders … Apr 21, 2026
CVE-2026-40874 UNKNOWN mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administrator verification takes place when deleting Forwarding Hosts … Apr 21, 2026
CVE-2026-40873 UNKNOWN mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quarantine details modal injects attachment filenames into HTML … Apr 21, 2026
CVE-2026-40872 UNKNOWN mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover logs render the EMailAddress value … Apr 21, 2026
CVE-2026-40871 HIGH 7.2 mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerability in the quarantine_category field … Apr 21, 2026
CVE-2026-40870 HIGH 7.5 Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the root level `commentable` field in the API … Apr 21, 2026
CVE-2026-40869 HIGH 7.5 Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user … Apr 21, 2026
CVE-2026-40372 CRITICAL 9.1 Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. Apr 21, 2026
CVE-2026-33813 HIGH 7.5 Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. Apr 21, 2026
CVE-2026-33812 MEDIUM 6.1 Parsing a malicious font file can cause excessive memory allocation. Apr 21, 2026
CVE-2026-6745 LOW 3.5 A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation … Apr 21, 2026
CVE-2026-6744 MEDIUM 6.3 A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side … Apr 21, 2026