Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

30887
Total
2440
Critical
9124
High
9492
Medium
CVE ID Severity Score Description Published
CVE-2026-35074 MEDIUM 6.7 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of … Apr 17, 2026
CVE-2026-35073 MEDIUM 6.7 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of … Apr 17, 2026
CVE-2026-35072 MEDIUM 6.7 Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of … Apr 17, 2026
CVE-2026-23779 MEDIUM 6.7 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 … Apr 17, 2026
CVE-2026-23776 HIGH 7.2 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 … Apr 17, 2026
CVE-2026-6494 MEDIUM 5.3 A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to … Apr 17, 2026
CVE-2026-6439 MEDIUM 4.4 The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. This is due to insufficient input sanitization … Apr 17, 2026
CVE-2026-23778 HIGH 7.2 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 … Apr 17, 2026
CVE-2026-23775 HIGH 7.6 Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 … Apr 17, 2026
CVE-2025-36568 HIGH 7.8 Dell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through … Apr 17, 2026
CVE-2025-15625 UNKNOWN Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. Apr 17, 2026
CVE-2025-15624 UNKNOWN Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID is used as the primary … Apr 17, 2026
CVE-2025-15623 UNKNOWN Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty … Apr 17, 2026
CVE-2025-15622 UNKNOWN Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the … Apr 17, 2026
CVE-2026-6451 MEDIUM 4.3 The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation … Apr 17, 2026
CVE-2026-40002 MEDIUM 5.0 Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for … Apr 17, 2026
CVE-2026-33392 HIGH 7.2 In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass Apr 17, 2026
CVE-2026-23853 HIGH 8.4 Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 … Apr 17, 2026
CVE-2026-6443 CRITICAL 9.8 The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold … Apr 17, 2026
CVE-2026-6441 MEDIUM 4.3 The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any … Apr 17, 2026
CVE-2026-4659 HIGH 7.5 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and … Apr 17, 2026
CVE-2026-6482 UNKNOWN The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a … Apr 17, 2026
CVE-2026-6421 HIGH 7.0 A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads … Apr 17, 2026
CVE-2026-5797 MEDIUM 5.3 The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to … Apr 17, 2026
CVE-2026-35496 LOW 2.7 A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privilege to access higher-level directories that should … Apr 17, 2026