Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34313
Total
2675
Critical
10128
High
10348
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-5253 | LOW | 3.5 | A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component editNotice … | Apr 01, 2026 |
| CVE-2026-5252 | LOW | 3.5 | A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. … | Apr 01, 2026 |
| CVE-2026-5251 | MEDIUM | 6.3 | A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation … | Apr 01, 2026 |
| CVE-2026-5249 | LOW | 3.5 | A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of … | Apr 01, 2026 |
| CVE-2026-4947 | HIGH | 7.1 | Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could have allowed an attacker … | Apr 01, 2026 |
| CVE-2026-4374 | UNKNOWN | — | Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Routing Service,Observability Collector,Recording Service,Queueing Service,Cloud Discovery Service) allows Serialized Data External Linking, Data … | Apr 01, 2026 |
| CVE-2026-3831 | MEDIUM | 4.3 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check … | Apr 01, 2026 |
| CVE-2026-3780 | HIGH | 7.3 | The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local … | Apr 01, 2026 |
| CVE-2026-3779 | HIGH | 7.8 | The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents … | Apr 01, 2026 |
| CVE-2026-3778 | MEDIUM | 6.2 | The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pages and annotations are crafted that reference … | Apr 01, 2026 |
| CVE-2026-3777 | MEDIUM | 5.5 | The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When … | Apr 01, 2026 |
| CVE-2026-3776 | MEDIUM | 5.5 | The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resources. When a PDF contains a stamp annotation missing … | Apr 01, 2026 |
| CVE-2026-3775 | HIGH | 7.8 | The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is … | Apr 01, 2026 |
| CVE-2026-3774 | MEDIUM | 4.7 | The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after … | Apr 01, 2026 |
| CVE-2026-5248 | MEDIUM | 6.3 | A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation … | Apr 01, 2026 |
| CVE-2026-35057 | MEDIUM | 6.4 | XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker … | Apr 01, 2026 |
| CVE-2026-35056 | HIGH | 7.2 | XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute … | Apr 01, 2026 |
| CVE-2026-35055 | MEDIUM | 6.1 | XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that … | Apr 01, 2026 |
| CVE-2026-35054 | MEDIUM | 6.4 | XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that … | Apr 01, 2026 |
| CVE-2026-2394 | UNKNOWN | — | Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from … | Apr 01, 2026 |
| CVE-2025-71282 | HIGH | 7.5 | XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This allows an attacker to obtain information about the server's directory structure. | Apr 01, 2026 |
| CVE-2025-71281 | HIGH | 8.8 | XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-word match for … | Apr 01, 2026 |
| CVE-2025-71280 | MEDIUM | 6.2 | XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where multiple users share a browser or machine, cached … | Apr 01, 2026 |
| CVE-2025-71279 | CRITICAL | 9.8 | XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security … | Apr 01, 2026 |
| CVE-2025-71278 | HIGH | 8.8 | XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using OAuth2 clients on any version of XenForo 2.3 prior … | Apr 01, 2026 |