Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
12686
Total
851
Critical
3660
High
3983
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-6296 | CRITICAL | 9.6 | Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … | Apr 15, 2026 |
| CVE-2026-40919 | MEDIUM | 6.1 | A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a specially crafted … | Apr 15, 2026 |
| CVE-2026-40918 | MEDIUM | 5.5 | A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This … | Apr 15, 2026 |
| CVE-2026-40917 | MEDIUM | 5.0 | A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS image files. An … | Apr 15, 2026 |
| CVE-2026-40916 | MEDIUM | 5.0 | A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause … | Apr 15, 2026 |
| CVE-2026-40915 | MEDIUM | 5.5 | A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted … | Apr 15, 2026 |
| CVE-2026-39857 | MEDIUM | 5.3 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameters of … | Apr 15, 2026 |
| CVE-2026-35569 | HIGH | 8.7 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in SEO-related fields (SEO Title and Meta … | Apr 15, 2026 |
| CVE-2026-33889 | MEDIUM | 5.4 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site scripting vulnerability in the @apostrophecms/color-field module, where color values … | Apr 15, 2026 |
| CVE-2026-33888 | MEDIUM | 5.3 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the getRestQuery method of the @apostrophecms/piece-type module, … | Apr 15, 2026 |
| CVE-2026-33877 | LOW | 3.7 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-channel vulnerability in the password reset endpoint (/api/v1/@apostrophecms/login/reset-request) that allows … | Apr 15, 2026 |
| CVE-2026-21727 | LOW | 3.3 | --- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero: image: /static/img/heros/hero-legal2.svg content: "# Cross-Tenant Legacy Correlation Disclosure and Deletion" date: 2026-01-29 product: Grafana … | Apr 15, 2026 |
| CVE-2026-21726 | MEDIUM | 5.3 | The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at … | Apr 15, 2026 |
| CVE-2025-41118 | CRITICAL | 9.1 | Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to … | Apr 15, 2026 |
| CVE-2026-6383 | MEDIUM | 5.4 | A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly truncates subresource names, leading to incorrect permission evaluations. This … | Apr 15, 2026 |
| CVE-2026-6245 | MEDIUM | 5.5 | A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to properly handle raw bytes … | Apr 15, 2026 |
| CVE-2026-5189 | UNKNOWN | — | CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write … | Apr 15, 2026 |
| CVE-2026-4857 | HIGH | 8.4 | IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned … | Apr 15, 2026 |
| CVE-2026-40256 | MEDIUM | 5.0 | Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple … | Apr 15, 2026 |
| CVE-2026-39845 | MEDIUM | 4.1 | Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been … | Apr 15, 2026 |
| CVE-2026-34632 | HIGH | 8.2 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the … | Apr 15, 2026 |
| CVE-2026-34393 | HIGH | 8.8 | Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This … | Apr 15, 2026 |
| CVE-2026-34244 | MEDIUM | 5.0 | Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can … | Apr 15, 2026 |
| CVE-2026-34242 | HIGH | 7.7 | Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the … | Apr 15, 2026 |
| CVE-2026-33667 | HIGH | 7.4 | OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the confirm_otp action of the two_factor_authentication module has no … | Apr 15, 2026 |