Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
30355
Total
2427
Critical
9086
High
9450
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-41475 | UNKNOWN | — | BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service … | Apr 24, 2026 |
| CVE-2026-41433 | HIGH | 8.4 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java agent injection path allows … | Apr 24, 2026 |
| CVE-2026-41429 | HIGH | 8.8 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, there is a remotely reachable memory corruption … | Apr 24, 2026 |
| CVE-2026-41428 | CRITICAL | 9.1 | Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against ctx.request.url. Since … | Apr 24, 2026 |
| CVE-2026-41427 | UNKNOWN | — | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but the OAuth client creation … | Apr 24, 2026 |
| CVE-2026-41426 | MEDIUM | 6.1 | pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered emails from a pretalx instance's configured sender address by … | Apr 24, 2026 |
| CVE-2026-41425 | MEDIUM | 5.4 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in … | Apr 24, 2026 |
| CVE-2026-41244 | MEDIUM | 4.7 | Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard … | Apr 24, 2026 |
| CVE-2026-41907 | UNKNOWN | — | uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject … | Apr 24, 2026 |
| CVE-2026-41894 | UNKNOWN | — | SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePath) but did not address … | Apr 24, 2026 |
| CVE-2026-41492 | CRITICAL | 9.8 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because … | Apr 24, 2026 |
| CVE-2026-41421 | HIGH | 8.8 | SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification … | Apr 24, 2026 |
| CVE-2026-41419 | HIGH | 7.6 | 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board import privileges … | Apr 24, 2026 |
| CVE-2026-41418 | MEDIUM | 5.3 | 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumeration via a timing side-channel in … | Apr 24, 2026 |
| CVE-2026-41416 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer overflow in media stream … | Apr 24, 2026 |
| CVE-2026-41415 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a … | Apr 24, 2026 |
| CVE-2026-41414 | HIGH | 7.4 | Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.yml checks out attacker-controlled fork code and executes it … | Apr 24, 2026 |
| CVE-2026-41328 | CRITICAL | 9.1 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read … | Apr 24, 2026 |
| CVE-2026-41327 | CRITICAL | 9.1 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read … | Apr 24, 2026 |
| CVE-2026-41326 | UNKNOWN | — | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, … | Apr 24, 2026 |
| CVE-2026-33666 | HIGH | 7.5 | Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, in BitStreamReader.h readBytes() / readString(), … | Apr 24, 2026 |
| CVE-2026-33662 | HIGH | 7.5 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. From … | Apr 24, 2026 |
| CVE-2026-33524 | HIGH | 7.5 | Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small … | Apr 24, 2026 |
| CVE-2026-42044 | MEDIUM | 6.5 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype … | Apr 24, 2026 |
| CVE-2026-42043 | HIGH | 7.2 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL … | Apr 24, 2026 |