| CVE-2016-20050 |
NetSchedScan 1.0 Buffer Overflow Denial of Service |
04.04.2026 |
|
| CVE-2016-20051 |
Snews CMS 1.7 Cross-Site Request Forgery via changeup |
04.04.2026 |
|
| CVE-2016-20052 |
Snews CMS 1.7 Unrestricted File Upload via snews_files |
04.04.2026 |
|
| CVE-2016-20053 |
Redaxo CMS 5.2 Cross-Site Request Forgery via users endpoint |
04.04.2026 |
|
| CVE-2016-20055 |
IObit Advanced SystemCare 10.0.2 Unquoted Service Path Privilege Escalation |
04.04.2026 |
|
| CVE-2016-20056 |
Spy Emergency build 23.0.205 Unquoted Service Path Privilege Escalation |
04.04.2026 |
|
| CVE-2016-20057 |
NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation |
04.04.2026 |
|
| CVE-2016-20058 |
Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation |
04.04.2026 |
|
| CVE-2016-20059 |
IObit Malware Fighter 4.3.1 Unquoted Service Path Privilege Escalation |
04.04.2026 |
|
| CVE-2016-20060 |
Hotspot Shield 6.0.3 Unquoted Service Path Privilege Escalation |
04.04.2026 |
|
| CVE-2016-20061 |
sheed AntiVirus 2.3 Unquoted Service Path Privilege Escalation |
04.04.2026 |
|
| CVE-2018-25238 |
Microsoft VSCO 1.1.1.0 Denial of Service via Search |
04.04.2026 |
|
| CVE-2018-25239 |
Microsoft Smart VPN 1.1.3.0 Denial of Service via Search |
04.04.2026 |
|
| CVE-2018-25240 |
Microsoft Watchr 1.1.0.0 Denial of Service via Search |
04.04.2026 |
|
| CVE-2018-25241 |
Microsoft VPN Browser+ 1.1.0.0 Denial of Service |
04.04.2026 |
|
| CVE-2018-25242 |
Microsoft One Search 1.1.0.0 Denial of Service |
04.04.2026 |
|
| CVE-2018-25243 |
Microsoft FastTube 1.0.1.0 Denial of Service via Search |
04.04.2026 |
|
| CVE-2018-25244 |
Microsoft Eco Search 1.0.2.0 Denial of Service |
04.04.2026 |
|
| CVE-2018-25245 |
Microsoft 7 Tik 1.0.1.0 Denial of Service via Search |
04.04.2026 |
|
| CVE-2018-25247 |
MyBB Like Plugin 3.0.0 Cross-Site Scripting via User Profiles |
04.04.2026 |
|
| CVE-2018-25248 |
MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php |
04.04.2026 |
|
| CVE-2018-25249 |
MyBB My Arcade Plugin 1.3 Persistent XSS via Comment |
04.04.2026 |
|
| CVE-2018-25250 |
MyBB Last User's Threads in Profile Plugin 1.2 Persistent XSS |
04.04.2026 |
|
| CVE-2018-25251 |
Snes9K 0.0.9z Buffer Overflow SEH via Netplay Socket |
04.04.2026 |
|
| CVE-2018-25252 |
FTP Voyager 16.2.0 Denial of Service via Malformed Site Profile |
04.04.2026 |
|
| CVE-2018-25253 |
Termite 3.4 Denial of Service via Settings Buffer Overflow |
04.04.2026 |
|
| CVE-2018-25254 |
NICO-FTP 3.0.1.19 Buffer Overflow SEH |
04.04.2026 |
|
| CVE-2018-25255 |
10-Strike LANState 8.8 Local Buffer Overflow SEH |
04.04.2026 |
|
| CVE-2025-14938 |
Listeo-Core - Directory Plugin by Purethemes <= 2.0.27 - Unauthenticated Arbitrary Media Upload |
04.04.2026 |
5.3 |
| CVE-2026-0626 |
WPFunnels <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpf_optin_form' Shortcode |
04.04.2026 |
6.4 |
| CVE-2026-1233 |
Text to Speech (TTS) by Mementor <= 1.9.8 - Use of Hardcoded Password to Unauthenticated Remote Database Access |
04.04.2026 |
7.5 |
| CVE-2026-2936 |
Visitor Traffic Real Time Statistics <= 8.4 - Unauthenticated Stored Cross-Site Scripting |
04.04.2026 |
7.2 |
| CVE-2026-3309 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields |
04.04.2026 |
6.5 |
| CVE-2026-3666 |
wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body |
04.04.2026 |
8.8 |
| CVE-2026-2437 |
WP Travel Engine - Travel and Tour Booking Plugin <= 6.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via wte_trip_tax Shortcode |
04.04.2026 |
6.4 |
| CVE-2026-2826 |
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor <= 3.6.3 - Missing Authorization to Authenticated (Contributor+) Media Upload |
04.04.2026 |
4.3 |
| CVE-2026-3445 |
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass |
04.04.2026 |
7.1 |
| CVE-2026-5425 |
Widgets for Social Photo Feed <= 1.7.9 - Unauthenticated Stored Cross-Site Scripting via feed_data |
04.04.2026 |
7.2 |
| CVE-2025-13368 |
Xpro Addons — 140+ Widgets for Elementor <= 1.4.20 - Authenticated (Contributor+) Stored Cross-Site Scripting |
04.04.2026 |
6.4 |
| CVE-2025-15064 |
Ultimate Member <= 2.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via DOM Gadgets |
04.04.2026 |
6.4 |
| CVE-2026-0552 |
Simple Shopping Cart <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsc_display_product' Shortcode |
04.04.2026 |
6.4 |
| CVE-2026-0664 |
Royal Elementor Addons <= 1.7.1049 - Authenticated (Contributor+) Stored Cross-Site Scripting via REST API Meta Bypass |
04.04.2026 |
6.4 |
| CVE-2026-0737 |
Shortcodes Ultimate <= 7.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'su_lightbox' Shortcode |
04.04.2026 |
6.4 |
| CVE-2026-0738 |
Shortcodes Ultimate <= 7.4.8 - authenticated (Contributor+) Stored Cross-Site Scripting via 'su_carousel' Shortcode |
04.04.2026 |
6.4 |
| CVE-2026-2600 |
ElementsKit Elementor Addons and Templates <= 3.7.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Simple Tab Widget |
04.04.2026 |
6.4 |
| CVE-2026-4896 |
WCFM - WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation |
04.04.2026 |
8.1 |
| CVE-2026-2924 |
Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'imageLoad' |
04.04.2026 |
6.4 |
| CVE-2026-2949 |
Xpro Addons — 140+ Widgets for Elementor <= 1.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Box Widget |
04.04.2026 |
6.4 |
| CVE-2026-3571 |
Pie Register – User Registration, Profiles & Content Restriction <= 3.8.4.8 - Missing Authorization to Unauthenticated Registration Form Status Modification |
04.04.2026 |
6.5 |
| CVE-2026-34780 |
Electron: Context Isolation bypass via contextBridge VideoFrame transfer |
04.04.2026 |
8.4 |
| CVE-2026-35616 |
|
04.04.2026 |
9.1 |
| CVE-2026-34773 |
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows |
03.04.2026 |
4.7 |
| CVE-2026-34774 |
Electron: Use-after-free in offscreen child window paint callback |
03.04.2026 |
8.1 |
| CVE-2026-34775 |
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes |
03.04.2026 |
6.8 |
| CVE-2026-34776 |
Electron: Out-of-bounds read in second-instance IPC on macOS and Linux |
03.04.2026 |
5.3 |
| CVE-2026-34777 |
Electron: Incorrect origin passed to permission request handler for iframe requests |
03.04.2026 |
5.4 |
| CVE-2026-34778 |
Electron: Service worker can spoof executeJavaScript IPC replies |
03.04.2026 |
5.9 |
| CVE-2026-34779 |
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS |
04.04.2026 |
6.5 |
| CVE-2026-34766 |
Electron: USB device selection not validated against filtered device list |
03.04.2026 |
3.3 |
| CVE-2026-34767 |
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest |
03.04.2026 |
5.9 |
| CVE-2026-34768 |
Electron: Unquoted executable path in app.setLoginItemSettings on Windows |
03.04.2026 |
3.9 |
| CVE-2026-34770 |
Electron: Use-after-free in PowerMonitor on Windows and macOS |
03.04.2026 |
7 |
| CVE-2026-34771 |
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks |
03.04.2026 |
7.5 |
| CVE-2026-34772 |
Electron: Use-after-free in download save dialog callback |
03.04.2026 |
5.8 |
| CVE-2026-34769 |
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference |
03.04.2026 |
7.8 |
| CVE-2026-34955 |
PraisonAI: Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandbox |
03.04.2026 |
8.8 |
| CVE-2017-20235 |
ProSoft Technology ICX35-HWC Authentication Bypass |
03.04.2026 |
8.8 |
| CVE-2017-20236 |
ProSoft Technology ICX35-HWC Command Injection via Web Interface |
03.04.2026 |
9.8 |
| CVE-2026-34936 |
PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback |
03.04.2026 |
7.7 |
| CVE-2026-34937 |
PraisonAI: Shell Injection in run_python() via Unescaped $() Substitution |
03.04.2026 |
7.8 |
| CVE-2026-34938 |
PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code |
03.04.2026 |
10 |
| CVE-2026-34939 |
PraisonAI: ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools() |
03.04.2026 |
6.5 |
| CVE-2026-34952 |
PraisonAI: Missing Authentication in WebSocket Gateway |
03.04.2026 |
9.1 |
| CVE-2026-34953 |
PraisonAI: Authentication Bypass in OAuthManager.validate_token() |
03.04.2026 |
9.1 |
| CVE-2026-34954 |
PraisonAI: SSRF in FileTools.download_file() via Unvalidated URL |
03.04.2026 |
8.6 |
| CVE-2017-20233 |
Hirschmann HiLCOS Layer-2 Firewall Multicast Broadcast Traffic Bypass |
03.04.2026 |
5.4 |
| CVE-2017-20234 |
GarrettCom Magnum 6K and 10K Authentication Bypass via Hardcoded String |
03.04.2026 |
9.8 |
| CVE-2018-25236 |
Hirschmann HiOS HiSecOS Authentication Bypass via HTTP Management |
03.04.2026 |
9.8 |
| CVE-2021-4477 |
Hirschmann HiLCOS OpenBAT BAT450 IPv6 IPsec Firewall Bypass |
03.04.2026 |
|
| CVE-2026-34229 |
Emlog: Stored XSS in Comment Module via URI Scheme Validation Bypass |
03.04.2026 |
6.1 |
| CVE-2026-34607 |
Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE |
03.04.2026 |
7.2 |
| CVE-2026-34612 |
Kestra: Remote Code Execution via SQL Injection |
03.04.2026 |
10 |
| CVE-2026-34787 |
Emlog: Local File Inclusion in plugin.php via unsanitized plugin parameter |
03.04.2026 |
6.5 |
| CVE-2026-34788 |
Emlog: SQL Injection in tag_model::updateTagName() via unsanitized parameters |
03.04.2026 |
6.5 |
| CVE-2026-34824 |
Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service |
03.04.2026 |
7.5 |
| CVE-2026-34933 |
Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon |
03.04.2026 |
5.5 |
| CVE-2026-34934 |
PraisonAI: Second-Order SQL Injection in `get_all_user_threads` |
03.04.2026 |
9.8 |
| CVE-2026-34935 |
PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command() |
03.04.2026 |
9.8 |
| CVE-2026-34228 |
Emlog: CSRF in Backend Upgrade Interface Leading to Arbitrary Remote SQL Execution and Arbitrary File Write |
03.04.2026 |
|
| CVE-2017-20238 |
Hirschmann Industrial HiVision Improper Authorization Privilege Escalation |
03.04.2026 |
7.1 |
| CVE-2026-33184 |
nimiq/core-rs-albatross: Discovery handshake limit could underflow and later provoke a deterministic overflow panic |
03.04.2026 |
7.5 |
| CVE-2026-34052 |
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service) |
03.04.2026 |
5.9 |
| CVE-2026-34061 |
nimiq/core-rs-albatross: Macro block proposal interlink bug |
03.04.2026 |
4.9 |
| CVE-2026-35468 |
nimiq/core-rs-albatross: Panic in history index request handlers when a full node runs without the history index |
03.04.2026 |
5.3 |
| CVE-2016-15058 |
Hirschmann HiLCOS Classic Platform Password Exposure via SNMP |
03.04.2026 |
8.1 |
| CVE-2026-33175 |
OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claims |
03.04.2026 |
8.8 |
| CVE-2026-33709 |
JupyterHub has an Open Redirect Vulnerability |
03.04.2026 |
|
| CVE-2015-10148 |
Hirschmann HiLCOS Hard-coded Credentials SSH SSL Keys |
03.04.2026 |
7.5 |
| CVE-2026-27885 |
Piwigo: SQL Injection in Activity.getList |
03.04.2026 |
7.2 |
| CVE-2026-28797 |
RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component |
03.04.2026 |
|
| CVE-2018-25237 |
Hirschmann HiSecOS Buffer Overflow via HTTPS Login |
03.04.2026 |
9.8 |
| CVE-2026-27456 |
util-linux: TOCTOU Race Condition in util-linux mount(8) - Loop Device Setup |
03.04.2026 |
4.7 |
| CVE-2026-27481 |
Discourse: Hidden tag visibility bypass on tag routes |
03.04.2026 |
|
| CVE-2026-27634 |
Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter |
03.04.2026 |
|
| CVE-2026-27833 |
Piwigo: Unauthenticated Information Disclosure via pwg.history.search API |
03.04.2026 |
7.5 |
| CVE-2026-27834 |
Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameter |
03.04.2026 |
7.2 |
| CVE-2026-34947 |
Discourse: Staged user custom fields are exposed on public invite pages |
03.04.2026 |
|
| CVE-2026-27447 |
OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup |
03.04.2026 |
4.8 |
| CVE-2026-34978 |
OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) |
03.04.2026 |
6.5 |
| CVE-2026-34979 |
OpenPrinting CUPS: Heap overflow in `get_options()` |
03.04.2026 |
5.3 |
| CVE-2026-34980 |
OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network |
03.04.2026 |
|
| CVE-2026-34990 |
OpenPrinting CUPS: Local print admin token disclosure using temporary printers |
03.04.2026 |
|
| CVE-2017-20237 |
Hirschmann Industrial HiVision Authentication Bypass Remote Code Execution |
03.04.2026 |
9.8 |
| CVE-2026-26058 |
Zulip: Path Traversal in Import |
03.04.2026 |
6.1 |
| CVE-2026-34511 |
OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter |
03.04.2026 |
|
| CVE-2025-10681 |
Gardyn Mobile Application and Device Firmware Use Hard-coded Credentials |
03.04.2026 |
|
| CVE-2026-22661 |
prompts.chat Path Traversal via Skill File Handling |
03.04.2026 |
|
| CVE-2026-22662 |
prompts.chat Blind SSRF via media-generate |
03.04.2026 |
|
| CVE-2026-22663 |
prompts.chat Authorization Bypass Information Disclosure |
03.04.2026 |
|
| CVE-2026-22664 |
prompts.chat SSRF via Fal.ai Media Status Polling |
03.04.2026 |
|
| CVE-2026-22665 |
prompts.chat Identity Confusion via Case-Sensitive Username Handling |
03.04.2026 |
|
| CVE-2026-25197 |
Gardyn Cloud API Authorization Bypass Through User-Controlled Key |
03.04.2026 |
|
| CVE-2026-28766 |
Gardyn Cloud API Missing Authentication for Critical Function |
03.04.2026 |
|
| CVE-2020-37216 |
Hirschmann HiOS EtherNet/IP Stack Denial of Service |
04.04.2026 |
7.5 |
| CVE-2022-4987 |
Hirschmann Industrial HiVision External Application Path Hijacking Leading to Arbitrary Code Execution |
03.04.2026 |
7.3 |
| CVE-2026-25742 |
Zulip: Anonymous File Access After Disabling Spectator Access |
03.04.2026 |
5.3 |
| CVE-2026-28767 |
Gardyn Cloud API Missing Authentication for Critical Function |
03.04.2026 |
|
| CVE-2026-32646 |
Gardyn Cloud API Missing Authentication for Critical Function |
03.04.2026 |
|
| CVE-2026-32662 |
Gardyn Cloud API Active Debug Code |
03.04.2026 |
|
| CVE-2026-35558 |
Improper neutralization of special elements in authentication components in Amazon Athena ODBC driver |
03.04.2026 |
7.8 |
| CVE-2026-35559 |
Out-of-bounds write in query processing components in Amazon Athena ODBC driver |
03.04.2026 |
6.5 |
| CVE-2026-35560 |
Improper certificate validation in identity provider connection components in Amazon Athena ODBC driver |
03.04.2026 |
7.4 |
| CVE-2026-35561 |
Insufficient authentication security controls in browser-based authentication components in Amazon Athena ODBC driver |
03.04.2026 |
7.4 |
| CVE-2026-35562 |
Allocation of resources without limits in parsing components in Amazon Athena ODBC driver |
03.04.2026 |
7.5 |
| CVE-2026-5485 |
OS command injection in Amazon Athena ODBC driver on Linux |
03.04.2026 |
7.8 |