CVE Vulnerability Database

Search and browse 1,874 known security vulnerabilities. Filter by severity, vendor, product, and year.

1,874 vulnerabilities found
CVE-2026-41572
5.3 medium

Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at /api/notes/{id}, /api/notes/{id}/content, the slug URL, and the asset endpoints. Unauthenticated callers who hold the note

May 4, 2026
CVE-2026-42080
4.6 medium

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary file write vulnerability via `save_generated_slides`. This issue has been patched via commit 418491a.

May 4, 2026
CVE-2026-42078
4.6 medium

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. This issue has been patched via commit 418491a.

May 4, 2026
CVE-2026-42077
5.2 medium

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious properties into Object.prototype. The vulnerability exists in

May 4, 2026
CVE-2026-38669
6.1 medium

wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog.

May 4, 2026
CVE-2026-25266
5.5 medium

Memory corruption while processing IOCTL command when device is in power-save state.

May 4, 2026
CVE-2025-47406
6.1 medium

Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.

May 4, 2026
CVE-2025-47404
6.5 medium

Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

May 4, 2026
CVE-2025-47403
6.5 medium

Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

May 4, 2026
CVE-2025-47401
6.5 medium

Transient DOS when processing target power rate tables during channel configuration.

May 4, 2026
CVE-2026-37458
6.5 medium

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.

May 4, 2026
CVE-2025-70071
5.9 medium

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()

May 4, 2026
CVE-2026-33523
6.5 medium

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Apache Http Server May 4, 2026
CVE-2026-33007
5.3 medium

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Apache Http Server May 4, 2026
CVE-2026-33006
4.8 medium

A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

Apache Http Server May 4, 2026
CVE-2025-70072
6.5 medium

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter::ConvertMeshMultiMaterial() components

May 4, 2026
CVE-2025-70070
6.5 medium

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()

May 4, 2026
CVE-2026-34032
5.3 medium

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Apache Http Server May 4, 2026
CVE-2026-33857
5.3 medium

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

Apache Http Server May 4, 2026
CVE-2026-31205
5.7 medium

Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function

May 4, 2026
CVE-2026-7746
6.3 medium

A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /product_expiry/edit-admin.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is pub

May 4, 2026
CVE-2026-7745
6.3 medium

A vulnerability was determined in CodeAstro Online Classroom 1.0. This impacts an unknown function of the file /OnlineClassroom/facultydetails. This manipulation of the argument deleteid causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and

May 4, 2026
CVE-2026-7744
6.3 medium

A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassroom/addnewstudent. The manipulation of the argument fname results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

May 4, 2026
CVE-2026-7743
6.3 medium

A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the file /OnlineClassroom/studentdetails. The manipulation of the argument deleteid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclos

May 4, 2026