Common Vulnerabilities and Exposures (CVE)

CVE-2026-5258

Apr 1, 2026 19:05:54 UTC

A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the component File Manager. Performing a manipulation of the argument filename results in path traver...

CVE-2026-5253

Apr 1, 2026 19:05:29 UTC

A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component editNotice Endpoint. Executing a manipulatio...

CVE-2026-35056

Apr 1, 2026 19:04:59 UTC

XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users. An attacker with admin panel access can execute arbitrary code on the server.

CVE-2026-22767

Apr 1, 2026 19:04:27 UTC

Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

CVE-2024-0874

Apr 1, 2026 19:04:01 UTC

A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.

CVE-2025-13535

Apr 1, 2026 19:03:57 UTC

The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is due to insufficient input sanitization an...

CVE-2023-6717

Apr 1, 2026 19:03:55 UTC

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue...

CVE-2026-5240

Apr 1, 2026 19:03:08 UTC

A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads to cross site scripting. It is possible t...

CVE-2026-34556

Apr 1, 2026 19:02:37 UTC

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a heap-buffer-overflow (HBO) in icAnsiToUtf8() in the XML conversion path. The issue is triggered by a crafted I...

CVE-2026-34552

Apr 1, 2026 19:01:26 UTC

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) issue in IccTagLut.cpp where the code performs member access through a null pointer o...

CVE-2026-34548

Apr 1, 2026 19:00:50 UTC

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in the XML conversion tooling path (iccToXml) caused by an implicit convers...

CVE-2026-30291

Apr 1, 2026 19:00:35 UTC

An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

CVE-2025-71279

Apr 1, 2026 19:00:09 UTC

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.

CVE-2026-34536

Apr 1, 2026 18:58:47 UTC

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a stack overflow (SO) in SIccCalcOp::ArgsUsed(). The issue is observable under AddressS...

CVE-2026-34605

Apr 1, 2026 18:57:40 UTC

SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to fix XSS in the unauthenticated /api/icon/getDynamicIcon endpoint can be bypassed by using ...