Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 12 April 2026

RSS

157 vulnerabilities published on 12 April 2026

Severity:
Mozilla Thunderbird Security Update: Multiple Critical Fixes
RLSA-2026:6917
Mozilla Thunderbird has released an update to fix several critical security issues that could allow attackers to take control of your computer, steal sensitive information, or disrupt your email and b...
8.2
1Panel-dev MaxKB: Remote Code Execution in MCP Node
CVE-2026-6108
An attacker can execute arbitrary system commands on a vulnerable system using the 1Panel-dev MaxKB MCP Node, which can lead to unauthorized access and data theft. This vulnerability allows an attacke...
5.3
MetaGPT Mineflayer API Cross-Site Request Forgery Risk
CVE-2026-6109
The MetaGPT Mineflayer API, used in Minecraft bots, has a security flaw that makes it vulnerable to a type of attack where an attacker can trick the system into performing unwanted actions. This could...
5.3
1Panel-dev MaxKB Chat Headers Middleware Cross-Site Scripting Risk
CVE-2026-6107
A security flaw in 1Panel-dev MaxKB's chat headers middleware can allow attackers to inject malicious code, potentially allowing them access to sensitive information or taking control of user sessions...
5.1
Apache HTTP Server Allows Remote File Disclosure
MINI-cgh2-hjjg-mpfx
Apache HTTP Server may reveal sensitive files on the server to unauthorized users. This could potentially allow an attacker to access confidential data. To protect your server, ensure that you're runn...
Adobe ColdFusion Server: Unrestricted File Upload
MINI-cf2m-cjw7-mgx9
Adobe ColdFusion Server has a vulnerability that allows attackers to upload arbitrary files, potentially allowing them to execute malicious code. This could lead to unauthorized access to sensitive da...
MINI-9x6r-jg65-6fgp
MINI-9x6r-jg65-6fgp
MINI-47vh-qqmq-32j5
MINI-47vh-qqmq-32j5
MINI-jm4g-xg59-vjwp
MINI-jm4g-xg59-vjwp
MINI-4ph6-q45g-mgxm
MINI-4ph6-q45g-mgxm
MINI-4r63-24f7-2v82
MINI-4r63-24f7-2v82
MINI-93r9-xhrh-fqpq
MINI-93r9-xhrh-fqpq
MINI-j62j-xxmm-6xc6
MINI-j62j-xxmm-6xc6
MINI-ccfh-q2fr-49p5
MINI-ccfh-q2fr-49p5
Apache HTTP Server Cross-Site Scripting (XSS) in mod_proxy_html
MINI-jv9h-3rx2-xpg2
Apache HTTP Server's mod_proxy_html module is vulnerable to a cross-site scripting (XSS) attack. This means that an attacker could inject malicious code into web pages, potentially stealing user data ...
MINI-p47q-x9p9-f3rj
MINI-p47q-x9p9-f3rj
Windows Server and Exchange Server Remote Code Execution Vulnerability
MINI-968q-mxfp-qwh8
A remote attacker can execute malicious code on affected servers, potentially compromising data and system integrity. This can happen if a user opens a specially crafted email attachment or visits a m...
Adobe Flash Player Unpatched Remote Code Execution Vulnerability
MINI-962h-rxr2-pm82
Adobe Flash Player has a security weakness that could allow an attacker to take control of a computer remotely. This affects many Windows, macOS, and Linux systems. To stay safe, update to the latest ...
MINI-8mj8-cxxh-86jh
MINI-8mj8-cxxh-86jh
MINI-8qcm-cmw2-gxcv
MINI-8qcm-cmw2-gxcv
MINI-4886-834g-f4j4
MINI-4886-834g-f4j4
MINI-8hrj-52j8-x9qh
MINI-8hrj-52j8-x9qh
MINI-8fhg-pv9x-jh34
MINI-8fhg-pv9x-jh34
MINI-7xwr-pc23-x8xp
MINI-7xwr-pc23-x8xp
MINI-8hxx-mx2v-g5pj
MINI-8hxx-mx2v-g5pj