Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 16 April 2026

RSS

965 vulnerabilities published on 16 April 2026

Severity:
Meridian: Public APIs Can Expose Sensitive Data
GHSA-f5v8-v6q3-q4h6
The Meridian software has a security issue that allows unauthorized access to sensitive data. This issue affects users who rely on Meridian for data mapping and processing. To fix this, update to the ...
7.5
ngtcp2: Large QUIC Parameter Can Crash the Server
CVE-2026-40170
A bug in ngtcp2's QUIC implementation can cause a server to crash if it receives a large QUIC parameter from a remote peer. This is fixed in version 1.22.1. If you can't update right away, you can dis...
7.5
Flowise: Password Reset Link Sent Over Unsecured Connection
GHSA-x5w6-38gp-mrqh
Flowise's password reset feature sends a reset link over an unsecured connection, making it possible for an attacker on the same network to intercept the link and gain unauthorized access to your acco...
7.5
Flowise: Sensitive Data Exposed in Public Chatbot Config
GHSA-4jpm-cgx2-8h37
Flowise exposes sensitive data, including API keys and passwords, in public chatbot configurations without authentication. This means an attacker can access and steal sensitive information by knowing ...
7.5
Basic-FTP: Unbounded Memory Consumption via Large FTP Listings
GHSA-rp42-5vxx-qpwr
An attacker can consume a Basic-FTP server's memory by sending an extremely large or never-ending directory listing. This can cause the server to become unstable or crash. To avoid this, consider usin...
7.5
basic-ftp: Denial of Service via Unbounded Memory Consumption
GHSA-rp42-5vxx-qpwr
The basic-ftp software is at risk of crashing or becoming unstable if it receives an extremely large or never-ending directory listing from a remote FTP server. This could happen if an attacker sends ...
7.5
DataEase Data Visualization Platform: Remote Code Execution Risk
CVE-2026-40901
DataEase versions 2.10.20 and below are at risk of a security breach that could allow an attacker to gain full control of the system. If an attacker with permission to schedule jobs can exploit this v...
7.5
PsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code execution on restart
GHSA-533q-w4g6-5586
### Summary The upload PATCH flow under `/files/:uploadId` validates the mounted request path using the still-encoded `req.path`, but the downstream tus handler later writes using the decoded `req.pa...
7.5
PsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code execution on restart
GHSA-533q-w4g6-5586
### Summary The upload PATCH flow under `/files/:uploadId` validates the mounted request path using the still-encoded `req.path`, but the downstream tus handler later writes using the decoded `req.pa...
7.5
Unauthenticated Denial of Service via Oversized Cookie Parsing
GHSA-cpf9-ph2j-ccr9 CVE-2026-40303
An attacker can cause the proxy server to run out of memory by sending a specially crafted cookie, taking down the server for all users. This requires no authentication and can be done with a single m...
7.5
BIND DNS Server Can Crash with Malicious DNS Data
RLSA-2026:8312
A security update is available for BIND, a key component of many organizations' DNS infrastructure. This update fixes a critical issue where a maliciously crafted DNS message could cause the DNS serve...
7.5
Apache SkyWalking Leaks Sensitive DB Config via Debugging Endpoint
CVE-2026-30778 GHSA-27h3-crw2-q36w
Apache SkyWalking versions 9.7.0 through 10.3.0 may expose sensitive database settings. This could allow unauthorized access to your database credentials. To fix, update to version 10.4.0 or later.
7.5
Fio Crashes When Parsing Malformed Job Files with fdp_pli Option
CVE-2026-30656
A flaw in fio 3.41 causes it to crash when processing certain job files. This means fio might stop working unexpectedly, making it difficult to run I/O tests. Update to a fixed version of fio to preve...
7.5
DirectoryPress plugin for WordPress allows attackers to access sensitive data
CVE-2026-3489
The DirectoryPress plugin for WordPress has a security flaw that allows hackers to access sensitive information from the database without needing a password. This affects versions up to 3.6.26. Update...
7.5
WSO2 Products Fail to Safely Process User-Submitted XML Data
CVE-2024-2374
WSO2's XML parsers don't safely handle user-submitted data, allowing hackers to access sensitive files or crash servers. This can lead to unauthorized data exposure or service disruptions. Update your...
7.5
LangChain Core: Unsecured File Access through User Config
GHSA-qh6h-p6c9-ff54 CVE-2026-34070
LangChain Core's legacy loading functions can read arbitrary files on the host filesystem when user-influenced config is passed to them. This can happen if an attacker can control prompt configuration...
7.5
Payment Gateway for Redsys & WooCommerce Lite plugin on WordPress allows fake payments
CVE-2026-5050
Versions of this WordPress plugin may allow attackers to fake payments and mark orders as paid without a real payment being made. This can lead to incorrect order fulfillment and financial loss. Updat...
7.5
Riaxe Product Customizer Plugin for WordPress Allows Attackers to Access Sensitive Data
CVE-2026-3599
The Riaxe Product Customizer plugin for WordPress allows attackers to extract sensitive database information without needing a login. This is because the plugin doesn't properly protect user input, al...
7.5
MailGates/MailAudit allows unauthorized access to system files
CVE-2026-6351
A flaw in MailGates/MailAudit allows attackers to view sensitive system files without a password. This could lead to the exposure of confidential information. Update MailGates/MailAudit to the latest ...
8.7
Froxlor Allows Malicious Users to Take Control of Arbitrary Directories
GHSA-75h4-c557-j89r
A security issue in Froxlor allows a malicious user to take ownership of any directory on the system, which can lead to unauthorized access and control of sensitive files. This is due to a missing sec...
7.5
Froxlor DataDump Feature Allows Unauthorized Directory Ownership
GHSA-75h4-c557-j89r
A security issue in Froxlor's DataDump feature allows an attacker to take control of arbitrary directories on the system if the ExportCron runs as root. This is due to a missed patch in the DataDump.a...
7.5
Fastify Middie versions 9.3.1 and earlier can be bypassed by attackers
CVE-2026-33804 GHSA-v9ww-2j6r-98q6
A security issue in outdated versions of @fastify/middie allows attackers to bypass security checks. This happens when a specific option is enabled, but it's not recommended to use. To fix it, update ...
7.4
Adobe Photoshop and Other Apps Can Run Malicious Code from Images
RLSA-2026:7682
A security update is available for Adobe Photoshop and other apps that use OpenEXR, a type of image file format. If you use these apps, be aware that hackers could potentially run malicious code if th...
7.4
Rsync with xattr enabled can crash on Linux systems
CVE-2026-41035
A bug in rsync's xattr feature can cause it to crash on Linux systems, but only if you're using a specific option. To fix, update to a newer version of rsync or disable the xattr feature if you don't ...
7.4
Old versions of radare2 on some Unix systems may allow hackers to execute commands
CVE-2026-41015
Old versions of radare2, a debugging tool, are vulnerable to a security risk on some Unix systems. If not using the latest version, hackers could potentially inject malicious commands. Update to the l...
7.4