Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,428
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,641 - 6,660 of 12,776 CVEs
CVE-2026-5828 HIGH - 7.3

A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and co...

Published: Apr 09, 2026
Source: NVD
CVE-2026-4326 HIGH - 8.8

The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capabi...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5827 HIGH - 7.3

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /question-function.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and ...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5824 HIGH - 7.3

A security vulnerability has been detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /userchecklogin.php. Such manipulation of the argument userid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly ...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5815 HIGH - 8.8

A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgi_main of the file /cgi-bin/hedwig.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only aff...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5814 HIGH - 7.3

A security vulnerability has been detected in PHPGurukul Online Course Registration 3.1. This issue affects some unknown processing of the file /admin/check_availability.php. The manipulation of the argument regno leads to sql injection. The attack can be initiated remotely. The exploit has been dis...

Published: Apr 09, 2026
Source: NVD
CVE-2026-5813 HIGH - 7.3

A weakness has been identified in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /check_availability.php. Executing a manipulation of the argument cid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made av...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5173 HIGH - 8.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper access control.

Published: Apr 08, 2026
Source: NVD
CVE-2026-1092 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input validation of JSON payloads.

Vendor: gitlab
Product: gitlab
Published: Apr 08, 2026
Source: NVD
CVE-2025-12664 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.

Vendor: GitLab
Product: GitLab
Published: Apr 08, 2026
Source: NVD
CVE-2026-5915 HIGH - 8.1

Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5914 HIGH - 8.8

Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5913 HIGH - 8.1

Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5912 HIGH - 8.8

Integer overflow in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5910 HIGH - 8.8

Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5909 HIGH - 8.8

Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5908 HIGH - 8.8

Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5907 HIGH - 8.1

Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5904 HIGH - 8.8

Use after free in V8 in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD
CVE-2026-5886 HIGH - 7.5

Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: Apr 08, 2026
Source: NVD