Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,400
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 6,841 - 6,860 of 12,776 CVEs
CVE-2026-39318 HIGH - 8.8

ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the endpoints `/GroupPropsFormRowOps.php`, `/PersonCustomFieldsRowOps.php`, and `/FamilyCustomFieldsRowOps.php`. A user has to be authenticated. For `ManageGroups` privileges have to ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39317 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in ChurchCRM's SettingsIndividual.php where user-controlled array keys from the type POST parameter are used directly in SQL queries without sanitization. This allows any authenticated use...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35576 HIGH - 8.7

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the Person Property Management subsystem. This issue persists in versions patched for CVE-2023-38766 and allows an authenticated user to inject arbitrary...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35575 HIGH - 8.0

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious JavaScript that executes automatically when an administrator v...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-24175 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request header to the server. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: Apr 07, 2026
Source: NVD
CVE-2026-24174 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request to the server. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: Apr 07, 2026
Source: NVD
CVE-2026-24173 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request to the server. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: Apr 07, 2026
Source: NVD
CVE-2026-24156 HIGH - 7.3

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.

Vendor: NVIDIA
Product: DALI
Published: Apr 07, 2026
Source: NVD
CVE-2026-24146 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a large number of outputs could cause a server crash. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: Apr 07, 2026
Source: NVD
CVE-2026-22682 HIGH - 7.1

OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling in permission enforcement, allowing attackers who can influence agent tool execution to read arbitrary local files outside the intended repository scope...

Vendor: HKUDS
Product: OpenHarness
Published: Apr 07, 2026
Source: NVD
CVE-2026-39384 HIGH - 7.6

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility parameter into account when merging customers. This vulnerability is fixed in 1.8.212.

Vendor: freescout-help-desk
Product: freescout
Published: Apr 07, 2026
Source: NVD
CVE-2026-39312 HIGH - 7.5

SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authentication denial-of-service vulnerability exists in SoftEther VPN Developer Edition 5.2.5188 (and likely earlier versions of Developer Edition). An unauthenticated remote attacker can cras...

Vendor: SoftEtherVPN
Product: SoftEtherVPN
Published: Apr 07, 2026
Source: NVD
CVE-2026-35611 HIGH - 7.5

Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3.0 to before 2.9.0, within the URI template implementation in Addressable, two classes of URI template generate regular expressions vulnerable to catastrophic backtracking. Te...

Vendor: sporkmonger
Product: addressable
Published: Apr 07, 2026
Source: NVD
CVE-2026-35610 HIGH - 8.8

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, password) and deleteUser(userId) in the account-management module used an inverted admin check. Because of the inverted condition, authenticated non-admin users were allowed to execute b...

Vendor: polarnl
Product: PolarLearn
Published: Apr 07, 2026
Source: NVD
CVE-2026-35607 HIGH - 8.1

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get execute perms") stripped Execute permission and Commands from users cre...

Vendor: filebrowser
Product: filebrowser
Published: Apr 07, 2026
Source: NVD

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, when an admin revokes a user's Share and Download permissions, existing share links created by that user remain fully accessible to unauthent...

Vendor: filebrowser
Product: filebrowser
Published: Apr 07, 2026
Source: NVD

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.0.0 through 2.63.1, the hook system in File Browser — which executes administrator-defined shell commands on file events such as upload, rename, and delete ...

Vendor: filebrowser
Product: filebrowser
Published: Apr 07, 2026
Source: NVD
CVE-2026-35581 HIGH - 7.2

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell commands by concatenating configuration-derived values — including the PLACE_NAME parameter — with insufficient sanitization. Only spaces were replaced with underscores, allowing shell...

Vendor: NationalSecurityAgency
Product: emissary
Published: Apr 07, 2026
Source: NVD
CVE-2026-35574 HIGH - 7.3

ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability in ChurchCRM's Note Editor allows authenticated users with note-adding permissions to execute arbitrary JavaScript code in the context of other users' browsers, including...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-27314 HIGH - 8.8

Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY. Users are recomm...

Vendor: Apache Software Foundation
Product: Apache Cassandra
Published: Apr 07, 2026
Source: NVD