Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,383
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,861 - 6,880 of 12,776 CVEs
CVE-2026-22683 HIGH - 8.8

Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the...

Vendor: Windmill Labs, Nextcloud
Product: Windmill CE (Community Edition), Windmill EE (Enterprise Edition), Flow
Published: Apr 07, 2026
Source: NVD
CVE-2025-14821 HIGH - 7.8

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insec...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images 1, Red Hat OpenShift Container Platform 4
Published: Apr 07, 2026
Source: NVD
CVE-2026-35567 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, the NewRole POST parameter in src/MemberRoleChange.php is used in an SQL query without proper integer validation, allowing authenticated users to inject arbitrary SQL. The attack requires an authenticated session with ManageGroups...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35566 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical SQL injection vulnerability exists in src/Reports/FundRaiserStatement.php where the $_SESSION['iCurrentFundraiser'] value is used in an unquoted numeric SQL context without integer validation. The value origin...

Published: Apr 07, 2026
Source: NVD
CVE-2026-35534 HIGH - 7.6

ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in PersonView.php due to incorrect use of sanitizeText() as an output sanitizer for HTML attribute context. The function only strips HTML tags, it does not escape quote characters...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35521 HIGH - 8.8

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP hosts configuration parameter (dhcp.hosts). This vulnerability allows an aut...

Vendor: pi-hole
Product: FTL
Published: Apr 07, 2026
Source: NVD
CVE-2026-35520 HIGH - 8.8

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP lease time configuration parameter (dhcp.leaseTime). This vulnerability allo...

Vendor: pi-hole
Product: FTL
Published: Apr 07, 2026
Source: NVD
CVE-2026-35519 HIGH - 8.8

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS host record configuration parameter (dns.hostRecord). This vulnerability allo...

Vendor: pi-hole
Product: FTL
Published: Apr 07, 2026
Source: NVD
CVE-2026-35518 HIGH - 8.8

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS CNAME records configuration parameter (dns.cnameRecords). This vulnerability ...

Vendor: pi-hole
Product: FTL
Published: Apr 07, 2026
Source: NVD
CVE-2026-35517 HIGH - 8.8

FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the upstream DNS servers configuration parameter (dns.upstreams). This vulnerability ...

Vendor: pi-hole
Product: FTL
Published: Apr 07, 2026
Source: NVD
CVE-2026-35489 HIGH - 7.3

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and unit directly from request.data and passes them without validation to ShoppingListEntry.objects.create(). Invalid amount va...

Vendor: TandoorRecipes
Product: recipes
Published: Apr 07, 2026
Source: NVD
CVE-2026-35488 HIGH - 8.1

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared as an alternative permission class, but CustomIsShared.has_object_permission() returns True for all HTTP methods โ€” incl...

Vendor: TandoorRecipes
Product: recipes
Published: Apr 07, 2026
Source: NVD
CVE-2026-35486 HIGH - 7.5

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and superboogav2 RAG extensions fetch user-supplied URLs via requests.get() with zero validation โ€” no scheme check, no IP filtering, no hostname allowlist. An attacker can access clou...

Vendor: oobabooga
Product: text-generation-webui
Published: Apr 07, 2026
Source: NVD
CVE-2026-30460 HIGH - 8.8

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.

Vendor: thedaylightstudio
Product: fuel_cms
Published: Apr 07, 2026
Source: NVD
CVE-2025-24818 HIGH - 8.0

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application.

Vendor: Nokia
Product: MantaRay NM
Published: Apr 07, 2026
Source: NVD
CVE-2025-24817 HIGH - 8.0

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.

Vendor: Nokia
Product: MantaRay NM
Published: Apr 07, 2026
Source: NVD
CVE-2026-5373 HIGH - 8.1

An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N (8.1 High). This issue was fixed in version ...

Published: Apr 07, 2026
Source: NVD
CVE-2026-4740 HIGH - 8.2

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This e...

Published: Apr 07, 2026
Source: NVD
CVE-2026-3902 HIGH - 7.5

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Djang...

Vendor: pip
Product: Django
Published: Apr 07, 2026
Source: NVD
CVE-2026-35485 HIGH - 7.5

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_grammar() allows reading any file on the server filesystem with no extension restriction. Gradio does not server-side validate dropdown value...

Vendor: oobabooga
Product: text-generation-webui
Published: Apr 07, 2026
Source: NVD