Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,383
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 6,881 - 6,900 of 12,776 CVEs
CVE-2026-35458 HIGH - 9.8

Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely.

Vendor: gotenberg
Product: gotenberg
Published: Apr 07, 2026
Source: NVD
CVE-2026-33034 HIGH - 7.5

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request bo...

Vendor: djangoproject
Product: Django
Published: Apr 07, 2026
Source: NVD
CVE-2026-24660 HIGH - 8.1

A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Vendor: LibRaw
Product: LibRaw
Published: Apr 07, 2026
Source: NVD
CVE-2026-24450 HIGH - 8.1

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Vendor: LibRaw
Product: LibRaw
Published: Apr 07, 2026
Source: NVD
CVE-2026-20884 HIGH - 8.1

An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Vendor: LibRaw
Product: LibRaw
Published: Apr 07, 2026
Source: NVD
CVE-2026-35554 HIGH - 8.7

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is pre...

Vendor: Apache Software Foundation
Product: Apache Kafka Clients
Published: Apr 07, 2026
Source: NVD
CVE-2026-5733 HIGH - 8.8

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.

Vendor: mozilla
Product: firefox
Published: Apr 07, 2026
Source: NVD
CVE-2026-5732 HIGH - 8.8

Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability affects Firefox < 149.0.2, Firefox ESR < 140.9.1, Thunderbird < 149.0.2, and Thunderbird < 140.9.1.

Vendor: mozilla
Product: firefox
Published: Apr 07, 2026
Source: NVD
CVE-2026-23818 HIGH - 8.8

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attac...

Vendor: Hewlett Packard Enterprise (HPE)
Product: Private 5G Core
Published: Apr 07, 2026
Source: NVD
CVE-2026-22666 HIGH - 7.2

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can inject...

Vendor: Dolibarr
Product: Dolibarr ERP/CRM
Published: Apr 07, 2026
Source: NVD
CVE-2025-39666 HIGH - 7.3

Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site context that are processed when the `omd` administrative...

Vendor: Checkmk GmbH
Product: Checkmk
Published: Apr 07, 2026
Source: NVD
CVE-2026-31842 HIGH - 7.5

Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer() function uses strcmp() to compare the header value against "chunked", even though RFC 7230 specifies ...

Vendor: Tinyproxy Project
Product: Tinyproxy
Published: Apr 07, 2026
Source: NVD
CVE-2026-34904 HIGH - 7.5

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects Simple Social Media Share Buttons: from n/a through 6.2.0.

Vendor: Analytify
Product: Simple Social Media Share Buttons
Published: Apr 07, 2026
Source: NVD
CVE-2026-34896 HIGH - 7.5

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & Maintenance Mode: from n/a through 2.1.1.

Vendor: Analytify
Product: Under Construction, Coming Soon & Maintenance Mode
Published: Apr 07, 2026
Source: NVD
CVE-2026-34197 HIGH - 8.8

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec op...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ Broker, Apache ActiveMQ
Published: Apr 07, 2026
Source: NVD
CVE-2026-5465 HIGH - 8.8

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Emplo...

Published: Apr 07, 2026
Source: NVD
CVE-2025-65115 HIGH - 8.8

Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT De...

Published: Apr 07, 2026
Source: NVD
CVE-2026-20433 HIGH - 8.8

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. P...

Vendor: MediaTek, Inc.
Product: MediaTek chipset
Published: Apr 07, 2026
Source: NVD
CVE-2026-20432 HIGH - 8.0

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. P...

Vendor: MediaTek, Inc.
Product: MediaTek chipset
Published: Apr 07, 2026
Source: NVD
CVE-2026-5692 HIGH - 7.3

A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be performed from remote. The exploit has been made public and could...

Published: Apr 07, 2026
Source: NVD