Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,349
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 6,921 - 6,940 of 12,776 CVEs
CVE-2026-35183 HIGH - 7.1

Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature. It is located in app/Http/Controllers/Dashboard/ArticleController.php within the deleteImage method. The endpoint accepts a filename from the URL bu...

Vendor: Ajax30
Product: BraveCMS-2.0
Published: Apr 06, 2026
Source: NVD
CVE-2026-35182 HIGH - 8.8

Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-user-roles middleware. This allows any authenticated user to cha...

Vendor: Ajax30
Product: BraveCMS-2.0
Published: Apr 06, 2026
Source: NVD
CVE-2026-35176 HIGH - 7.1

openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in POFParser::parseSection() that allows out-of-bounds heap memory access when parsing a crafted .pof file. No FPGA hardware is required to trigger this vulnerability.

Vendor: trabucayre
Product: openFPGALoader
Published: Apr 06, 2026
Source: NVD
CVE-2026-35170 HIGH - 7.1

openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in BitParser::parseHeader() that allows out-of-bounds heap memory access when parsing a crafted .bit file. No FPGA hardware is required to trigger this vulnerability.

Vendor: trabucayre
Product: openFPGALoader
Published: Apr 06, 2026
Source: NVD
CVE-2026-35021 HIGH - 7.8

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious file paths. Attackers can inject shell metacharacters such as $() or backtick expressions int...

Vendor: Anthropic
Product: Claude Code, Claude Agent SDK for Python
Published: Apr 06, 2026
Source: NVD
CVE-2026-35020 HIGH - 8.4

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the command lookup helper and deep-link terminal launcher that allows local attackers to execute arbitrary commands by manipulating the TERMINAL environment variable. Attackers can inject shell metacharac...

Vendor: Anthropic
Product: Claude Code, Claude Agent SDK for Python
Published: Apr 06, 2026
Source: NVD
CVE-2025-57834 HIGH - 7.5

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem (Exynos 980, 850, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400, and Modem 5410). The absence of proper input validation leads to a ...

Vendor: samsung
Product: exynos_980_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2025-54602 HIGH - 7.0

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a use-after-free. An attacker can trigger a race condition by invoking an ...

Vendor: samsung
Product: exynos_980_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-5678 HIGH - 7.3

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection. The attack may be launched remotely. The exploit has been mad...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5677 HIGH - 7.3

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument resetFlags results in os command injection. The attack may be initiated remotely. The exploit has been release...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5676 HIGH - 7.3

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument langType leads to missing authentication. The attack can be launched remotely. The exploit is publicly available an...

Published: Apr 06, 2026
Source: NVD
CVE-2025-54324 HIGH - 7.5

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Incorrect Handling of a DL NAS Transport packet leads to a Deni...

Vendor: samsung
Product: exynos_990_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-5672 HIGH - 7.3

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /edit-category.php of the component Parameter Handler. The manipulation of the argument cat_id leads to sql injection. It is possible to initiate the attac...

Published: Apr 06, 2026
Source: NVD
CVE-2026-35164 HIGH - 8.8

Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorController.php within the ckupload method. The method fails to validate uploaded file types and relies entirel...

Vendor: Ajax30
Product: BraveCMS-2.0
Published: Apr 06, 2026
Source: NVD
CVE-2026-35045 HIGH - 8.1

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update/ endpoint in Tandoor Recipes allows any authenticated user within a Space to modify any recipe in that Space, including recipes marked as private by o...

Vendor: TandoorRecipes
Product: recipes
Published: Apr 06, 2026
Source: NVD
CVE-2025-59440 HIGH - 7.5

An issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Improper handling of SIM card proactive commands leads to a De...

Vendor: samsung
Product: exynos_990_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2025-57835 HIGH - 7.5

An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Improper memory initialization results in an illegal memory acc...

Vendor: samsung
Product: exynos_990_firmware
Published: Apr 06, 2026
Source: NVD

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&i...

Vendor: npm
Product: vite
Published: Apr 06, 2026
Source: GitHub

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw ...

Vendor: npm
Product: vite
Published: Apr 06, 2026
Source: GitHub
CVE-2026-35526 HIGH - 7.5

Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphql-transport-ws and legacy graphql-ws protocols allocate an asyncio.Task and associated Operation object for every incoming subscribe message witho...

Vendor: pip
Product: strawberry-graphql
Published: Apr 06, 2026
Source: GitHub