Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,330
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,941 - 6,960 of 12,776 CVEs
CVE-2026-35523 HIGH - 7.5

Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler does not verify that a connection_init handshake has been completed before processin...

Vendor: pip
Product: strawberry-graphql
Published: Apr 06, 2026
Source: GitHub
CVE-2026-35172 HIGH - 7.5

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest ...

Vendor: go
Product: github.com/distribution/distribution/v3
Published: Apr 06, 2026
Source: GitHub
CVE-2026-5669 HIGH - 7.3

A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unknown code of the file /login.php of the component Parameter Handler. Such manipulation of the argument Password leads to sql injection. It is possible t...

Published: Apr 06, 2026
Source: NVD
CVE-2026-35035 HIGH - 7.2

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.2.0 , the application fails to properly sanitize user-controlled input within System Settings โ€“ Company Information. Several administrative conf...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 06, 2026
Source: NVD
CVE-2026-34975 HIGH - 8.5

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability was discovered in SESService.ts, where user-supplied values for from.name, subject, custom header keys/values, and attachment filenames were interpolated directly into raw MIME messa...

Vendor: useplunk
Product: plunk
Published: Apr 06, 2026
Source: NVD
CVE-2026-5665 HIGH - 7.3

A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/checklogin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack is possible to be...

Published: Apr 06, 2026
Source: NVD
CVE-2026-34982 HIGH - 8.2

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be execu...

Vendor: vim
Product: vim
Published: Apr 06, 2026
Source: NVD
CVE-2026-34588 HIGH - 7.8

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, a...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 06, 2026
Source: NVD

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary...

Vendor: scoder
Product: lupa
Published: Apr 06, 2026
Source: NVD
CVE-2026-34402 HIGH - 8.1

ChurchCRM is an open-source church management system. Prior to 7.1.0, authenticated users with Edit Records or Manage Groups permissions can exploit a time-based blind SQL injection vulnerability in the PropertyAssign.php endpoint to exfiltrate or modify any database content, including user credenti...

Vendor: ChurchCRM
Product: CRM
Published: Apr 06, 2026
Source: NVD
CVE-2026-34379 HIGH - 7.1

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_d...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 06, 2026
Source: NVD
CVE-2026-34148 HIGH - 7.5

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-...

Vendor: @fedify
Product: fedify, vocab-runtime
Published: Apr 06, 2026
Source: NVD
CVE-2026-21382 HIGH - 7.8

Memory Corruption when handling power management requests with improperly sized input/output buffers.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21381 HIGH - 7.6

Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21380 HIGH - 7.8

Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21378 HIGH - 7.8

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21376 HIGH - 7.8

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21375 HIGH - 7.8

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21374 HIGH - 7.8

Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21373 HIGH - 7.8

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD