Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,330
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,961 - 6,980 of 12,776 CVEs
CVE-2026-21372 HIGH - 7.8

Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21371 HIGH - 7.8

Memory Corruption when retrieving output buffer with insufficient size validation.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21367 HIGH - 7.6

Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2025-47400 HIGH - 7.1

Cryptographic issue while copying data to a destination buffer without validating its size.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2025-47392 HIGH - 8.8

Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2025-47391 HIGH - 7.8

Memory corruption while processing a frame request from user.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2025-47390 HIGH - 7.8

Memory corruption while preprocessing IOCTL request in JPEG driver.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2025-47389 HIGH - 7.8

Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2024-14032 HIGH - 7.8

Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invoke the installFromPath:toPath:withReply: method to overwrite sy...

Vendor: Twitch
Product: Twitch Studio
Published: Apr 06, 2026
Source: NVD
CVE-2026-5663 HIGH - 7.3

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. Th...

Published: Apr 06, 2026
Source: NVD
CVE-2026-34885 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34.

Vendor: David Lingren
Product: Media LIbrary Assistant
Published: Apr 06, 2026
Source: NVD
CVE-2026-33540 HIGH - 7.5

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used wi...

Vendor: distribution
Product: distribution
Published: Apr 06, 2026
Source: NVD
CVE-2026-33510 HIGH - 8.8

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application improperly trusts a URL parameter (callbackUrl), which is passed to redirect and router.push. An attacker can craft a malic...

Vendor: homarr-labs
Product: homarr
Published: Apr 06, 2026
Source: NVD
CVE-2026-29047 HIGH - 7.2

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.

Vendor: glpi-project
Product: glpi
Published: Apr 06, 2026
Source: NVD
CVE-2026-26263 HIGH - 8.1

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.

Vendor: glpi-project
Product: glpi
Published: Apr 06, 2026
Source: NVD
CVE-2026-26027 HIGH - 7.5

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.

Vendor: glpi-project
Product: glpi
Published: Apr 06, 2026
Source: NVD
CVE-2026-25932 HIGH - 7.2

GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.

Vendor: glpi-project
Product: glpi
Published: Apr 06, 2026
Source: NVD
CVE-2026-30078 HIGH - 7.5

OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires InitiatingMessage but sent with successfulOutcome.

Vendor: openairinterface
Product: oai-cn5g-amf
Published: Apr 06, 2026
Source: NVD
CVE-2026-3524 HIGH - 8.8

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5648 HIGH - 7.3

A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /userfinishregister.php of the component Parameter Handler. This manipulation of the argument firstName causes sql injection. Remote exploitation of the attack is possible. The explo...

Published: Apr 06, 2026
Source: NVD