Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,646
Quick preset (or use dates below)
Clear Filters
Showing 6,981 - 7,000 of 13,544 CVEs
CVE-2026-35643 HIGH - 8.8

OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages can invoke the canvas bridge to execute malicious code within the Android application context.

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 10, 2026
Source: NVD
CVE-2026-35641 HIGH - 7.8

OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that allows attackers to execute malicious code by crafting a .npmrc file with a git executable override. During npm install execution in the staged package directory, attackers can lev...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 10, 2026
Source: NVD
CVE-2026-35595 HIGH - 8.3

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrite on the new parent project when changing parent_project_id. However, Vikunja's permission model uses a recursive CTE that walks ...

Vendor: go-vikunja
Product: vikunja
Published: Apr 10, 2026
Source: NVD
CVE-2026-34727 HIGH - 7.4

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enrolled is matched via the OIDC email fallback mechanis...

Vendor: go-vikunja
Product: vikunja
Published: Apr 10, 2026
Source: NVD
CVE-2026-29002 HIGH - 7.2

CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in user creation requests. Attackers can modify the parameter value from 4 to 10 in the HTTP request body to bypass authori...

Vendor: CouchCMS
Product: CouchCMS
Published: Apr 10, 2026
Source: NVD
CVE-2026-23782 HIGH - 7.5

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to unau...

Published: Apr 10, 2026
Source: NVD
CVE-2026-23780 HIGH - 8.8

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable ar...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6069 HIGH - 7.5

NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffer capacity.

Vendor: nasm
Product: netwide_assembler
Published: Apr 10, 2026
Source: NVD
CVE-2026-6067 HIGH - 7.5

A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm file, potentially leading to heap memory corruption, denial of service (crash), and ...

Vendor: nasm
Product: netwide_assembler
Published: Apr 10, 2026
Source: NVD
CVE-2026-40217 HIGH - 8.8

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

Vendor: BerriAI
Product: LiteLLM
Published: Apr 10, 2026
Source: NVD
CVE-2026-33092 HIGH - 7.8

Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before build 42902.

Vendor: Acronis
Product: Acronis True Image OEM, Acronis True Image
Published: Apr 10, 2026
Source: NVD
CVE-2025-5804 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case Themes Case Theme User allows PHP Local File Inclusion.This issue affects Case Theme User: from n/a before 1.0.4.

Published: Apr 10, 2026
Source: NVD
CVE-2025-58920 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato allows Reflected XSS.This issue affects Cerato: from n/a through 2.2.18.

Vendor: Zootemplate
Product: Cerato
Published: Apr 10, 2026
Source: NVD
CVE-2025-58913 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CactusThemes VideoPro allows PHP Local File Inclusion.This issue affects VideoPro: from n/a through 2.3.8.1.

Vendor: CactusThemes
Product: VideoPro
Published: Apr 10, 2026
Source: NVD
CVE-2026-39304 HIGH - 7.5

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes th...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ
Published: Apr 10, 2026
Source: NVD
CVE-2026-4162 HIGH - 7.1

The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and ...

Published: Apr 10, 2026
Source: NVD
CVE-2021-47961 HIGH - 8.1

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when comb...

Vendor: Synology
Product: Synology SSL VPN Client
Published: Apr 10, 2026
Source: NVD
CVE-2026-6038 HIGH - 7.3

A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function of the file /util/RegisterCustomerFunction.php. Such manipulation of the argument BRANCH_ID leads to sql injection. The attack may be performed from remote. The exploit is publicl...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6037 HIGH - 7.3

A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function of the file /util/AddVehicleFunction.php. This manipulation of the argument BRANCH_ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been...

Published: Apr 10, 2026
Source: NVD
CVE-2026-6036 HIGH - 7.3

A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown function of the file /util/VehicleDetailsFunction.php. The manipulation of the argument VEHICLE_ID results in sql injection. The attack can be executed remotely. The exploit has been...

Published: Apr 10, 2026
Source: NVD