Total CVEs

139,448

Critical Severity

3,643

High Severity

13,083

Last 7 Days

1,262
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,201 - 7,220 of 12,780 CVEs
CVE-2026-31935 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system. This issue has been patched in versions 7.0.15 and 8.0.4.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-31934 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a performance impact. This issue has been patched in version 8.0.4.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-5334 HIGH - 7.3

A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=edit&id=3 of the component Parameter Handler. This manipulation of the argument deptid causes sql injection. The attack is possible to be carried ou...

Vendor: itsourcecode
Product: online_enrollment_system
Published: Apr 02, 2026
Source: NVD
CVE-2026-5333 HIGH - 7.3

A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host results in command injection. The attack can be executed remotely. The exploit has been released to the ...

Vendor: defaultfuction
Product: content_management_system
Published: Apr 02, 2026
Source: NVD
CVE-2026-3692 HIGH - 8.8

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

Vendor: progress
Product: flowmon
Published: Apr 02, 2026
Source: NVD
CVE-2026-35168 HIGH - 8.8

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database conflict resolution feature (op=risolvi-conflitti-database) that accepts a JSON array of SQL statements via P...

Vendor: devcode-it
Product: openstamanager
Published: Apr 02, 2026
Source: NVD
CVE-2026-31933 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been patched in versions 7.0.15 and 8.0.4.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-31932 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-31931 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched in version 8.0.4.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-4636 HIGH - 8.1

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resour...

Published: Apr 02, 2026
Source: NVD
CVE-2026-4634 HIGH - 7.5

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimatel...

Published: Apr 02, 2026
Source: NVD
CVE-2026-4282 HIGH - 7.4

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulti...

Published: Apr 02, 2026
Source: NVD
CVE-2026-3872 HIGH - 7.3

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclo...

Published: Apr 02, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via multipart form body parsing. The multipart_body function bypasses configured max_body_size and max_files_size limits. When a multipart boundary is not present in a chunk, the parser ...

Vendor: gleam-wisp
Product: wisp
Published: Apr 02, 2026
Source: NVD
CVE-2026-33616 HIGH - 7.5

An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

Vendor: MB connect line
Product: mbCONNECT24, mymbCONNECT24
Published: Apr 02, 2026
Source: NVD
CVE-2026-33614 HIGH - 7.5

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

Vendor: MB connect line
Product: mbCONNECT24, mymbCONNECT24
Published: Apr 02, 2026
Source: NVD
CVE-2026-33613 HIGH - 7.2

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full system compromise. This vulnerability can only be attacked if the attacker has some other way to write arbitrary data t...

Vendor: MB connect line
Product: mbCONNECT24, mymbCONNECT24
Published: Apr 02, 2026
Source: NVD
CVE-2026-0634 HIGH - 7.8

Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as system via command injection.

Published: Apr 02, 2026
Source: NVD
CVE-2026-5244 HIGH - 7.3

A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been d...

Published: Apr 02, 2026
Source: NVD
CVE-2026-5032 HIGH - 7.5

The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which caus...

Published: Apr 02, 2026
Source: NVD