Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,649
Quick preset (or use dates below)
Clear Filters
Showing 7,221 - 7,240 of 13,935 CVEs
CVE-2026-35398 MEDIUM - 6.1

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos & listarId_Nome and nomeClasse...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Apr 06, 2026
Source: NVD
CVE-2026-35396 MEDIUM - 6.1

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarId and nomeClasse=IsaidaControle. The ap...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Apr 06, 2026
Source: NVD
CVE-2026-35390 MEDIUM - 6.1

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) set the Content-Security-Policy-Report-Only header instead of the enforcing Content-Security-Policy header. This means cross-site scripting (XSS) attacks were logged but not blocke...

Vendor: bulwarkmail
Product: webmail
Published: Apr 06, 2026
Source: NVD
CVE-2026-34972 MEDIUM - 5.0

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper poli...

Vendor: openfga
Product: openfga
Published: Apr 06, 2026
Source: NVD
CVE-2026-5681 MEDIUM - 6.3

A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the argument emp_id causes sql injection. The attack is possible to be carried out remotely. The exploit...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5679 MEDIUM - 5.5

A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument stun_pass leads to os command injection. The exploit has been disclosed publicly and may be used.

Published: Apr 06, 2026
Source: NVD
CVE-2026-35199 MEDIUM - 6.1

SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes a 64-bit leaf count value to a helper function that accepts a 32-bit parameter. For XMSS^MT parameter sets with total tree height >= 32 (which inclu...

Vendor: microsoft
Product: SymCrypt
Published: Apr 06, 2026
Source: NVD
CVE-2026-35197 MEDIUM - 6.6

dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code. This issue was discovered and fixed by dye's author, and is not known to be exploited. This vulnerability is fixed in 1.1.1.

Vendor: mattieb
Product: dye
Published: Apr 06, 2026
Source: NVD
CVE-2026-35180 MEDIUM - 4.3

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/customize_settings_nativeUpdate.json.php lacks CSRF token validation and writes uploaded logo files to disk before the ORM's domain-based security check executes. Combined with Sam...

Vendor: WWBN
Product: AVideo
Published: Apr 06, 2026
Source: NVD
CVE-2026-33817 MEDIUM - 6.2

(This report has been withdrawn with reason: "Reporter and maintainer have confirmed this as false positive"). Index out-of-range when encountering a branch page with zero elements in go.etcd.io/bbolt

Vendor: go.etcd.io/bbolt
Product: go.etcd.io/bbolt
Published: Apr 06, 2026
Source: NVD
CVE-2026-0049 MEDIUM - 6.2

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Apr 06, 2026
Source: NVD
CVE-2025-48651 MEDIUM - 5.5

In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: Google
Product: Android
Published: Apr 06, 2026
Source: NVD
CVE-2026-5675 MEDIUM - 6.3

A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in sql injection. It is possible to launch the attack remotely. The exploit has b...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5671 MEDIUM - 4.3

A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Impacted is an unknown function of the file /admin/class%20schedule/delete_batch.php of the component Class Schedule Deletion Endpoint. Executing a manipulation of the argument batch...

Published: Apr 06, 2026
Source: NVD
CVE-2026-35177 MEDIUM - 4.1

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.

Vendor: vim
Product: vim
Published: Apr 06, 2026
Source: NVD
CVE-2026-35173 MEDIUM - 6.5

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authenticated users with post editing permissions (Edit Post, Edit Draft, Edit Own Post, Edit Own Draft) to modify posts they do not own and do not have permissi...

Vendor: xenocrat
Product: chyrp-lite
Published: Apr 06, 2026
Source: NVD
CVE-2026-35046 MEDIUM - 5.4

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tandoor Recipes allows authenticated users to inject arbitrary <style> tags into recipe step instructions. The bleach.clean() sanitizer explicitly whitelists the <style> t...

Vendor: TandoorRecipes
Product: recipes
Published: Apr 06, 2026
Source: NVD
CVE-2026-30613 MEDIUM - 4.6

An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface. An attacker with physical access can connect to the UART interface and obtain sensitive information from the...

Published: Apr 06, 2026
Source: NVD
CVE-2025-61166 MEDIUM - 6.1

An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL.

Vendor: ascertia
Product: signinghub
Published: Apr 06, 2026
Source: NVD

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev serverโ€™s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the serve...

Vendor: npm
Product: vite
Published: Apr 06, 2026
Source: GitHub