Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,607
Quick preset (or use dates below)
Clear Filters
Showing 7,301 - 7,320 of 13,544 CVEs
CVE-2026-39327 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /MemberRoleChange.php in ChurchCRM 7.0.5. Authenticated users with the role Manage Groups & Roles (ManageGroups) can inject arbitrary SQL statements through the NewRole ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39326 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /PropertyTypeEditor.php in ChurchCRM. Authenticated users with the role isMenuOptionsEnabled can inject arbitrary SQL statements through the Name and Description parameters ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39325 HIGH - 7.2

ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the endpoint /SettingsUser.php in ChurchCRM 7.0.5. Authenticated administrative users can inject arbitrary SQL statements through the type array parameter via the index and thus extract ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39323 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical SQL injection vulnerability exists in ChurchCRM's PropertyTypeEditor.php where the Name and Description POST parameters are sanitized only with strip_tags() before direct concatenation into SQL queries. This allows...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39319 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was found in the endpoint /FundRaiserEditor.php in ChurchCRM. A user has to be authenticated but doesn't need any privileges. These users can inject arbitrary SQL statements through ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39318 HIGH - 8.8

ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the endpoints `/GroupPropsFormRowOps.php`, `/PersonCustomFieldsRowOps.php`, and `/FamilyCustomFieldsRowOps.php`. A user has to be authenticated. For `ManageGroups` privileges have to ...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39317 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in ChurchCRM's SettingsIndividual.php where user-controlled array keys from the type POST parameter are used directly in SQL queries without sanitization. This allows any authenticated use...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35576 HIGH - 8.7

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the Person Property Management subsystem. This issue persists in versions patched for CVE-2023-38766 and allows an authenticated user to inject arbitrary...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-35575 HIGH - 8.0

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows any user with group-creation privileges to inject malicious JavaScript that executes automatically when an administrator v...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-24175 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request header to the server. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: Apr 07, 2026
Source: NVD
CVE-2026-24174 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request to the server. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: Apr 07, 2026
Source: NVD
CVE-2026-24173 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malformed request to the server. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: Apr 07, 2026
Source: NVD
CVE-2026-24156 HIGH - 7.3

NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution.

Vendor: NVIDIA
Product: DALI
Published: Apr 07, 2026
Source: NVD
CVE-2026-24146 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a large number of outputs could cause a server crash. A successful exploit of this vulnerability might lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: Apr 07, 2026
Source: NVD
CVE-2026-22682 HIGH - 7.1

OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inconsistent parameter handling in permission enforcement, allowing attackers who can influence agent tool execution to read arbitrary local files outside the intended repository scope...

Vendor: HKUDS
Product: OpenHarness
Published: Apr 07, 2026
Source: NVD
CVE-2026-39384 HIGH - 7.6

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility parameter into account when merging customers. This vulnerability is fixed in 1.8.212.

Vendor: freescout-help-desk
Product: freescout
Published: Apr 07, 2026
Source: NVD
CVE-2026-39312 HIGH - 7.5

SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authentication denial-of-service vulnerability exists in SoftEther VPN Developer Edition 5.2.5188 (and likely earlier versions of Developer Edition). An unauthenticated remote attacker can cras...

Vendor: SoftEtherVPN
Product: SoftEtherVPN
Published: Apr 07, 2026
Source: NVD
CVE-2026-35611 HIGH - 7.5

Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3.0 to before 2.9.0, within the URI template implementation in Addressable, two classes of URI template generate regular expressions vulnerable to catastrophic backtracking. Te...

Vendor: sporkmonger
Product: addressable
Published: Apr 07, 2026
Source: NVD
CVE-2026-35610 HIGH - 8.8

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, password) and deleteUser(userId) in the account-management module used an inverted admin check. Because of the inverted condition, authenticated non-admin users were allowed to execute b...

Vendor: polarnl
Product: PolarLearn
Published: Apr 07, 2026
Source: NVD
CVE-2026-35607 HIGH - 8.1

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get execute perms") stripped Execute permission and Commands from users cre...

Vendor: filebrowser
Product: filebrowser
Published: Apr 07, 2026
Source: NVD