Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,604
Quick preset (or use dates below)
Clear Filters
Showing 7,341 - 7,360 of 13,544 CVEs
CVE-2025-24817 HIGH - 8.0

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.

Vendor: Nokia
Product: MantaRay NM
Published: Apr 07, 2026
Source: NVD
CVE-2026-5373 HIGH - 8.1

An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N (8.1 High). This issue was fixed in version ...

Published: Apr 07, 2026
Source: NVD
CVE-2026-4740 HIGH - 8.2

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This e...

Published: Apr 07, 2026
Source: NVD
CVE-2026-3902 HIGH - 7.5

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Djang...

Vendor: pip
Product: Django
Published: Apr 07, 2026
Source: NVD
CVE-2026-35485 HIGH - 7.5

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_grammar() allows reading any file on the server filesystem with no extension restriction. Gradio does not server-side validate dropdown value...

Vendor: oobabooga
Product: text-generation-webui
Published: Apr 07, 2026
Source: NVD
CVE-2026-35458 HIGH - 9.8

Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely.

Vendor: gotenberg
Product: gotenberg
Published: Apr 07, 2026
Source: NVD
CVE-2026-33034 HIGH - 7.5

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request bo...

Vendor: djangoproject
Product: Django
Published: Apr 07, 2026
Source: NVD
CVE-2026-24660 HIGH - 8.1

A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Vendor: LibRaw
Product: LibRaw
Published: Apr 07, 2026
Source: NVD
CVE-2026-24450 HIGH - 8.1

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Vendor: LibRaw
Product: LibRaw
Published: Apr 07, 2026
Source: NVD
CVE-2026-20884 HIGH - 8.1

An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

Vendor: LibRaw
Product: LibRaw
Published: Apr 07, 2026
Source: NVD
CVE-2026-35554 HIGH - 8.7

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is pre...

Vendor: Apache Software Foundation
Product: Apache Kafka Clients
Published: Apr 07, 2026
Source: NVD
CVE-2026-5733 HIGH - 8.8

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.

Vendor: mozilla
Product: firefox
Published: Apr 07, 2026
Source: NVD
CVE-2026-5732 HIGH - 8.8

Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability affects Firefox < 149.0.2, Firefox ESR < 140.9.1, Thunderbird < 149.0.2, and Thunderbird < 140.9.1.

Vendor: mozilla
Product: firefox
Published: Apr 07, 2026
Source: NVD
CVE-2026-23818 HIGH - 8.8

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attac...

Vendor: Hewlett Packard Enterprise (HPE)
Product: Private 5G Core
Published: Apr 07, 2026
Source: NVD
CVE-2026-22666 HIGH - 7.2

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can inject...

Vendor: Dolibarr
Product: Dolibarr ERP/CRM
Published: Apr 07, 2026
Source: NVD
CVE-2025-39666 HIGH - 7.3

Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in the site context that are processed when the `omd` administrative...

Vendor: Checkmk GmbH
Product: Checkmk
Published: Apr 07, 2026
Source: NVD
CVE-2026-31842 HIGH - 7.5

Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer() function uses strcmp() to compare the header value against "chunked", even though RFC 7230 specifies ...

Vendor: Tinyproxy Project
Product: Tinyproxy
Published: Apr 07, 2026
Source: NVD
CVE-2026-34904 HIGH - 7.5

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects Simple Social Media Share Buttons: from n/a through 6.2.0.

Vendor: Analytify
Product: Simple Social Media Share Buttons
Published: Apr 07, 2026
Source: NVD
CVE-2026-34896 HIGH - 7.5

Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & Maintenance Mode: from n/a through 2.1.1.

Vendor: Analytify
Product: Under Construction, Coming Soon & Maintenance Mode
Published: Apr 07, 2026
Source: NVD
CVE-2026-34197 HIGH - 8.8

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec op...

Vendor: Apache Software Foundation
Product: Apache ActiveMQ Broker, Apache ActiveMQ
Published: Apr 07, 2026
Source: NVD