Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,599
Quick preset (or use dates below)
Clear Filters
Showing 7,381 - 7,400 of 13,544 CVEs
CVE-2026-35395 HIGH - 8.8

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in dao/memorando/DespachoDAO.php. The id_memorando parameter is extracted from $_REQUEST without validation and directly interpolated int...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Apr 06, 2026
Source: NVD
CVE-2026-35391 HIGH - 7.5

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For header, which is fully controlled by the client. An attacker could forge their source IP address to ...

Vendor: bulwarkmail
Product: webmail
Published: Apr 06, 2026
Source: NVD
CVE-2026-35389 HIGH - 7.5

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vuln...

Vendor: bulwarkmail
Product: webmail
Published: Apr 06, 2026
Source: NVD
CVE-2025-54601 HIGH - 7.0

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a double free. An attacker can trigger a race condition by invoking an ioc...

Vendor: samsung
Product: exynos_980_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-35203 HIGH - 7.5

ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fields from the RTP payload based on flag bits in the first byte, without verifying that sufficient data exists in the buffer. A crafted VP9 RTP packet with a 1-byte payload (0xFF, al...

Vendor: ZLMediaKit
Product: ZLMediaKit
Published: Apr 06, 2026
Source: NVD
CVE-2026-35183 HIGH - 7.1

Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the article image deletion feature. It is located in app/Http/Controllers/Dashboard/ArticleController.php within the deleteImage method. The endpoint accepts a filename from the URL bu...

Vendor: Ajax30
Product: BraveCMS-2.0
Published: Apr 06, 2026
Source: NVD
CVE-2026-35182 HIGH - 8.8

Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update role endpoint at routes/web.php. The POST route for /rights/update-role/{id} lacks the checkUserPermissions:assign-user-roles middleware. This allows any authenticated user to cha...

Vendor: Ajax30
Product: BraveCMS-2.0
Published: Apr 06, 2026
Source: NVD
CVE-2026-35176 HIGH - 7.1

openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in POFParser::parseSection() that allows out-of-bounds heap memory access when parsing a crafted .pof file. No FPGA hardware is required to trigger this vulnerability.

Vendor: trabucayre
Product: openFPGALoader
Published: Apr 06, 2026
Source: NVD
CVE-2026-35170 HIGH - 7.1

openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exists in BitParser::parseHeader() that allows out-of-bounds heap memory access when parsing a crafted .bit file. No FPGA hardware is required to trigger this vulnerability.

Vendor: trabucayre
Product: openFPGALoader
Published: Apr 06, 2026
Source: NVD
CVE-2026-35021 HIGH - 7.8

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious file paths. Attackers can inject shell metacharacters such as $() or backtick expressions int...

Vendor: Anthropic
Product: Claude Code, Claude Agent SDK for Python
Published: Apr 06, 2026
Source: NVD
CVE-2026-35020 HIGH - 8.4

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the command lookup helper and deep-link terminal launcher that allows local attackers to execute arbitrary commands by manipulating the TERMINAL environment variable. Attackers can inject shell metacharac...

Vendor: Anthropic
Product: Claude Code, Claude Agent SDK for Python
Published: Apr 06, 2026
Source: NVD
CVE-2025-57834 HIGH - 7.5

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem (Exynos 980, 850, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400, and Modem 5410). The absence of proper input validation leads to a ...

Vendor: samsung
Product: exynos_980_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2025-54602 HIGH - 7.0

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a use-after-free. An attacker can trigger a race condition by invoking an ...

Vendor: samsung
Product: exynos_980_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-5678 HIGH - 7.3

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument mode can lead to os command injection. The attack may be launched remotely. The exploit has been mad...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5677 HIGH - 7.3

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument resetFlags results in os command injection. The attack may be initiated remotely. The exploit has been release...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5676 HIGH - 7.3

A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument langType leads to missing authentication. The attack can be launched remotely. The exploit is publicly available an...

Published: Apr 06, 2026
Source: NVD
CVE-2025-54324 HIGH - 7.5

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Incorrect Handling of a DL NAS Transport packet leads to a Deni...

Vendor: samsung
Product: exynos_990_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-5672 HIGH - 7.3

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /edit-category.php of the component Parameter Handler. The manipulation of the argument cat_id leads to sql injection. It is possible to initiate the attac...

Published: Apr 06, 2026
Source: NVD
CVE-2026-35164 HIGH - 8.8

Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload functionality. It is found in app/Http/Controllers/Dashboard/CkEditorController.php within the ckupload method. The method fails to validate uploaded file types and relies entirel...

Vendor: Ajax30
Product: BraveCMS-2.0
Published: Apr 06, 2026
Source: NVD
CVE-2026-35045 HIGH - 8.1

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update/ endpoint in Tandoor Recipes allows any authenticated user within a Space to modify any recipe in that Space, including recipes marked as private by o...

Vendor: TandoorRecipes
Product: recipes
Published: Apr 06, 2026
Source: NVD