Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,589
Quick preset (or use dates below)
Clear Filters
Showing 7,401 - 7,420 of 13,544 CVEs
CVE-2025-59440 HIGH - 7.5

An issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Improper handling of SIM card proactive commands leads to a De...

Vendor: samsung
Product: exynos_990_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2025-57835 HIGH - 7.5

An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Improper memory initialization results in an illegal memory acc...

Vendor: samsung
Product: exynos_990_firmware
Published: Apr 06, 2026
Source: NVD

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&i...

Vendor: npm
Product: vite
Published: Apr 06, 2026
Source: GitHub

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw ...

Vendor: npm
Product: vite
Published: Apr 06, 2026
Source: GitHub
CVE-2026-35526 HIGH - 7.5

Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphql-transport-ws and legacy graphql-ws protocols allocate an asyncio.Task and associated Operation object for every incoming subscribe message witho...

Vendor: pip
Product: strawberry-graphql
Published: Apr 06, 2026
Source: GitHub
CVE-2026-35523 HIGH - 7.5

Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler does not verify that a connection_init handshake has been completed before processin...

Vendor: pip
Product: strawberry-graphql
Published: Apr 06, 2026
Source: GitHub
CVE-2026-35172 HIGH - 7.5

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest ...

Vendor: go
Product: github.com/distribution/distribution/v3
Published: Apr 06, 2026
Source: GitHub
CVE-2026-5669 HIGH - 7.3

A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This vulnerability affects unknown code of the file /login.php of the component Parameter Handler. Such manipulation of the argument Password leads to sql injection. It is possible t...

Published: Apr 06, 2026
Source: NVD
CVE-2026-35035 HIGH - 7.2

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.2.0 , the application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative conf...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Apr 06, 2026
Source: NVD
CVE-2026-34975 HIGH - 8.5

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability was discovered in SESService.ts, where user-supplied values for from.name, subject, custom header keys/values, and attachment filenames were interpolated directly into raw MIME messa...

Vendor: useplunk
Product: plunk
Published: Apr 06, 2026
Source: NVD
CVE-2026-5665 HIGH - 7.3

A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/checklogin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack is possible to be...

Published: Apr 06, 2026
Source: NVD
CVE-2026-34982 HIGH - 8.2

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be execu...

Vendor: vim
Product: vim
Published: Apr 06, 2026
Source: NVD
CVE-2026-34588 HIGH - 7.8

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, a...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 06, 2026
Source: NVD

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary...

Vendor: scoder
Product: lupa
Published: Apr 06, 2026
Source: NVD
CVE-2026-34402 HIGH - 8.1

ChurchCRM is an open-source church management system. Prior to 7.1.0, authenticated users with Edit Records or Manage Groups permissions can exploit a time-based blind SQL injection vulnerability in the PropertyAssign.php endpoint to exfiltrate or modify any database content, including user credenti...

Vendor: ChurchCRM
Product: CRM
Published: Apr 06, 2026
Source: NVD
CVE-2026-34379 HIGH - 7.1

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_d...

Vendor: AcademySoftwareFoundation
Product: openexr
Published: Apr 06, 2026
Source: NVD
CVE-2026-34148 HIGH - 7.5

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-...

Vendor: @fedify
Product: fedify, vocab-runtime
Published: Apr 06, 2026
Source: NVD
CVE-2026-21382 HIGH - 7.8

Memory Corruption when handling power management requests with improperly sized input/output buffers.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21381 HIGH - 7.6

Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21380 HIGH - 7.8

Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD