Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,581
Quick preset (or use dates below)
Clear Filters
Showing 7,421 - 7,440 of 13,544 CVEs
CVE-2026-21378 HIGH - 7.8

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21376 HIGH - 7.8

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21375 HIGH - 7.8

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21374 HIGH - 7.8

Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21373 HIGH - 7.8

Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21372 HIGH - 7.8

Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21371 HIGH - 7.8

Memory Corruption when retrieving output buffer with insufficient size validation.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2026-21367 HIGH - 7.6

Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2025-47400 HIGH - 7.1

Cryptographic issue while copying data to a destination buffer without validating its size.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2025-47392 HIGH - 8.8

Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2025-47391 HIGH - 7.8

Memory corruption while processing a frame request from user.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2025-47390 HIGH - 7.8

Memory corruption while preprocessing IOCTL request in JPEG driver.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2025-47389 HIGH - 7.8

Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Apr 06, 2026
Source: NVD
CVE-2024-14032 HIGH - 7.8

Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invoke the installFromPath:toPath:withReply: method to overwrite sy...

Vendor: Twitch
Product: Twitch Studio
Published: Apr 06, 2026
Source: NVD
CVE-2026-5663 HIGH - 7.3

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. Th...

Published: Apr 06, 2026
Source: NVD
CVE-2026-34885 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbrary Assistant: from n/a through 3.34.

Vendor: David Lingren
Product: Media LIbrary Assistant
Published: Apr 06, 2026
Source: NVD
CVE-2026-33540 HIGH - 7.5

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used wi...

Vendor: distribution
Product: distribution
Published: Apr 06, 2026
Source: NVD
CVE-2026-33510 HIGH - 8.8

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application improperly trusts a URL parameter (callbackUrl), which is passed to redirect and router.push. An attacker can craft a malic...

Vendor: homarr-labs
Product: homarr
Published: Apr 06, 2026
Source: NVD
CVE-2026-29047 HIGH - 7.2

GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user can perform a SQL injection via the logs export feature. This vulnerability is fixed in 10.0.24 and 11.0.6.

Vendor: glpi-project
Product: glpi
Published: Apr 06, 2026
Source: NVD
CVE-2026-26263 HIGH - 8.1

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.

Vendor: glpi-project
Product: glpi
Published: Apr 06, 2026
Source: NVD