Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,540
Quick preset (or use dates below)
Clear Filters
Showing 7,441 - 7,460 of 13,544 CVEs
CVE-2026-26027 HIGH - 7.5

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.

Vendor: glpi-project
Product: glpi
Published: Apr 06, 2026
Source: NVD
CVE-2026-25932 HIGH - 7.2

GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.

Vendor: glpi-project
Product: glpi
Published: Apr 06, 2026
Source: NVD
CVE-2026-30078 HIGH - 7.5

OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires InitiatingMessage but sent with successfulOutcome.

Vendor: openairinterface
Product: oai-cn5g-amf
Published: Apr 06, 2026
Source: NVD
CVE-2026-3524 HIGH - 8.8

Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5648 HIGH - 7.3

A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /userfinishregister.php of the component Parameter Handler. This manipulation of the argument firstName causes sql injection. Remote exploitation of the attack is possible. The explo...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5646 HIGH - 7.3

A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed ...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5645 HIGH - 7.3

A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /pay.php of the component Parameter Handler. Executing a manipulation of the argument mpesa can lead to sql injection. The attack can be launched remotely. Th...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5642 HIGH - 7.3

A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affects an unknown function of the file /viva/update.php of the component HTTP POST Request Handler. This manipulation of the argument Name causes improper authorization. It is ...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5637 HIGH - 7.3

A security vulnerability has been detected in projectworlds Car Rental System 1.0. This vulnerability affects unknown code of the file /message_admin.php of the component Parameter Handler. Such manipulation of the argument Message leads to sql injection. The attack may be launched remotely. The exp...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5634 HIGH - 7.3

A vulnerability was identified in projectworlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /book_car.php of the component Parameter Handler. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The ex...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5633 HIGH - 7.3

A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been pub...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5632 HIGH - 7.3

A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be us...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5631 HIGH - 7.3

A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/server_utils.py of the component ws Endpoint. Such manipulation of the argument args leads to code injection. The attack may be performed from remote. T...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5629 HIGH - 8.8

A vulnerability was detected in Belkin F9K1015 1.00.10. The affected element is the function formSetFirewall of the file /goform/formSetFirewall. The manipulation of the argument webpage results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5628 HIGH - 8.8

A security vulnerability has been detected in Belkin F9K1015 1.00.10. Impacted is the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handler. The manipulation of the argument webpage leads to stack-based buffer overflow. Remote exploitation of the a...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5616 HIGH - 7.3

A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the component AI Chat Module. Such manipulation leads to mi...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5614 HIGH - 8.8

A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the publ...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5613 HIGH - 8.8

A vulnerability was identified in Belkin F9K1015 1.00.10. This issue affects the function formReboot of the file /goform/formReboot. The manipulation of the argument webpage leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be use...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5612 HIGH - 8.8

A vulnerability was determined in Belkin F9K1015 1.00.10. This vulnerability affects the function formWlEncrypt of the file /goform/formWlEncrypt. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been publi...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5611 HIGH - 8.8

A vulnerability was found in Belkin F9K1015 1.00.10. This affects the function formCrossBandSwitch of the file /goform/formCrossBandSwitch. Performing a manipulation of the argument webpage results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public...

Published: Apr 06, 2026
Source: NVD