Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,503
Quick preset (or use dates below)
Clear Filters
Showing 7,621 - 7,640 of 13,549 CVEs
CVE-2022-4986 HIGH - 7.5

Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service avai...

Published: Apr 02, 2026
Source: NVD
CVE-2026-35467 HIGH - 7.5

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.

Vendor: CERT/CC
Product: cveClient/encrypt-storage.js
Published: Apr 02, 2026
Source: NVD
CVE-2025-15620 HIGH - 8.6

HiOS Switch Platform versions 09.1.00 prior to 09.4.05 and 10.3.01 contains a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot c...

Vendor: Belden
Product: Hirschmann HiOS Switch Platform
Published: Apr 02, 2026
Source: NVD
CVE-2024-14033 HIGH - 7.5

Hirschmann Industrial IT products (BAT-R, BAT-F, BAT450-F, BAT867-R, BAT867-F, WLC, BAT Controller Virtual) contain a heap overflow vulnerability in the HiLCOS web interface that allows unauthenticated remote attackers to trigger a denial-of-service condition by sending specially crafted requests to...

Vendor: Belden
Product: Hirschmann EagleSDV
Published: Apr 02, 2026
Source: NVD
CVE-2026-34840 HIGH - 8.1

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Identity/Utils/SSO.ts) has decoupled signature verification and identity extraction. isSignatureValid() verifies the first <Signature> element i...

Vendor: OneUptime
Product: oneuptime
Published: Apr 02, 2026
Source: NVD
CVE-2026-34834 HIGH - 7.5

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session cookies were present. This allowed unauthenticated attackers to bypass security checks and access/modify user settings via...

Vendor: bulwarkmail
Product: webmail
Published: Apr 02, 2026
Source: NVD
CVE-2026-34833 HIGH - 7.5

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue ha...

Vendor: bulwarkmail
Product: webmail
Published: Apr 02, 2026
Source: NVD
CVE-2023-7343 HIGH - 7.8

HiSecOS web server versions 05.0.00 to 08.3.01 prior to 08.3.02 contains a privilege escalation vulnerability that allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted packets to the web server. Attackers can exploit ...

Published: Apr 02, 2026
Source: NVD
CVE-2026-5429 HIGH - 7.8

Unsanitized input during web page generation in the Kiro Agent webview in Kiro IDE before version 0.8.140 allows a remote unauthenticated threat actor to execute arbitrary code via a potentially damaging crafted color theme name when a local user opens the workspace. This issue requires the user to ...

Published: Apr 02, 2026
Source: NVD
CVE-2026-5418 HIGH - 7.3

A vulnerability was identified in appsmithorg appsmith up to 1.97. Impacted is the function computeDisallowedHosts of the file app/server/appsmith-interfaces/src/main/java/com/appsmith/util/WebClientUtils.java of the component Dashboard. Such manipulation leads to server-side request forgery. The at...

Published: Apr 02, 2026
Source: NVD
CVE-2026-34426 HIGH - 7.6

OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment variable normalization between approval and execution paths, allowing attackers to inject attacker-controlled environment variables into execution without approval system validation. At...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 02, 2026
Source: NVD
CVE-2025-43264 HIGH - 8.8

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43257 HIGH - 8.7

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43219 HIGH - 8.8

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2025-43202 HIGH - 8.8

This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memory corruption.

Vendor: Apple
Product: iOS and iPadOS, macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44303 HIGH - 7.5

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify protected parts of the file system.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44286 HIGH - 7.5

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access can input keyboard events to apps running on a locked device.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44250 HIGH - 8.2

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-44219 HIGH - 7.5

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious application with root privileges may be able to access private information.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2024-40858 HIGH - 7.1

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access Contacts without user consent.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD