Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,501
Quick preset (or use dates below)
Clear Filters
Showing 7,641 - 7,660 of 13,549 CVEs
CVE-2024-40849 HIGH - 7.5

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Apr 02, 2026
Source: NVD
CVE-2023-7342 HIGH - 8.8

HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted packets to the web server. Attackers can exploit this flaw t...

Published: Apr 02, 2026
Source: NVD
CVE-2026-5368 HIGH - 7.3

A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This manipulation of the argument uname causes sql injection. Remote exploitation of the attack is possible. The exploit has ...

Published: Apr 02, 2026
Source: NVD
CVE-2026-34827 HIGH - 7.5

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition: form-data; name="..." using repeated String#index searches combined w...

Vendor: rack
Product: rack
Published: Apr 02, 2026
Source: NVD
CVE-2026-34577 HIGH - 8.6

Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the GET /public/stream endpoint in PublicController accepts a user-supplied url query parameter and proxies the full HTTP response back to the caller. The only validation is url.endsWith('mp4'), which is trivially bypas...

Vendor: gitroomhq
Product: postiz-app
Published: Apr 02, 2026
Source: NVD
CVE-2026-34576 HIGH - 7.7

Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-from-url endpoint accepts a user-supplied URL and fetches it server-side using axios.get() with no SSRF protections. The only validation is a file extension check (.png, .jpg, etc.) which is trivially b...

Vendor: gitroomhq
Product: postiz-app
Published: Apr 02, 2026
Source: NVD
CVE-2026-34121 HIGH - 8.8

An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent parsing and authorization logic in JSON requests during authentication check. An unauthenticated attacker can append an authentication-exem...

Vendor: TP-Link Systems Inc.
Product: Tapo C520WS v2.6
Published: Apr 02, 2026
Source: NVD
CVE-2026-35385 HIGH - 7.5

In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).

Vendor: OpenBSD
Product: OpenSSH
Published: Apr 02, 2026
Source: NVD
CVE-2026-34829 HIGH - 7.5

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a BoundedIO when CONTENT_LENGTH is present. When a multipart/form-data request is sent without a Content-Length header, such as with HTTP chunked transfer ...

Vendor: rack
Product: rack
Published: Apr 02, 2026
Source: NVD
CVE-2026-34785 HIGH - 7.5

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begin...

Vendor: rack
Product: rack
Published: Apr 02, 2026
Source: NVD
CVE-2025-65114 HIGH - 7.5

Apache Traffic Server allows request smuggling if chunked messages are malformed.ย  This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1. Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.

Vendor: Apache Software Foundation
Product: Apache Traffic Server
Published: Apr 02, 2026
Source: NVD
CVE-2025-58136 HIGH - 7.5

A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A workaround for older versions is to setย pr...

Vendor: Apache Software Foundation
Product: Apache Traffic Server
Published: Apr 02, 2026
Source: NVD
CVE-2026-5350 HIGH - 8.8

A security flaw has been discovered in Trendnet TEW-657BRM 1.00.1. The impacted element is the function update_pcdb of the file /setup.cgi. The manipulation of the argument mac_pc_dba results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the pu...

Vendor: trendnet
Product: tew-657brm_firmware
Published: Apr 02, 2026
Source: NVD
CVE-2026-5349 HIGH - 8.8

A vulnerability was identified in Trendnet TEW-657BRM 1.00.1. The affected element is the function add_apcdb of the file /setup.cgi. The manipulation of the argument mac_pc_dba leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be ...

Vendor: trendnet
Product: tew-657brm_firmware
Published: Apr 02, 2026
Source: NVD
CVE-2026-34876 HIGH - 7.5

An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of...

Vendor: arm
Product: mbed_tls
Published: Apr 02, 2026
Source: NVD
CVE-2026-30332 HIGH - 7.5

A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows attackers to escalate privileges and execute arbitrary code via replacing a legitimate script with a crafted payload during the flashing process.

Published: Apr 02, 2026
Source: NVD
CVE-2026-5346 HIGH - 7.3

A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src/mcp-server.js of the component image-to-base64 Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. It is possible to launch the attack ...

Published: Apr 02, 2026
Source: NVD
CVE-2026-34797 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete re...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34796 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34795 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete reg...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD