Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,490
Quick preset (or use dates below)
Clear Filters
Showing 7,661 - 7,680 of 13,549 CVEs
CVE-2026-34794 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete reg...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34793 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplet...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34792 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete ...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34791 HIGH - 8.8

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete r...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-34790 HIGH - 7.1

Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without sanitization of directory traversal sequences, whic...

Vendor: Endian
Product: Endian Firewall
Published: Apr 02, 2026
Source: NVD
CVE-2026-31937 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in version 7.0.15.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-31935 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exhaustion, usually resulting in the Suricata process being shut down by the operating system. This issue has been patched in versions 7.0.15 and 8.0.4.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-31934 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a performance impact. This issue has been patched in version 8.0.4.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-5334 HIGH - 7.3

A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=edit&id=3 of the component Parameter Handler. This manipulation of the argument deptid causes sql injection. The attack is possible to be carried ou...

Vendor: itsourcecode
Product: online_enrollment_system
Published: Apr 02, 2026
Source: NVD
CVE-2026-5333 HIGH - 7.3

A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host results in command injection. The attack can be executed remotely. The exploit has been released to the ...

Vendor: defaultfuction
Product: content_management_system
Published: Apr 02, 2026
Source: NVD
CVE-2026-3692 HIGH - 8.8

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

Vendor: progress
Product: flowmon
Published: Apr 02, 2026
Source: NVD
CVE-2026-35168 HIGH - 8.8

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database conflict resolution feature (op=risolvi-conflitti-database) that accepts a JSON array of SQL statements via P...

Vendor: devcode-it
Product: openstamanager
Published: Apr 02, 2026
Source: NVD
CVE-2026-31933 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been patched in versions 7.0.15 and 8.0.4.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-31932 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-31931 HIGH - 7.5

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched in version 8.0.4.

Vendor: OISF
Product: suricata
Published: Apr 02, 2026
Source: NVD
CVE-2026-4636 HIGH - 8.1

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned by other users in a policy creation request, even if the URL path specifies an attacker-owned resour...

Published: Apr 02, 2026
Source: NVD
CVE-2026-4634 HIGH - 7.5

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high resource consumption and prolonged processing times, ultimatel...

Published: Apr 02, 2026
Source: NVD
CVE-2026-4282 HIGH - 7.4

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable access tokens, resulti...

Published: Apr 02, 2026
Source: NVD
CVE-2026-3872 HIGH - 7.3

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclo...

Published: Apr 02, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via multipart form body parsing. The multipart_body function bypasses configured max_body_size and max_files_size limits. When a multipart boundary is not present in a chunk, the parser ...

Vendor: gleam-wisp
Product: wisp
Published: Apr 02, 2026
Source: NVD