Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,958
Quick preset (or use dates below)
Clear Filters
Showing 1,341 - 1,360 of 3,557 CVEs
CVE-2026-41462 CRITICAL - 9.8

ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username fie...

Vendor: ProjeQtor
Product: ProjeQtor
Published: Apr 27, 2026
Source: NVD
CVE-2026-30352 CRITICAL - 9.8

A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7125 CRITICAL - 9.8

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge leads to os command injection. The attack may be initiated remotely. The...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7124 CRITICAL - 9.8

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument addrPrefixLen can lead to os command injection. The attack can ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7123 CRITICAL - 9.8

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument setIptvCfg results in os command injection. The attack can be initiated remotely. The exploi...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7122 CRITICAL - 9.8

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection. It is possible to launch the attack remotely. The exploi...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7121 CRITICAL - 9.8

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument wizard causes os command injection. It is possible to initiate the attack remotely. The exploit has b...

Published: Apr 27, 2026
Source: NVD
CVE-2026-33453 CRITICAL - 10.0

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-s...

Vendor: Apache Software Foundation
Product: Apache Camel
Published: Apr 27, 2026
Source: NVD
CVE-2026-22337 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4.

Vendor: Directorist
Product: Directorist Social Login
Published: Apr 27, 2026
Source: NVD
CVE-2026-22336 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This issue affects Directorist Booking: from n/a before 3.0.2.

Vendor: Directorist Booking
Product: Directorist Booking
Published: Apr 27, 2026
Source: NVD
CVE-2026-41409 CRITICAL - 9.8

The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized was applied too late after a static initializer in a class to be read might already have been executed. Affected versions are Apache MINA 2.0.0 <...

Vendor: Apache Software Foundation
Product: Apache MINA
Published: Apr 27, 2026
Source: NVD
CVE-2026-33454 CRITICAL - 9.4

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direction via setInFilter...

Vendor: Apache Software Foundation
Product: Apache Camel
Published: Apr 27, 2026
Source: NVD
CVE-2026-41635 CRITICAL - 9.8

Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at all, bypassing the classname allowlist and allowing arbitrary code to be executed. The fix checks if the class is present in the accepted clas...

Vendor: Apache Software Foundation
Product: Apache MINA
Published: Apr 27, 2026
Source: NVD
CVE-2026-40860 CRITICAL - 9.8

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is ...

Vendor: Apache Software Foundation
Product: Apache Camel
Published: Apr 27, 2026
Source: NVD
CVE-2026-40453 CRITICAL - 9.9

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP Header...

Vendor: Apache Software Foundation
Product: Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub
Published: Apr 27, 2026
Source: NVD
CVE-2026-42363 CRITICAL - 9.3

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various...

Vendor: GeoVision Inc.
Product: GV-IP Device Utility
Published: Apr 27, 2026
Source: NVD
CVE-2026-7037 CRITICAL - 9.8

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru results in os command injection. The attack can be executed remotely...

Published: Apr 26, 2026
Source: NVD
CVE-2026-41571 CRITICAL - 9.4

Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored password. OIDC-registered users are created with an empty password, so anyone who submits pass...

Vendor: go
Product: github.com/enchant97/note-mark/backend
Published: Apr 25, 2026
Source: GitHub
CVE-2026-31685 CRITICAL - 9.4

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` derives a modified EUI-64 from the Ethernet source address and compares it with the low 64 bits of the IPv6 source address. The existing guard only re...

Vendor: Linux
Product: Linux
Published: Apr 25, 2026
Source: NVD
CVE-2026-31682 CRITICAL - 9.1

In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses neighbour discovery options from ns->opt[] and assumes that these options are in the linear part of request. Its callers only guarantee that the I...

Vendor: Linux
Product: Linux
Published: Apr 25, 2026
Source: NVD