Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
Showing 1,541 - 1,560 of 3,569 CVEs
CVE-2026-37345 CRITICAL - 9.8

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.

Published: Apr 16, 2026
Source: NVD
CVE-2026-37340 CRITICAL - 9.8

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.

Published: Apr 16, 2026
Source: NVD
CVE-2026-37339 CRITICAL - 9.8

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.

Published: Apr 16, 2026
Source: NVD
CVE-2026-37338 CRITICAL - 9.4

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.

Published: Apr 16, 2026
Source: NVD
CVE-2026-6270 CRITICAL - 9.1

@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instances. When a Fastify application registers authentication middleware in a parent scope and then registers child plugins with @fastify/middie, the child scope does not inherit the pare...

Vendor: npm
Product: @fastify/middie
Published: Apr 16, 2026
Source: NVD
CVE-2026-31843 CRITICAL - 9.8

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any() without authentication middleware, enabling ...

Vendor: goodoneuz
Product: pay-uz
Published: Apr 16, 2026
Source: NVD
CVE-2026-3596 CRITICAL - 9.8

The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopriv_install-imprint') that maps to the ink_pd_add_option() function. This function reads �...

Published: Apr 16, 2026
Source: NVD
CVE-2026-6350 CRITICAL - 9.8

MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.

Published: Apr 16, 2026
Source: NVD
CVE-2026-40504 CRITICAL - 9.8

Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string literals at global scope. Attackers can exploit insufficient bounds checking in gravity_fiber_reassign(...

Vendor: marcobambini
Product: gravity
Published: Apr 16, 2026
Source: NVD
CVE-2026-40959 CRITICAL - 9.3

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

Vendor: Luanti
Product: Luanti
Published: Apr 16, 2026
Source: NVD
CVE-2026-32179 CRITICAL - 9.8

MsQuic has a Remote Elevation of Privilege Vulnerability

Vendor: nuget
Product: Microsoft.Native.Quic.MsQuic.OpenSSL
Published: Apr 16, 2026
Source: GitHub
CVE-2026-4880 CRITICAL - 9.8

The Barcode Scanner (+Mobile App) โ€“ Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up to, and including, 1.11.0. This is due to the plugin trusting a user-supplied Bas...

Published: Apr 16, 2026
Source: NVD
CVE-2026-6388 CRITICAL - 9.1

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on ...

Published: Apr 15, 2026
Source: NVD
CVE-2026-40173 CRITICAL - 9.4

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without authentication, exposing the full process command line includ...

Vendor: dgraph-io
Product: dgraph
Published: Apr 15, 2026
Source: NVD
CVE-2026-6296 CRITICAL - 9.6

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Vendor: google
Product: chrome
Published: Apr 15, 2026
Source: NVD
CVE-2025-41118 CRITICAL - 9.1

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyr...

Vendor: Grafana
Product: Pyroscope
Published: Apr 15, 2026
Source: NVD
CVE-2026-40478 CRITICAL - 9.1

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neu...

Vendor: maven
Product: org.thymeleaf:thymeleaf
Published: Apr 15, 2026
Source: GitHub
CVE-2026-40477 CRITICAL - 9.1

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restric...

Vendor: maven
Product: org.thymeleaf:thymeleaf
Published: Apr 15, 2026
Source: GitHub
CVE-2026-40575 CRITICAL - 9.1

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header so...

Vendor: go
Product: github.com/oauth2-proxy/oauth2-proxy/v7
Published: Apr 15, 2026
Source: GitHub
CVE-2026-30993 CRITICAL - 9.8

Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.

Published: Apr 15, 2026
Source: NVD