Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
Showing 1,721 - 1,740 of 3,569 CVEs
CVE-2026-39847 CRITICAL - 9.1

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traversal attacks. An attacker can use ../ sequences (eg /__emmett__/../rsgi/handlers.py) to read arbi...

Vendor: emmett-framework
Product: emmett
Published: Apr 07, 2026
Source: NVD
CVE-2026-39846 CRITICAL - 9.0

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, crea...

Vendor: siyuan-note
Product: siyuan
Published: Apr 07, 2026
Source: NVD
CVE-2026-28386 CRITICAL - 9.1

Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for ...

Vendor: OpenSSL
Product: OpenSSL
Published: Apr 07, 2026
Source: NVD
CVE-2026-39397 CRITICAL - 9.4

@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAccess: true, bypassing all collection-level access control....

Vendor: delmaredigital
Product: payload-puck
Published: Apr 07, 2026
Source: NVD
CVE-2025-69515 CRITICAL - 9.1

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location.

Published: Apr 07, 2026
Source: NVD
CVE-2026-39355 CRITICAL - 9.9

Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary non-personal teams to themselves. This enables complete takeover of other users’ team workspaces an...

Vendor: MGeurts
Product: genealogy
Published: Apr 07, 2026
Source: NVD
CVE-2026-39351 CRITICAL - 9.1

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.

Vendor: frappe
Product: frappe
Published: Apr 07, 2026
Source: NVD
CVE-2025-71058 CRITICAL - 9.1

Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configured upstream DNS server. The implementation matches responses primarily by TXID and inserts results into the cache, enabling a remote attacker to inject ...

Published: Apr 07, 2026
Source: NVD
CVE-2026-39339 CRITICAL - 9.1

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated attackers to access all protected API endpoints by including "api/public...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-39337 CRITICAL - 10.0

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server com...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secrets:. If cookie decryption fails, the implementation falls back to a default decoder instead of rejecting the cookie. This...

Vendor: rack
Product: rack-session
Published: Apr 07, 2026
Source: NVD
CVE-2026-35573 CRITICAL - 9.1

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. T...

Vendor: ChurchCRM
Product: CRM
Published: Apr 07, 2026
Source: NVD
CVE-2026-31272 CRITICAL - 9.8

MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks proper authorization validation, enabling direct addition of super administrator accounts without authentication.

Vendor: mrcms
Product: mrcms
Published: Apr 07, 2026
Source: NVD
CVE-2026-31271 CRITICAL - 9.8

megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality. The insert() method in UserController.java lacks authentication checks, allowing unauthenticated attackers to create super administrator accounts by directly accessing the /user/insert endp...

Published: Apr 07, 2026
Source: NVD
CVE-2026-4631 CRITICAL - 9.8

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH op...

Published: Apr 07, 2026
Source: NVD
CVE-2026-35614 CRITICAL - 9.8

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fixed in 16.14.0 and 15.104.0.

Vendor: frappe
Product: frappe
Published: Apr 07, 2026
Source: NVD
CVE-2026-35580 CRITICAL - 9.1

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated directly into shell commands via ${{ }} expression syntax. An attacker with repository write access co...

Vendor: NationalSecurityAgency
Product: emissary
Published: Apr 07, 2026
Source: NVD
CVE-2026-23696 CRITICAL - 9.9

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing ...

Vendor: Windmill Labs, Nextcloud
Product: Windmill CE (Community Edition), Windmill EE (Enterprise Edition), Flow
Published: Apr 07, 2026
Source: NVD
CVE-2024-36058 CRITICAL - 9.8

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database.

Published: Apr 07, 2026
Source: NVD
CVE-2026-33816 CRITICAL - 9.8

Memory-safety vulnerability in github.com/jackc/pgx/v5.

Vendor: github.com/jackc/pgx/v5
Product: github.com/jackc/pgx/v5/pgproto3
Published: Apr 07, 2026
Source: NVD