Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,761 - 1,780 of 3,443 CVEs
CVE-2026-35184 CRITICAL - 9.8

EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the custom and value parameters. This vulnerability is fixed in 8.0.0.

Vendor: phili67
Product: ecclesiacrm
Published: Apr 06, 2026
Source: NVD
CVE-2026-35022 CRITICAL - 9.8

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in authentication helper execution where helper configuration values are executed using shell=true without input validation. Attackers who can influence authentication settings can inject shell metacharacter...

Vendor: Anthropic
Product: Claude Code, Claude Agent SDK for Python
Published: Apr 06, 2026
Source: NVD
CVE-2025-54328 CRITICAL - 10.0

An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. A Stack-based Buffer Overflow occurs while parsing SMS RP-DATA ...

Vendor: samsung
Product: exynos_980_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2025-58349 CRITICAL - 9.1

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Incorrect handling of LTE MAC packets containing many MAC Contro...

Vendor: samsung
Product: exynos_990_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-35174 CRITICAL - 9.1

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings permission to change the uploads path to any folder. This vulnerability allows the user to download an...

Vendor: xenocrat
Product: chyrp-lite
Published: Apr 06, 2026
Source: NVD
CVE-2026-35050 CRITICAL - 9.1

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save extention settings in "py" format and in the app root directory. This allows to overwrite python files, for instance the "download-model.py" file could be overw...

Vendor: oobabooga
Product: text-generation-webui
Published: Apr 06, 2026
Source: NVD
CVE-2026-35047 CRITICAL - 9.8

Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitrary files, including executable scripts. This may lead to Remote Code Execution (RCE) on the server, potentially resulting in full system compromise, d...

Vendor: Ajax30
Product: BraveCMS-2.0
Published: Apr 06, 2026
Source: NVD
CVE-2026-35490 CRITICAL - 9.8

changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route() must be the outermost decorator because it registers the function it receives. Whe...

Vendor: pip
Product: changedetection.io
Published: Apr 06, 2026
Source: GitHub
CVE-2026-31151 CRITICAL - 9.8

An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the application 's resources.

Vendor: kaleris
Product: yard_management_solutions
Published: Apr 06, 2026
Source: NVD
CVE-2026-31059 CRITICAL - 9.8

A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string.

Vendor: utt
Product: 520w_firmware
Published: Apr 06, 2026
Source: NVD
CVE-2026-26026 CRITICAL - 9.1

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

Vendor: glpi-project
Product: glpi
Published: Apr 06, 2026
Source: NVD
CVE-2019-25687 CRITICAL - 9.8

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action...

Vendor: wisdom
Product: Pegasus CMS
Published: Apr 05, 2026
Source: NVD
CVE-2018-25254 CRITICAL - 9.8

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect...

Vendor: nico-ftp
Product: NICO-FTP
Published: Apr 04, 2026
Source: NVD
CVE-2016-20052 CRITICAL - 9.8

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by access...

Vendor: Snewscms
Product: Snews CMS upload sheller
Published: Apr 04, 2026
Source: NVD
CVE-2026-35459 CRITICAL - 9.1

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to BaseDownloader.download() that checks the hostname of the initial download URL. However,...

Vendor: pip
Product: pyload-ng
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35616 CRITICAL - 9.8

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Vendor: Fortinet
Product: FortiClientEMS
Published: Apr 04, 2026
Source: NVD
CVE-2026-34612 CRITICAL - 9.9

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the following endpoint "GET /api/v1/main/flows/search". Once a user is authe...

Vendor: kestra-io
Product: kestra
Published: Apr 03, 2026
Source: NVD
CVE-2021-4477 CRITICAL - 9.1

Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connections to bypass configured firewall rules. Attackers can exploit this vulnerability by establishing IPv6 IPsec connections (IKEv1 or IKEv2) while simulta...

Published: Apr 03, 2026
Source: NVD
CVE-2018-25236 CRITICAL - 9.8

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by crafting specially formed HTTP requests. Attac...

Vendor: Belden
Product: Hirschmann HiOS, Hirschmann HiSecOS EAGLE
Published: Apr 03, 2026
Source: NVD
CVE-2017-20236 CRITICAL - 9.8

ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows remote attackers to inject and execute system commands by submitting malicious input through unvalidated fields. Attackers can exploit this vulnerabil...

Vendor: ProSoft Technology
Product: ICX35-HWC Cellular Gateway
Published: Apr 03, 2026
Source: NVD