Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
30289
Total
2415
Critical
9078
High
9425
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-34378 | MEDIUM | 6.5 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.4.0 to before … | Apr 06, 2026 |
| CVE-2026-34217 | UNKNOWN | — | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sandboxjs. The vulnerability allows untrusted sandboxed code to leak internal … | Apr 06, 2026 |
| CVE-2026-34211 | UNKNOWN | — | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion in the restOfExp function and the lispify/lispifyExpr call chain. An … | Apr 06, 2026 |
| CVE-2026-34208 | CRITICAL | 10.0 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can … | Apr 06, 2026 |
| CVE-2026-34148 | HIGH | 7.5 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively … | Apr 06, 2026 |
| CVE-2026-33752 | HIGH | 8.6 | curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via … | Apr 06, 2026 |
| CVE-2026-33727 | MEDIUM | 6.4 | Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability allows code execution as root from the … | Apr 06, 2026 |
| CVE-2026-33405 | LOW | 3.1 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, the formatInfo() … | Apr 06, 2026 |
| CVE-2026-31354 | UNKNOWN | — | Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via … | Apr 06, 2026 |
| CVE-2026-31353 | UNKNOWN | — | An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via … | Apr 06, 2026 |
| CVE-2026-31352 | UNKNOWN | — | An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML … | Apr 06, 2026 |
| CVE-2026-31351 | MEDIUM | 4.8 | An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via … | Apr 06, 2026 |
| CVE-2026-31350 | UNKNOWN | — | An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload … | Apr 06, 2026 |
| CVE-2026-21382 | HIGH | 7.8 | Memory Corruption when handling power management requests with improperly sized input/output buffers. | Apr 06, 2026 |
| CVE-2026-21381 | HIGH | 7.6 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | Apr 06, 2026 |
| CVE-2026-21380 | HIGH | 7.8 | Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory. | Apr 06, 2026 |
| CVE-2026-21378 | HIGH | 7.8 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | Apr 06, 2026 |
| CVE-2026-21376 | HIGH | 7.8 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | Apr 06, 2026 |
| CVE-2026-21375 | HIGH | 7.8 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | Apr 06, 2026 |
| CVE-2026-21374 | HIGH | 7.8 | Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validation. | Apr 06, 2026 |
| CVE-2026-21373 | HIGH | 7.8 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. | Apr 06, 2026 |
| CVE-2026-21372 | HIGH | 7.8 | Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations. | Apr 06, 2026 |
| CVE-2026-21371 | HIGH | 7.8 | Memory Corruption when retrieving output buffer with insufficient size validation. | Apr 06, 2026 |
| CVE-2026-21367 | HIGH | 7.6 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | Apr 06, 2026 |
| CVE-2025-47400 | HIGH | 7.1 | Cryptographic issue while copying data to a destination buffer without validating its size. | Apr 06, 2026 |