CVE Find is a real-time vulnerability database indexing 342 280 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 1381 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-35039 |
2026-04-06 17h17 +00:00 |
fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.1.0, setting up a... Input Validation |
9.1 |
Critical |
|
CVE-2026-34976 |
2026-04-06 17h17 +00:00 |
Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin muta... Authorization problems |
10 |
Critical |
|
CVE-2026-34975 |
2026-04-06 17h17 +00:00 |
Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header inject... |
8.5 |
High |
|
CVE-2026-34841 |
2026-04-06 17h17 +00:00 |
Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a ... |
9.8 |
Critical |
|
CVE-2026-34982 |
2026-04-06 16h16 +00:00 |
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypas... OS Command Injection |
8.2 |
High |
|
CVE-2026-34950 |
2026-04-06 16h16 +00:00 |
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMa... |
9.1 |
Critical |
|
CVE-2026-34208 |
2026-04-06 16h16 +00:00 |
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to... |
10 |
Critical |
|
CVE-2026-33752 |
2026-04-06 16h16 +00:00 |
curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to... Server-Side Request Forgery - SSRF |
8.6 |
High |
|
CVE-2025-47392 |
2026-04-06 16h16 +00:00 |
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.... |
8.8 |
High |
|
CVE-2026-34885 |
2026-04-06 15h17 +00:00 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i... SQL Injection |
8.5 |
High |