Common Vulnerabilities and Exposures (CVE)

CVE-2026-1839

Apr 7, 2026 05:22:00 UTC

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the...

CVE-2025-65115

Apr 7, 2026 05:19:50 UTC

Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Man...

CVE-2024-51983

Apr 7, 2026 05:11:27 UTC

An unauthenticated attacker who can connect to the Web Services feature (HTTP TCP port 80) can issue a WS-Scan SOAP request containing an unexpected JobToken value which will crash the target device. The device will reboot, after which the ...

CVE-2024-51984

Apr 7, 2026 05:01:43 UTC

An authenticated attacker can reconfigure the target device to use an external service (such as LDAP or FTP) controlled by the attacker. If an existing password is present for an external service, the attacker can force the target device to...

CVE-2026-0740

Apr 7, 2026 04:25:58 UTC

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. Th...

CVE-2026-32145

Apr 7, 2026 04:07:10 UTC

Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via multipart form body parsing. The multipart_body function bypasses configured max_body_size and max_files_size limits. When...

CVE-2023-5106

Apr 7, 2026 04:06:43 UTC

An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through ...

CVE-2025-47391

Apr 7, 2026 03:56:06 UTC

Memory corruption while processing a frame request from user.

CVE-2026-34589

Apr 7, 2026 03:56:04 UTC

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-co...

CVE-2026-34588

Apr 7, 2026 03:56:03 UTC

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wave...

CVE-2026-34982

Apr 7, 2026 03:56:01 UTC

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options a...

CVE-2026-33727

Apr 7, 2026 03:56:00 UTC

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability allows code execution as root from the low-privilege pihole account. Important context: the...

CVE-2025-47390

Apr 7, 2026 03:55:58 UTC

Memory corruption while preprocessing IOCTL request in JPEG driver.

CVE-2026-21382

Apr 7, 2026 03:55:57 UTC

Memory Corruption when handling power management requests with improperly sized input/output buffers.

CVE-2026-21380

Apr 7, 2026 03:55:56 UTC

Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.