Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 7 April 2026
RSS14 vulnerabilities published on 7 April 2026
Severity:
FreeRDP: Remote Code Execution on Windows Machines
RLSA-2026:6005
A security update is available for FreeRDP, a software that allows remote access to Windows machines. If not updated, hackers could potentially take control of your Windows machine through a remote co...
8.8
Firefox Browser: Security Update to Fix Multiple Critical Flaws
RLSA-2026:5932
Firefox has released a security update to fix multiple critical bugs that could allow hackers to take control of your computer, steal sensitive information, or disrupt your browsing experience. Affect...
7.5
Totolink A7100RU Router Allows Remote Code Execution Through CGI Script
CVE-2026-5692
A security flaw in the Totolink A7100RU router's CGI script makes it possible for an attacker to execute unauthorized code on the router from a remote location. This could allow an attacker to take co...
6.9
Linux Kernel Real-Time Update Fixes Security Flaws
RLSA-2026:6036
Linux kernel updates fix security issues that could allow an attacker to take control of a system or disrupt network connections. This update is recommended for systems using the Real Time Linux Kerne...
7.3
Linux Kernel Update Fixes Security Flaws in ATM and Networking
RLSA-2026:6037
This update fixes security issues in the Linux kernel that could allow attackers to gain control of your system or disrupt network services. The update is recommended to ensure the stability and secur...
7.3
389 Directory Server: Remote Code Execution and Denial of Service
RLSA-2026:5513
A critical security update is available for 389 Directory Server, which could allow an attacker to take control of a server or make it unavailable. This update is recommended to prevent potential secu...
7.2
Python 3.11: Malicious URLs Can Execute Code
RLSA-2026:6281
A security update is available for Python 3.11 to prevent malicious URLs from executing code on your system. This issue affects anyone using Python 3.11 to open URLs from the command line. To stay sec...
7.1
Python 3.12 Command-Line Risk: Malicious URLs Can Hijack Browser
RLSA-2026:6283
A security update is available for Python 3.12 to prevent malicious websites from tricking users into opening unwanted or malicious links in their web browsers. This update fixes a vulnerability that ...
7.1
IBM opencryptoki update fixes critical security risk on IBM crypto cards
RLSA-2026:5587
IBM has released a security update for its opencryptoki software, which affects IBM crypto cards and software tokens. This update fixes a critical vulnerability that could allow an attacker to gain el...
6.8
IBM Concert Predictable File Naming Allows Local File Overwrite
CVE-2025-13044
IBM Concert versions 1.0.0 through 2.2.0 creates predictable temporary files that can be exploited by local users to overwrite arbitrary files on the system. This can lead to unauthorized data modific...
6.2
Nginx Server May Allow Attackers to Inject Data into Your Website
RLSA-2026:5581
A security update is available for the Nginx server software. This update fixes a vulnerability that could allow an attacker to inject malicious data into your website if they intercept your internet ...
5.9
GnuTLS: Data Theft and Crash Risks Due to Security Flaws
RLSA-2026:5585
GnuTLS, a library used by many applications to secure online communications, has two security issues that could allow hackers to steal sensitive information or crash software, potentially leading to d...
5.3
Online Hotel Booking 1.0 allows hackers to inject malicious code
CVE-2026-5705
A security weakness in the Online Hotel Booking 1.0 system makes it possible for hackers to inject malicious code into the system, potentially causing harm to users. This could lead to unauthorized ac...
5.3
CGA-5hr8-xvjm-6p6p
CGA-5hr8-xvjm-6p6p