Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,001 - 2,020 of 3,443 CVEs
CVE-2026-25031 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.

Vendor: park_of_ideas
Product: Tasty Daily
Published: Mar 25, 2026
Source: NVD
CVE-2026-25030 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.

Vendor: park_of_ideas
Product: Goldish
Published: Mar 25, 2026
Source: NVD
CVE-2026-25029 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.

Vendor: park_of_ideas
Product: KIDZ
Published: Mar 25, 2026
Source: NVD
CVE-2026-24993 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects Advanced WooCommerce Product Sales Repor...

Vendor: WPFactory
Product: Advanced WooCommerce Product Sales Reporting
Published: Mar 25, 2026
Source: NVD
CVE-2026-24989 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.

Vendor: FantasticPlugins
Product: SUMO Affiliates Pro
Published: Mar 25, 2026
Source: NVD
CVE-2026-24971 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8.

Vendor: Elated-Themes
Product: Search & Go
Published: Mar 25, 2026
Source: NVD
CVE-2026-24968 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30.

Vendor: Xagio SEO
Product: Xagio SEO
Published: Mar 25, 2026
Source: NVD
CVE-2026-24378 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.

Vendor: Metagauss
Product: EventPrime
Published: Mar 25, 2026
Source: NVD
CVE-2026-22507 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through <= 1.2.6.

Vendor: AncoraThemes
Product: Beelove
Published: Mar 25, 2026
Source: NVD
CVE-2026-22500 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 | Construction and Tools Store: from n/a through <= 1.1.2.

Vendor: axiomthemes
Product: m2 | Construction and Tools Store
Published: Mar 25, 2026
Source: NVD
CVE-2026-22484 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL Injection.This issue affects Lisfinity Core: from n/a through <= 1.5.0.

Vendor: pebas
Product: Lisfinity Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-26833 CRITICAL - 9.8

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.

Vendor: mmahrous
Product: thumbler
Published: Mar 25, 2026
Source: NVD
CVE-2026-26832 CRITICAL - 9.8

node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. The file path parameter is concatenated into a shell command string and passed to child_process.exec(...

Published: Mar 25, 2026
Source: NVD
CVE-2026-26831 CRITICAL - 9.8

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequat...

Vendor: dbashford
Product: textract
Published: Mar 25, 2026
Source: NVD
CVE-2026-26830 CRITICAL - 9.8

pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths into shell command strings that are executed via child_process...

Published: Mar 25, 2026
Source: NVD
CVE-2025-59707 CRITICAL - 9.8

In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability.

Vendor: n2w
Product: n2w
Published: Mar 25, 2026
Source: NVD
CVE-2025-59706 CRITICAL - 9.8

In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.

Vendor: n2w
Product: n2w
Published: Mar 25, 2026
Source: NVD
CVE-2025-32991 CRITICAL - 9.0

In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.

Vendor: n2w
Product: backup\&_recovery
Published: Mar 25, 2026
Source: NVD
CVE-2026-28858 CRITICAL - 9.8

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

Vendor: Apple
Product: iOS and iPadOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-28827 CRITICAL - 9.3

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD