Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,021 - 2,040 of 3,443 CVEs
CVE-2026-20688 CRITICAL - 9.3

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to break out of its sandbox.

Vendor: Apple
Product: iOS and iPadOS, macOS, visionOS
Published: Mar 25, 2026
Source: NVD
CVE-2025-33244 CRITICAL - 9.0

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlier than 2.6. A successful exploit of this vulnerability might lead to code execution, denial of servic...

Vendor: NVIDIA
Product: Apex
Published: Mar 24, 2026
Source: NVD
CVE-2026-33511 CRITICAL - 9.8

pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofing. This allows unauthenticated remote users t...

Vendor: pyload
Product: pyload
Published: Mar 24, 2026
Source: NVD
CVE-2026-33407 CRITICAL - 9.1

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking. The server performs DNS resolution on user-supplied search ...

Vendor: ellite
Product: Wallos
Published: Mar 24, 2026
Source: NVD
CVE-2026-33340 CRITICAL - 9.1

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. The `@router.post("/api/proxy")` endpoint allows unauthenticate...

Vendor: ParisNeo
Product: lollms-webui
Published: Mar 24, 2026
Source: NVD
CVE-2026-33334 CRITICAL - 9.6

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `contextIsolation` or `sandbox`. This means any cross-site scripting (XSS) vulnerabili...

Vendor: go-vikunja
Product: vikunja
Published: Mar 24, 2026
Source: NVD
CVE-2025-71275 CRITICAL - 9.8

Zimbra Collaboration Suite (ZCS) PostJournal service version 8.8.15 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by exploiting improper sanitization of the RCPT TO parameter via SMTP injection. Attackers can inject shell expans...

Vendor: Zimbra
Product: Zimbra Collaboration Suite
Published: Mar 24, 2026
Source: NVD
CVE-2026-4729 CRITICAL - 9.8

Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4725 CRITICAL - 10.0

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4724 CRITICAL - 9.1

Undefined behavior in the Audio/Video component. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4723 CRITICAL - 9.8

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4721 CRITICAL - 9.8

Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerabilit...

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4720 CRITICAL - 9.8

Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &l...

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4717 CRITICAL - 9.8

Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4716 CRITICAL - 9.1

Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4715 CRITICAL - 9.1

Uninitialized memory in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4711 CRITICAL - 9.8

Use-after-free in the Widget: Cocoa component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4710 CRITICAL - 9.8

Incorrect boundary conditions in the Audio/Video component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4705 CRITICAL - 9.8

Undefined behavior in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4702 CRITICAL - 9.8

JIT miscompilation in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD