Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
Showing 2,021 - 2,040 of 3,576 CVEs
CVE-2026-26831 CRITICAL - 9.8

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequat...

Vendor: dbashford
Product: textract
Published: Mar 25, 2026
Source: NVD
CVE-2026-26830 CRITICAL - 9.8

pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths into shell command strings that are executed via child_process...

Published: Mar 25, 2026
Source: NVD
CVE-2025-59707 CRITICAL - 9.8

In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability.

Vendor: n2w
Product: n2w
Published: Mar 25, 2026
Source: NVD
CVE-2025-59706 CRITICAL - 9.8

In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.

Vendor: n2w
Product: n2w
Published: Mar 25, 2026
Source: NVD
CVE-2025-32991 CRITICAL - 9.0

In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.

Vendor: n2w
Product: backup\&_recovery
Published: Mar 25, 2026
Source: NVD
CVE-2026-28858 CRITICAL - 9.8

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

Vendor: Apple
Product: iOS and iPadOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-28827 CRITICAL - 9.3

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD
CVE-2026-20688 CRITICAL - 9.3

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to break out of its sandbox.

Vendor: Apple
Product: iOS and iPadOS, macOS, visionOS
Published: Mar 25, 2026
Source: NVD
CVE-2025-33244 CRITICAL - 9.0

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability affects environments that use PyTorch versions earlier than 2.6. A successful exploit of this vulnerability might lead to code execution, denial of servic...

Vendor: NVIDIA
Product: Apex
Published: Mar 24, 2026
Source: NVD
CVE-2026-33511 CRITICAL - 9.8

pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator in pyLoad's ClickNLoad feature can be bypassed by any remote attacker through HTTP Host header spoofing. This allows unauthenticated remote users t...

Vendor: pyload
Product: pyload
Published: Mar 24, 2026
Source: NVD
CVE-2026-33407 CRITICAL - 9.1

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking. The server performs DNS resolution on user-supplied search ...

Vendor: ellite
Product: Wallos
Published: Mar 24, 2026
Source: NVD
CVE-2026-33340 CRITICAL - 9.1

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. The `@router.post("/api/proxy")` endpoint allows unauthenticate...

Vendor: ParisNeo
Product: lollms-webui
Published: Mar 24, 2026
Source: NVD
CVE-2026-33334 CRITICAL - 9.6

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `contextIsolation` or `sandbox`. This means any cross-site scripting (XSS) vulnerabili...

Vendor: go-vikunja
Product: vikunja
Published: Mar 24, 2026
Source: NVD
CVE-2025-71275 CRITICAL - 9.8

Zimbra Collaboration Suite (ZCS) PostJournal service version 8.8.15 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by exploiting improper sanitization of the RCPT TO parameter via SMTP injection. Attackers can inject shell expans...

Vendor: Zimbra
Product: Zimbra Collaboration Suite
Published: Mar 24, 2026
Source: NVD
CVE-2026-4729 CRITICAL - 9.8

Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4725 CRITICAL - 10.0

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4724 CRITICAL - 9.1

Undefined behavior in the Audio/Video component. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4723 CRITICAL - 9.8

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4721 CRITICAL - 9.8

Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerabilit...

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4720 CRITICAL - 9.8

Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &l...

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD