Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,041 - 2,060 of 3,443 CVEs
CVE-2026-4701 CRITICAL - 9.8

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4700 CRITICAL - 9.8

Mitigation bypass in the Networking: HTTP component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4698 CRITICAL - 9.8

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4696 CRITICAL - 9.8

Use-after-free in the Layout: Text and Fonts component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4692 CRITICAL - 10.0

Sandbox escape in the Responsive Design Mode component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4691 CRITICAL - 9.8

Use-after-free in the CSS Parsing and Computation component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4689 CRITICAL - 10.0

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-4688 CRITICAL - 10.0

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-33475 CRITICAL - 9.1

Langflow is a tool for building and deploying AI-powered agents and workflows. An unauthenticated remote shell injection vulnerability exists in multiple GitHub Actions workflows in the Langflow repository prior to version 1.9.0. Unsanitized interpolation of GitHub context variables (e.g., `${{ gith...

Vendor: langflow-ai
Product: langflow
Published: Mar 24, 2026
Source: NVD
CVE-2019-25646 CRITICAL - 9.8

Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter. Attackers can connect to the SMTP service on port 25 and send a malicious MAIL FROM command with an oversize...

Vendor: Tabs
Product: Mail Carrier
Published: Mar 24, 2026
Source: NVD
CVE-2019-25628 CRITICAL - 9.8

Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and ex...

Vendor: Speedbit
Product: Download Accelerator Plus DAP
Published: Mar 24, 2026
Source: NVD
CVE-2026-4755 CRITICAL - 9.8

CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

Vendor: molotovcherry
Product: android-imagemagick7
Published: Mar 24, 2026
Source: NVD
CVE-2026-4753 CRITICAL - 9.1

Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.

Published: Mar 24, 2026
Source: NVD
CVE-2026-4750 CRITICAL - 9.1

Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0.

Published: Mar 24, 2026
Source: NVD
CVE-2026-4283 CRITICAL - 9.1

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirma...

Published: Mar 24, 2026
Source: NVD
CVE-2026-4001 CRITICAL - 9.8

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within includes/process/price.php. This is due to insufficient sanitization...

Published: Mar 24, 2026
Source: NVD
CVE-2026-33634 CRITICAL - 8.8

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with maliciou...

Vendor: aquasecurity
Product: setup-trivy, trivy-action, trivy
Published: Mar 23, 2026
Source: NVD
CVE-2026-32913 CRITICAL - 9.3

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended ...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 23, 2026
Source: NVD
CVE-2025-60949 CRITICAL - 9.1

Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.

Vendor: Census
Product: CSWeb
Published: Mar 23, 2026
Source: NVD
CVE-2026-30849 CRITICAL - 9.8

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter. Other database backends are not affect...

Vendor: mantisbt
Product: mantisbt
Published: Mar 23, 2026
Source: NVD