Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,061 - 2,080 of 3,443 CVEs
CVE-2026-2298 CRITICAL - 9.4

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 30th, 2026.

Published: Mar 23, 2026
Source: NVD
CVE-2026-33716 CRITICAL - 9.4

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that overrides where the server sends token verification requests. An atta...

Vendor: WWBN
Product: AVideo
Published: Mar 23, 2026
Source: NVD
CVE-2026-4404 CRITICAL - 9.4

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Published: Mar 23, 2026
Source: NVD
CVE-2026-4585 CRITICAL - 9.8

A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/ImportSystemConfiguration.jsp of the component Configuration Handler. The manipulation of the argument File leads to os command injec...

Published: Mar 23, 2026
Source: NVD
CVE-2026-32968 CRITICAL - 9.8

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.

Vendor: MB connect line, Helmholz
Product: MB connect line mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
Published: Mar 23, 2026
Source: NVD
CVE-2026-3587 CRITICAL - 10.0

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface and gain root access to the underlying Linux based OS, leading to full compromise of the device.

Published: Mar 23, 2026
Source: NVD
CVE-2026-4599 CRITICAL - 9.1

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compare...

Vendor: jsrsasign_project
Product: jsrsasign
Published: Mar 23, 2026
Source: NVD
CVE-2026-4567 CRITICAL - 9.8

A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and m...

Published: Mar 23, 2026
Source: NVD
CVE-2019-25614 CRITICAL - 9.8

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containi...

Vendor: Freefloat
Product: Free Float FTP
Published: Mar 22, 2026
Source: NVD
CVE-2019-25568 CRITICAL - 9.8

Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable, which executes with sy...

Vendor: Memuplay
Product: Memu Play
Published: Mar 21, 2026
Source: NVD
CVE-2026-24060 CRITICAL - 9.1

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filt...

Vendor: Automated Logic
Product: WebCTRL Premium Server
Published: Mar 21, 2026
Source: NVD
CVE-2026-29796 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then is...

Vendor: IGL-Technologies
Product: eParking.fi
Published: Mar 20, 2026
Source: NVD
CVE-2026-25192 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then is...

Vendor: CTEK
Product: Chargeportal
Published: Mar 20, 2026
Source: NVD
CVE-2026-21732 CRITICAL - 9.6

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Mar 20, 2026
Source: NVD
CVE-2026-3584 CRITICAL - 9.8

The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined ...

Published: Mar 20, 2026
Source: NVD
CVE-2026-33502 CRITICAL - 9.3

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to make the AVideo server send HTTP requests to arbitrary URLs. This can be used to probe localhost/intern...

Vendor: composer
Product: wwbn/avideo
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33494 CRITICAL - 10.0

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal. An attacker can craft a URL containing path traversal sequen...

Vendor: go
Product: github.com/ory/oathkeeper
Published: Mar 20, 2026
Source: GitHub

MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined weaknesses: (1) distinguishable error responses that enabl...

Vendor: go
Product: github.com/minio/minio
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33478 CRITICAL - 10.0

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json.php` endpoint exposes clone secret keys with...

Vendor: composer
Product: avideo/avideo
Published: Mar 20, 2026
Source: GitHub
CVE-2026-22901 CRITICAL - 9.8

A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

Vendor: QNAP Systems Inc.
Product: QuNetSwitch
Published: Mar 20, 2026
Source: NVD