Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,007
Quick preset (or use dates below)
Clear Filters
Showing 2,061 - 2,080 of 3,576 CVEs
CVE-2026-4750 CRITICAL - 9.1

Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0.

Published: Mar 24, 2026
Source: NVD
CVE-2026-4283 CRITICAL - 9.1

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This is due to the `super-unsubscribe` AJAX action accepting a `process_now` parameter from unauthenticated users, which bypasses the intended email-confirma...

Published: Mar 24, 2026
Source: NVD
CVE-2026-4001 CRITICAL - 9.8

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_custom_formula() function within includes/process/price.php. This is due to insufficient sanitization...

Published: Mar 24, 2026
Source: NVD
CVE-2026-33634 CRITICAL - 8.8

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with maliciou...

Vendor: aquasecurity
Product: setup-trivy, trivy-action, trivy
Published: Mar 23, 2026
Source: NVD
CVE-2026-32913 CRITICAL - 9.3

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended ...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 23, 2026
Source: NVD
CVE-2025-60949 CRITICAL - 9.1

Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.

Vendor: Census
Product: CSWeb
Published: Mar 23, 2026
Source: NVD
CVE-2026-30849 CRITICAL - 9.8

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter. Other database backends are not affect...

Vendor: mantisbt
Product: mantisbt
Published: Mar 23, 2026
Source: NVD
CVE-2026-2298 CRITICAL - 9.4

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 30th, 2026.

Published: Mar 23, 2026
Source: NVD
CVE-2026-33716 CRITICAL - 9.4

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that overrides where the server sends token verification requests. An atta...

Vendor: WWBN
Product: AVideo
Published: Mar 23, 2026
Source: NVD
CVE-2026-4404 CRITICAL - 9.4

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Published: Mar 23, 2026
Source: NVD
CVE-2026-4585 CRITICAL - 9.8

A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/ImportSystemConfiguration.jsp of the component Configuration Handler. The manipulation of the argument File leads to os command injec...

Published: Mar 23, 2026
Source: NVD
CVE-2026-32968 CRITICAL - 9.8

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.

Vendor: MB connect line, Helmholz
Product: MB connect line mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
Published: Mar 23, 2026
Source: NVD
CVE-2026-3587 CRITICAL - 10.0

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface and gain root access to the underlying Linux based OS, leading to full compromise of the device.

Published: Mar 23, 2026
Source: NVD
CVE-2026-4599 CRITICAL - 9.1

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compare...

Vendor: jsrsasign_project
Product: jsrsasign
Published: Mar 23, 2026
Source: NVD
CVE-2026-4567 CRITICAL - 9.8

A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and m...

Published: Mar 23, 2026
Source: NVD
CVE-2019-25614 CRITICAL - 9.8

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containi...

Vendor: Freefloat
Product: Free Float FTP
Published: Mar 22, 2026
Source: NVD
CVE-2019-25568 CRITICAL - 9.8

Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable, which executes with sy...

Vendor: Memuplay
Product: Memu Play
Published: Mar 21, 2026
Source: NVD
CVE-2026-24060 CRITICAL - 9.1

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filt...

Vendor: Automated Logic
Product: WebCTRL Premium Server
Published: Mar 21, 2026
Source: NVD
CVE-2026-29796 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then is...

Vendor: IGL-Technologies
Product: eParking.fi
Published: Mar 20, 2026
Source: NVD
CVE-2026-25192 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then is...

Vendor: CTEK
Product: Chargeportal
Published: Mar 20, 2026
Source: NVD