Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,081 - 2,100 of 3,443 CVEs
CVE-2026-22900 CRITICAL - 9.8

A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.5.0906 and later

Vendor: QNAP Systems Inc.
Product: QuNetSwitch
Published: Mar 20, 2026
Source: NVD
CVE-2026-22897 CRITICAL - 9.8

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later

Vendor: QNAP Systems Inc.
Product: QuNetSwitch
Published: Mar 20, 2026
Source: NVD
CVE-2026-33286 CRITICAL - 9.1

Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary...

Vendor: rubygems
Product: graphiti
Published: Mar 20, 2026
Source: GitHub
CVE-2026-22172 CRITICAL - 9.9

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password-authenticated connections to self-declare elevated scopes without server-side binding. Attackers can exploit this logic flaw to present unauthorized s...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 20, 2026
Source: NVD
CVE-2024-44722 CRITICAL - 9.8

SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.

Published: Mar 20, 2026
Source: NVD
CVE-2026-33136 CRITICAL - 9.3

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An attacker can inject arbitrary JavaScript or HTML tags into the sccd GET parameter, which is then directly echoed int...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Mar 20, 2026
Source: NVD
CVE-2026-33135 CRITICAL - 9.3

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_memorandoo.php endpoint. An attacker can inject arbitrary JavaScript into the sccs GET parameter, which is directly echoed into the HTML response without...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Mar 20, 2026
Source: NVD
CVE-2026-33134 CRITICAL - 9.3

WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto.php endpoint. The vulnerability allows an authenticated attacker to inject arbitrary SQL commands via the id_produto GET parameter, l...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Mar 20, 2026
Source: NVD
CVE-2026-33024 CRITICAL - 9.1

AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpoints getImage.php and getImageMP4.php. Both endpoints accept a base64Url GET parameter, base64-decode it, and pass the resulting URL to ffmpeg as an in...

Vendor: WWBN
Product: AVideo-Encoder
Published: Mar 20, 2026
Source: NVD
CVE-2026-4038 CRITICAL - 9.8

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated...

Published: Mar 20, 2026
Source: NVD
CVE-2026-32945 CRITICAL - 9.8

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability in the DNS parser's name length handler. Thisimpacts applications using PJSIP's built-in DNS resolver, such as those configured with pjsua_c...

Vendor: pjsip
Product: pjproject
Published: Mar 20, 2026
Source: NVD
CVE-2026-32940 CRITICAL - 9.3

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist โ€” it blocks data:text/html and data:image/svg+xml in href attributes but misses data:text/xml and data:application/xml, both of which can render SVG with JavaScript execution. The u...

Vendor: siyuan-note
Product: siyuan
Published: Mar 20, 2026
Source: NVD
CVE-2026-32938 CRITICAL - 9.9

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// links in pasted HTML into the workspace assets directory without validating paths against a sensitive-path list. Together with GET /asset...

Vendor: siyuan-note
Product: siyuan
Published: Mar 20, 2026
Source: NVD
CVE-2026-32891 CRITICAL - 9.0

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector. Jellyseerr allows any account holder to execute arbitrary JavaScript in the Anc...

Vendor: openVESSL
Product: Anchorr
Published: Mar 20, 2026
Source: NVD
CVE-2026-32890 CRITICAL - 9.6

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnerability in the web dashboard's User Mapping dropdown allows any unprivileged Discord user in the...

Vendor: openVESSL
Product: Anchorr
Published: Mar 20, 2026
Source: NVD
CVE-2026-21992 CRITICAL - 9.8

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita...

Vendor: oracle
Product: identity_manager
Published: Mar 20, 2026
Source: NVD
CVE-2026-32817 CRITICAL - 9.1

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delete folders or files. The folder_delete and file_delete action handlers in modules/documents-files.php only perform a VIEW...

Vendor: Admidio
Product: admidio
Published: Mar 20, 2026
Source: NVD
CVE-2026-32985 CRITICAL - 9.8

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality. The issue exists in /website_code/php/import/import.php where missing authentication checks allow an attacker to upload a crafted ZIP archive disguised...

Vendor: Xerte
Product: Xerte Online Toolkits
Published: Mar 20, 2026
Source: NVD
CVE-2026-29103 CRITICAL - 9.1

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 and 8.9.2, allowing authenticated administrators to execute arbitrary system commands. This vulnerability is a dire...

Vendor: SuiteCRM
Product: SuiteCRM
Published: Mar 19, 2026
Source: NVD
CVE-2026-22732 CRITICAL - 9.1

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.ย  This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through...

Vendor: Spring
Product: Spring Security
Published: Mar 19, 2026
Source: NVD