Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,006
Quick preset (or use dates below)
Clear Filters
Showing 2,101 - 2,120 of 3,576 CVEs
CVE-2026-32891 CRITICAL - 9.0

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector. Jellyseerr allows any account holder to execute arbitrary JavaScript in the Anc...

Vendor: openVESSL
Product: Anchorr
Published: Mar 20, 2026
Source: NVD
CVE-2026-32890 CRITICAL - 9.6

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnerability in the web dashboard's User Mapping dropdown allows any unprivileged Discord user in the...

Vendor: openVESSL
Product: Anchorr
Published: Mar 20, 2026
Source: NVD
CVE-2026-21992 CRITICAL - 9.8

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita...

Vendor: oracle
Product: identity_manager
Published: Mar 20, 2026
Source: NVD
CVE-2026-32817 CRITICAL - 9.1

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delete folders or files. The folder_delete and file_delete action handlers in modules/documents-files.php only perform a VIEW...

Vendor: Admidio
Product: admidio
Published: Mar 20, 2026
Source: NVD
CVE-2026-32985 CRITICAL - 9.8

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality. The issue exists in /website_code/php/import/import.php where missing authentication checks allow an attacker to upload a crafted ZIP archive disguised...

Vendor: Xerte
Product: Xerte Online Toolkits
Published: Mar 20, 2026
Source: NVD
CVE-2026-29103 CRITICAL - 9.1

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 and 8.9.2, allowing authenticated administrators to execute arbitrary system commands. This vulnerability is a dire...

Vendor: SuiteCRM
Product: SuiteCRM
Published: Mar 19, 2026
Source: NVD
CVE-2026-22732 CRITICAL - 9.1

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.ย  This issue affects Spring Security: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through...

Vendor: Spring
Product: Spring Security
Published: Mar 19, 2026
Source: NVD
CVE-2026-32754 CRITICAL - 9.3

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. Incoming email bodies are stored in the database without sanitization and rend...

Vendor: freescout-help-desk
Product: freescout
Published: Mar 19, 2026
Source: NVD
CVE-2026-32194 CRITICAL - 9.8

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

Published: Mar 19, 2026
Source: NVD
CVE-2026-32038 CRITICAL - 9.8

OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network namespace. Attackers can configure the docker.network parameter with container:<id> values to reach services in target container namespaces...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 19, 2026
Source: NVD
CVE-2026-30872 CRITICAL - 9.8

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function, triggered when processing PTR queries for IPv6 reverse DNS domains (.ip6.arpa) recei...

Vendor: openwrt
Product: openwrt
Published: Mar 19, 2026
Source: NVD
CVE-2026-30871 CRITICAL - 9.8

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue is triggered by PTR queries for reverse DNS domains (.in-addr.arpa and .ip6.arp...

Vendor: openwrt
Product: openwrt
Published: Mar 19, 2026
Source: NVD
CVE-2026-4395 CRITICAL - 9.8

Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-controlled data past the bounds of the pubkey_raw buffer via a crafted oversized EC public key point. The WOLFSSL_KCAPI_ECC code path copies the input to k...

Vendor: wolfssl
Product: wolfssl
Published: Mar 19, 2026
Source: NVD
CVE-2026-3849 CRITICAL - 9.8

Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) support, where a maliciously crafted ECH config could cause a stack buffer overflow on the client side, leading to potential remote execution and client prog...

Vendor: wolfssl
Product: wolfssl
Published: Mar 19, 2026
Source: NVD
CVE-2026-3549 CRITICAL - 9.8

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is off by default, and the ECH standard is still evolving.

Vendor: wolfssl
Product: wolfssl
Published: Mar 19, 2026
Source: NVD
CVE-2026-32191 CRITICAL - 9.8

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

Published: Mar 19, 2026
Source: NVD
CVE-2026-32169 CRITICAL - 10.0

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

Published: Mar 19, 2026
Source: NVD
CVE-2026-32238 CRITICAL - 9.1

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers. The vulnerability exists due to insufficient inpu...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-33352 CRITICAL - 9.8

WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. The `doNotShowCats` request parameter is sanitized only by stripping single-quote characters (`str_replace("&#...

Vendor: composer
Product: wwbn/avideo
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33351 CRITICAL - 9.1

WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live plugin is deployed in standalone mode (the intended configuration for this file), the `$_REQUEST[...

Vendor: composer
Product: wwbn/avideo
Published: Mar 19, 2026
Source: GitHub