Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,121 - 2,140 of 3,443 CVEs
CVE-2026-30836 CRITICAL - 10.0

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

Vendor: go
Product: github.com/smallstep/certificates
Published: Mar 19, 2026
Source: GitHub
CVE-2026-32865 CRITICAL - 9.8

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security question...

Vendor: OPEXUS
Product: eComplaint, eCASE
Published: Mar 19, 2026
Source: NVD
CVE-2026-30402 CRITICAL - 9.8

An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function

Published: Mar 19, 2026
Source: NVD
CVE-2026-22557 CRITICAL - 10.0

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

Vendor: Ubiquiti Inc
Product: UniFi Network Application
Published: Mar 19, 2026
Source: NVD
CVE-2025-69720 CRITICAL - 9.8

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

Vendor: invisible-island
Product: ncurses
Published: Mar 19, 2026
Source: NVD
CVE-2006-10003 CRITICAL - 9.8

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the all...

Vendor: TODDR
Product: XML::Parser
Published: Mar 19, 2026
Source: NVD
CVE-2026-27067 CRITICAL - 9.1

Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor allows Upload a Web Shell to a Web Server.This issue affects Mobile App Editor: from n/a through 1.3.1.

Vendor: Syarif
Product: Mobile App Editor
Published: Mar 19, 2026
Source: NVD
CVE-2026-27065 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress allows PHP Local File Inclusion.This issue affects BuilderPress: from n/a through 2.0.1.

Vendor: ThimPress
Product: BuilderPress
Published: Mar 19, 2026
Source: NVD
CVE-2025-60237 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.

Vendor: Themeton
Product: Finag
Published: Mar 19, 2026
Source: NVD
CVE-2025-60233 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.

Vendor: Themeton
Product: Zuut
Published: Mar 19, 2026
Source: NVD
CVE-2026-27542 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a through 2.0.3.1.

Vendor: Rymera Web Co Pty Ltd.
Product: Woocommerce Wholesale Lead Capture
Published: Mar 19, 2026
Source: NVD
CVE-2026-27540 CRITICAL - 9.0

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through 2.0.3.1.

Vendor: Rymera Web Co Pty Ltd.
Product: Woocommerce Wholesale Lead Capture
Published: Mar 19, 2026
Source: NVD
CVE-2026-27413 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a through 3.13.9.

Vendor: Cozmoslabs
Product: Profile Builder Pro
Published: Mar 19, 2026
Source: NVD
CVE-2026-32703 CRITICAL - 9.0

OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This allowed an attacker with push access into the repository to create commits with f...

Vendor: opf
Product: openproject
Published: Mar 18, 2026
Source: NVD
CVE-2026-32698 CRITICAL - 9.1

OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom field's name. When that custom field was used in a Cost Report, the custom field's name was injected into the SQ...

Vendor: opf
Product: openproject
Published: Mar 18, 2026
Source: NVD
CVE-2026-31972 CRITICAL - 9.8

SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been aligned against a known reference. On each output line it writes the reference position, optionally the reference DNA base at that position (obtained fr...

Vendor: samtools
Product: samtools
Published: Mar 18, 2026
Source: NVD
CVE-2026-25873 CRITICAL - 9.8

OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure pickle deserialization of request bodies to achieve code execu...

Vendor: Beijing Academy of Artificial Intelligence (BAAI)
Product: OmniGen2-RL
Published: Mar 18, 2026
Source: NVD
CVE-2026-33211 CRITICAL - 9.6

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permissio...

Vendor: go
Product: github.com/tektoncd/pipeline
Published: Mar 18, 2026
Source: GitHub
CVE-2026-31967 CRITICAL - 9.1

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function called while reading CRAM records, the value of the mate reference id field was not validated. Later use of this value,...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD
CVE-2026-31966 CRITICAL - 9.1

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant data, CRAM uses reference-based compression so that instead of storing the full sequence for each alignment record it sto...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD