Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,006
Quick preset (or use dates below)
Clear Filters
Showing 2,121 - 2,140 of 3,576 CVEs
CVE-2026-30694 CRITICAL - 9.8

An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

Vendor: dedecms
Product: dedecms
Published: Mar 19, 2026
Source: NVD
CVE-2025-67114 CRITICAL - 9.8

Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive valid administrative/root credentials from the device's MAC address, enabling authentication bypa...

Published: Mar 19, 2026
Source: NVD
CVE-2025-67113 CRITICAL - 9.8

OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint to execute arbitrary commands as root via a crafted TR-069 Download URL that is passed unescaped into ...

Published: Mar 19, 2026
Source: NVD
CVE-2025-67112 CRITICAL - 9.8

Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authenticated users to decrypt, modify, and re-encrypt device configurations, enabling credential manipulation...

Published: Mar 19, 2026
Source: NVD

MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and...

Vendor: go
Product: github.com/minio/minio
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33309 CRITICAL - 10.0

Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `LocalStorageService` remaining unresolved. Because the underlying...

Vendor: pip
Product: langflow
Published: Mar 19, 2026
Source: GitHub

qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning Access-Control-Allow-Credentials: true, effectively allowing any external webpage to make authenticated requests on behalf of a logge...

Vendor: go
Product: github.com/autobrr/qui
Published: Mar 19, 2026
Source: GitHub
CVE-2026-30836 CRITICAL - 10.0

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

Vendor: go
Product: github.com/smallstep/certificates
Published: Mar 19, 2026
Source: GitHub
CVE-2026-32865 CRITICAL - 9.8

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'ForcePasswordReset.aspx'. An attacker who knows an existing user's email address can reset the user's password and security question...

Vendor: OPEXUS
Product: eComplaint, eCASE
Published: Mar 19, 2026
Source: NVD
CVE-2026-30402 CRITICAL - 9.8

An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function

Published: Mar 19, 2026
Source: NVD
CVE-2026-22557 CRITICAL - 10.0

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

Vendor: Ubiquiti Inc
Product: UniFi Network Application
Published: Mar 19, 2026
Source: NVD
CVE-2025-69720 CRITICAL - 9.8

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

Vendor: invisible-island
Product: ncurses
Published: Mar 19, 2026
Source: NVD
CVE-2006-10003 CRITICAL - 9.8

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the all...

Vendor: TODDR
Product: XML::Parser
Published: Mar 19, 2026
Source: NVD
CVE-2026-27067 CRITICAL - 9.1

Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor allows Upload a Web Shell to a Web Server.This issue affects Mobile App Editor: from n/a through 1.3.1.

Vendor: Syarif
Product: Mobile App Editor
Published: Mar 19, 2026
Source: NVD
CVE-2026-27065 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress allows PHP Local File Inclusion.This issue affects BuilderPress: from n/a through 2.0.1.

Vendor: ThimPress
Product: BuilderPress
Published: Mar 19, 2026
Source: NVD
CVE-2025-60237 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.

Vendor: Themeton
Product: Finag
Published: Mar 19, 2026
Source: NVD
CVE-2025-60233 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.

Vendor: Themeton
Product: Zuut
Published: Mar 19, 2026
Source: NVD
CVE-2026-27542 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a through 2.0.3.1.

Vendor: Rymera Web Co Pty Ltd.
Product: Woocommerce Wholesale Lead Capture
Published: Mar 19, 2026
Source: NVD
CVE-2026-27540 CRITICAL - 9.0

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through 2.0.3.1.

Vendor: Rymera Web Co Pty Ltd.
Product: Woocommerce Wholesale Lead Capture
Published: Mar 19, 2026
Source: NVD
CVE-2026-27413 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a through 3.13.9.

Vendor: Cozmoslabs
Product: Profile Builder Pro
Published: Mar 19, 2026
Source: NVD