Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,056
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,141 - 2,160 of 3,450 CVEs
CVE-2026-32703 CRITICAL - 9.0

OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1, the Repositories module did not properly escape filenames displayed from repositories. This allowed an attacker with push access into the repository to create commits with f...

Vendor: opf
Product: openproject
Published: Mar 18, 2026
Source: NVD
CVE-2026-32698 CRITICAL - 9.1

OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom field's name. When that custom field was used in a Cost Report, the custom field's name was injected into the SQ...

Vendor: opf
Product: openproject
Published: Mar 18, 2026
Source: NVD
CVE-2026-31972 CRITICAL - 9.8

SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been aligned against a known reference. On each output line it writes the reference position, optionally the reference DNA base at that position (obtained fr...

Vendor: samtools
Product: samtools
Published: Mar 18, 2026
Source: NVD
CVE-2026-25873 CRITICAL - 9.8

OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure pickle deserialization of request bodies to achieve code execu...

Vendor: Beijing Academy of Artificial Intelligence (BAAI)
Product: OmniGen2-RL
Published: Mar 18, 2026
Source: NVD
CVE-2026-33211 CRITICAL - 9.6

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permissio...

Vendor: go
Product: github.com/tektoncd/pipeline
Published: Mar 18, 2026
Source: GitHub
CVE-2026-31967 CRITICAL - 9.1

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function called while reading CRAM records, the value of the mate reference id field was not validated. Later use of this value,...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD
CVE-2026-31966 CRITICAL - 9.1

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant data, CRAM uses reference-based compression so that instead of storing the full sequence for each alignment record it sto...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD
CVE-2026-33186 CRITICAL - 9.1

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory l...

Vendor: go
Product: google.golang.org/grpc
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33180 CRITICAL - 9.8

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests, the internal HTTP client sends headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP re...

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.utilities
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33057 CRITICAL - 9.8

Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai/ testing module infrastructure directly ingests untrusted Python code strings unconditionally without authentication measures, yielding standard Unres...

Vendor: pip
Product: mesop
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33054 CRITICAL - 10.0

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_token through the UI stream payload to arbitrarily target files on the disk under the standard file-base...

Vendor: pip
Product: mesop
Published: Mar 18, 2026
Source: GitHub
CVE-2026-32731 CRITICAL - 10.0

ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.createWriteStream(path.join(exportPath, header.name))`. `path.join()` does not resolve or sanitise trave...

Vendor: npm
Product: @apostrophecms/import-export
Published: Mar 18, 2026
Source: GitHub
CVE-2026-30704 CRITICAL - 9.1

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB

Published: Mar 18, 2026
Source: NVD
CVE-2026-30703 CRITICAL - 9.8

A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi endpoint improperly sanitizes user-supplied input provided to a command-related parameter in the sysCMD functionality.

Published: Mar 18, 2026
Source: NVD
CVE-2026-30702 CRITICAL - 9.8

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints...

Published: Mar 18, 2026
Source: NVD
CVE-2026-30701 CRITICAL - 9.1

The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of Server Side Include) within multiple server-side web pages, including login.shtml and settings.shtml. These pages embed server-side execution directives...

Published: Mar 18, 2026
Source: NVD
CVE-2026-29859 CRITICAL - 9.8

An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.

Vendor: aapanel
Product: aapanel
Published: Mar 18, 2026
Source: NVD
CVE-2025-67830 CRITICAL - 9.8

Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2026-2991 CRITICAL - 9.8

The KiviCare โ€“ Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access token before authenticating a user. This ma...

Published: Mar 18, 2026
Source: NVD
CVE-2025-67829 CRITICAL - 9.8

Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD