Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,971
Quick preset (or use dates below)
Clear Filters
Showing 2,161 - 2,180 of 3,576 CVEs
CVE-2026-25449 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Shinetheme Traveler allows Object Injection.This issue affects Traveler: from n/a before 3.2.8.1.

Vendor: Shinetheme
Product: Traveler
Published: Mar 18, 2026
Source: NVD
CVE-2026-30884 CRITICAL - 9.6

mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. Prior to versions 4.4.9 and 5.0.3, a teacher who holds `mod/customcert:manage` in any single course can read and silently overwrite certificate elements...

Vendor: mdjnelson
Product: moodle-mod_customcert
Published: Mar 18, 2026
Source: NVD
CVE-2026-21994 CRITICAL - 9.8

Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affected is 0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to co...

Published: Mar 17, 2026
Source: NVD
CVE-2026-33017 CRITICAL - 9.8

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker...

Vendor: pip
Product: langflow
Published: Mar 17, 2026
Source: GitHub
CVE-2026-32298 CRITICAL - 9.1

The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute OS-level commands.

Vendor: ANGEET
Product: ES3 KVM
Published: Mar 17, 2026
Source: NVD
CVE-2026-25770 CRITICAL - 9.1

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, a privilege escalation vulnerability exists in the Wazuh Manager's cluster synchronization protocol. The `wazuh-clusterd` service allows authentic...

Vendor: wazuh
Product: wazuh
Published: Mar 17, 2026
Source: NVD
CVE-2026-25769 CRITICAL - 9.1

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All Wazuh deployments using cluster mode (master/worker architecture) and any organi...

Vendor: wazuh
Product: wazuh
Published: Mar 17, 2026
Source: NVD
CVE-2026-31938 CRITICAL - 9.6

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) into the browser context the created PDF is opened in. The vulnerability can be exploited in the foll...

Vendor: npm
Product: jspdf
Published: Mar 17, 2026
Source: GitHub
CVE-2026-3564 CRITICAL - 9.0

A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios.

Published: Mar 17, 2026
Source: NVD
CVE-2026-4312 CRITICAL - 9.8

GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access certain APIs to create a new administrative account.

Published: Mar 17, 2026
Source: NVD
CVE-2026-4177 CRITICAL - 9.1

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on traili...

Vendor: toddr
Product: yaml\
Published: Mar 16, 2026
Source: NVD
CVE-2025-69902 CRITICAL - 9.8

A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to execute arbitrary commands via injecting arbitrary shell metacharacters.

Published: Mar 16, 2026
Source: NVD
CVE-2026-32767 CRITICAL - 9.8

SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextSearchBlock endpoint. When the method parameter is set to 2, the endpoint passes user-supplied input directly as a raw SQL statement to the underlying S...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 16, 2026
Source: GitHub
CVE-2026-32760 CRITICAL - 9.8

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthenticated visitor can register a full administrator account when self-registration (signup = true) is enabled and the defau...

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Mar 16, 2026
Source: GitHub
CVE-2026-28430 CRITICAL - 9.8

Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQL commands via the custom_dates parameter. By chaining this with a predictable legacy password reset mechanism, an attac...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 16, 2026
Source: NVD
CVE-2025-69809 CRITICAL - 9.8

A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values to memory, enabling arbitrary code execution via a crafted packet.

Published: Mar 16, 2026
Source: NVD
CVE-2025-69808 CRITICAL - 9.1

An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive information and cause a Denial of Service (DoS) via supplying a crafted packet.

Published: Mar 16, 2026
Source: NVD
CVE-2026-32267 CRITICAL - 9.8

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->...

Vendor: composer
Product: craftcms/cms
Published: Mar 16, 2026
Source: GitHub
CVE-2026-4254 CRITICAL - 9.8

A weakness has been identified in Tenda AC8 up to 16.03.50.11. This vulnerability affects the function doSystemCmd of the file /goform/SysToolChangePwd of the component HTTP Endpoint. This manipulation of the argument local_2c causes stack-based buffer overflow. The attack can be initiated remotely....

Vendor: tenda
Product: ac8_firmware
Published: Mar 16, 2026
Source: NVD
CVE-2026-23489 CRITICAL - 9.1

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP code from users that are allowed to create dropdowns. This issue has been patched in version 1.23.3.

Vendor: pluginsGLPI
Product: fields
Published: Mar 16, 2026
Source: NVD