Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,053
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,181 - 2,200 of 3,450 CVEs
CVE-2026-4252 CRITICAL - 9.8

A vulnerability was identified in Tenda AC8 16.03.50.11. Affected by this issue is the function check_is_ipv6 of the component IPv6 Handler. The manipulation leads to reliance on ip address for authentication. It is possible to initiate the attack remotely. The exploit is publicly available and migh...

Published: Mar 16, 2026
Source: NVD
CVE-2026-32633 CRITICAL - 9.1

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from `GlancesServersList.get_servers_list()`. Those objects are mutated in-place during background polling and can contain a ...

Vendor: pip
Product: Glances
Published: Mar 16, 2026
Source: GitHub
CVE-2025-62319 CRITICAL - 9.8

Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the in...

Vendor: HCL
Product: Unica
Published: Mar 16, 2026
Source: NVD
CVE-2026-27962 CRITICAL - 9.1

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to a...

Vendor: pip
Product: authlib
Published: Mar 16, 2026
Source: GitHub
CVE-2026-25534 CRITICAL - 9.1

### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly handle underscores on parsing. This led to a bypass of the previous CVE (CVE-2025-61916) through the use of caref...

Vendor: maven
Product: io.spinnaker.clouddriver:clouddriver-artifacts
Published: Mar 16, 2026
Source: GitHub
CVE-2026-4184 CRITICAL - 9.8

A vulnerability was detected in D-Link DIR-816 1.10CNB05. Affected by this vulnerability is an unknown functionality of the file /goform/form2Wl5BasicSetup.cgi of the component goahead. Performing a manipulation of the argument pskValue results in stack-based buffer overflow. The attack is possible ...

Vendor: dlink
Product: dir-816_firmware
Published: Mar 16, 2026
Source: NVD
CVE-2026-4183 CRITICAL - 9.8

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05. Affected is an unknown function of the file /goform/form2WlanBasicSetup.cgi of the component goahead. Such manipulation of the argument pskValue leads to stack-based buffer overflow. The attack can be executed remotely. The expl...

Vendor: dlink
Product: dir-816_firmware
Published: Mar 16, 2026
Source: NVD
CVE-2026-4182 CRITICAL - 9.8

A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the component goahead. This manipulation of the argument key1/key2/key3/key4/pskValue causes stack-based buffer overflow. Remote exploitation of the attack is...

Vendor: dlink
Product: dir-816_firmware
Published: Mar 16, 2026
Source: NVD
CVE-2026-4181 CRITICAL - 9.8

A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the component goahead. The manipulation of the argument key1/key2/key3/key4/pskValue results in stack-based buffer overflow. The attack may be launched remo...

Vendor: dlink
Product: dir-816_firmware
Published: Mar 16, 2026
Source: NVD
CVE-2026-4170 CRITICAL - 9.8

A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/management/nmc_sync.php of the component HTTP Request Handler. Executing a manipulation of the argument template_path can lead to os command injection. The a...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4164 CRITICAL - 9.8

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Executing a manipulation can lead to command injection. It is possible to launch the attack remotely. The exploit ha...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4163 CRITICAL - 9.8

A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the component POST Request Handler. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The exploit is...

Published: Mar 16, 2026
Source: NVD
CVE-2026-32626 CRITICAL - 9.6

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the chat rendering pipeline that escalates to Remote Code Execution on the host OS du...

Vendor: Mintplex-Labs
Product: anything-llm
Published: Mar 16, 2026
Source: NVD
CVE-2025-69246 CRITICAL - 9.8

Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without triggering lockout, throttling, or step-up challenges. This issue was fixed in version 1.4.6.

Vendor: Raytha
Product: Raytha
Published: Mar 16, 2026
Source: NVD
CVE-2025-15060 CRITICAL - 9.8

claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of claude-hovercraft. Authentication is not required to exploit this vulnerability. The specific flaw exists with...

Vendor: claude-hovercraft
Product: claude-hovercraft
Published: Mar 16, 2026
Source: NVD
CVE-2017-20224 CRITICAL - 9.8

Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious content by exploiting enabled WebDAV HTTP methods. Attackers can use PUT, DELETE, MKCOL, MOVE, COPY, and PROPPATCH methods to upload executable ...

Vendor: Telesquare
Product: SDT-CS3B1
Published: Mar 16, 2026
Source: NVD
CVE-2017-20223 CRITICAL - 9.8

Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access resources by manipulating user-supplied input parameters. Attackers can directly reference objects in the system to retrieve ...

Vendor: Telesquare
Product: SDT-CS3B1
Published: Mar 16, 2026
Source: NVD
CVE-2016-20030 CRITICAL - 9.8

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attackers can send requests to the authLoginAction!login.do script with varying username inputs to enumera...

Vendor: ZKTeco Inc.
Product: ZKTeco ZKBioSecurity
Published: Mar 16, 2026
Source: NVD
CVE-2016-20026 CRITICAL - 9.8

ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hardcoded credentials stored in tomcat-users.xml to upload malicious WAR archives containing JSP applica...

Vendor: ZKTeco Inc.
Product: ZKTeco ZKBioSecurity
Published: Mar 16, 2026
Source: NVD
CVE-2016-20024 CRITICAL - 9.8

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with maliciou...

Vendor: ZKTeco Inc.
Product: ZKTeco ZKTime.Net
Published: Mar 16, 2026
Source: NVD