Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,961
Quick preset (or use dates below)
Clear Filters
Showing 2,201 - 2,220 of 3,576 CVEs
CVE-2026-32621 CRITICAL - 9.9

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may ...

Vendor: npm
Product: @apollo/federation-internals
Published: Mar 13, 2026
Source: GitHub
CVE-2026-3891 CRITICAL - 9.8

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and including, 1.5.0. This makes it possible for unauthent...

Published: Mar 13, 2026
Source: NVD
CVE-2026-32746 CRITICAL - 9.8

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

Vendor: GNU
Product: inetutils
Published: Mar 13, 2026
Source: NVD
CVE-2026-32367 CRITICAL - 9.1

Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.This issue affects Modal Dialog: from n/a through <= 3.5.16.

Vendor: Yannick Lefebvre
Product: Modal Dialog
Published: Mar 13, 2026
Source: NVD
CVE-2026-32306 CRITICAL - 9.9

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregationType, aggregateColumnName, and aggregationTimestampColumnName parameters and interpolates them directly into ClickHouse SQL queries via the .append(...

Vendor: OneUptime
Product: oneuptime
Published: Mar 13, 2026
Source: NVD
CVE-2026-32304 CRITICAL - 9.8

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, allowing arbitrary code execution. This is distinct from CVE-2...

Vendor: locutusjs
Product: locutus
Published: Mar 13, 2026
Source: NVD
CVE-2026-32301 CRITICAL - 9.3

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoint URL using template variables (e.g. {{tenant}}). An unauthenticated attacker can craft a JWT with a malicious i...

Vendor: centrifugal
Product: centrifugo
Published: Mar 13, 2026
Source: NVD
CVE-2026-31806 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly va...

Vendor: FreeRDP
Product: FreeRDP
Published: Mar 13, 2026
Source: NVD
CVE-2026-25823 CRITICAL - 9.8

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer overflow that leads to a Denial of Service, which can also be exploited to achieve Unauthenticated Remote Code Execution.

Published: Mar 13, 2026
Source: NVD
CVE-2026-25818 CRITICAL - 9.1

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cookies, allowing an attacker with a stolen session cookie to find the user password by brute-forcing an encryption parameter...

Published: Mar 13, 2026
Source: NVD
CVE-2026-32614 CRITICAL - 7.5

Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial cryptographic public algorithms SM2/SM3/SM4/SM9/ZUC. Prior to 0.41.1, the current SM9 decryption implementation contains an infinity-point ciphertext forgery vulnerability. The root caus...

Vendor: go
Product: github.com/emmansun/gmsm
Published: Mar 13, 2026
Source: GitHub
CVE-2026-31886 CRITICAL - 9.1

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoints is passed directly into filepath.Join to construct a temporary directory path without any format validation. Go's filepath.Join resolves .. seg...

Vendor: go
Product: github.com/dagu-org/dagu
Published: Mar 13, 2026
Source: GitHub
CVE-2026-26954 CRITICAL - 10.0

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Function, and Object.fromEntries, it is possible to construct {[p]: Function} where p is any constructible property. This v...

Vendor: npm
Product: @nyariv/sandboxjs
Published: Mar 13, 2026
Source: GitHub
CVE-2026-3611 CRITICAL - 10.0

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileg...

Published: Mar 12, 2026
Source: NVD
CVE-2026-32242 CRITICAL - 7.4

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly across all OAuth2 provider configurations. Under concurren...

Vendor: parse-community
Product: parse-server
Published: Mar 12, 2026
Source: NVD
CVE-2026-26793 CRITICAL - 9.8

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

Vendor: gl-inet
Product: ar300m16_firmware
Published: Mar 12, 2026
Source: NVD
CVE-2025-70245 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 12, 2026
Source: NVD
CVE-2026-26795 CRITICAL - 9.8

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

Vendor: gl-inet
Product: ar300m16_firmware
Published: Mar 12, 2026
Source: NVD
CVE-2026-26792 CRITICAL - 9.8

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type parameters. These vulnerabilities allow attackers to execute arbit...

Vendor: gl-inet
Product: ar300m16_firmware
Published: Mar 12, 2026
Source: NVD
CVE-2026-26791 CRITICAL - 9.8

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

Vendor: gl-inet
Product: ar300m16_firmware
Published: Mar 12, 2026
Source: NVD