Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,961
Quick preset (or use dates below)
Clear Filters
Showing 2,221 - 2,240 of 3,576 CVEs
CVE-2026-32248 CRITICAL - 9.8

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider that does not validate the format of the user identi...

Vendor: npm
Product: parse-server
Published: Mar 12, 2026
Source: GitHub
CVE-2026-28792 CRITICAL - 9.6

Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Allow-Origin: *) with the path traversal vulnerability (previously reported) to enable a browser-based drive-by attack. A remote attacker can enumerate t...

Vendor: @tinacms
Product: cli
Published: Mar 12, 2026
Source: NVD
CVE-2026-21708 CRITICAL - 9.9

A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

Vendor: Veeam
Product: Backup and Recovery
Published: Mar 12, 2026
Source: NVD
CVE-2026-21671 CRITICAL - 9.1

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.

Vendor: Veeam
Product: Software Appliance
Published: Mar 12, 2026
Source: NVD
CVE-2026-21669 CRITICAL - 9.9

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Vendor: Veeam
Product: Backup and Replication
Published: Mar 12, 2026
Source: NVD
CVE-2026-21667 CRITICAL - 9.9

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Vendor: Veeam
Product: Backup and Replication
Published: Mar 12, 2026
Source: NVD
CVE-2026-21666 CRITICAL - 9.9

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Vendor: Veeam
Product: Backup and Replication
Published: Mar 12, 2026
Source: NVD
CVE-2026-3060 CRITICAL - 9.8

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deserializes untrusted data using pickle.loads() without authentication.

Vendor: pip
Product: sglang
Published: Mar 12, 2026
Source: NVD
CVE-2026-3059 CRITICAL - 9.8

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted data using pickle.loads() without authentication.

Vendor: pip
Product: sglang
Published: Mar 12, 2026
Source: NVD
CVE-2025-59388 CRITICAL - 9.8

A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability to gain unauthorized access. We have already fixed the vulnerability in the following version: Hyper Data Protector 2.3.1.455 and later

Vendor: QNAP Systems Inc.
Product: Hyper Data Protector
Published: Mar 12, 2026
Source: NVD
CVE-2026-3916 CRITICAL - 9.6

Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Mar 11, 2026
Source: NVD
CVE-2026-32136 CRITICAL - 9.8

AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cleartext (h2c). Once the upgrade is accepted, the resulting HTT...

Vendor: AdguardTeam
Product: AdGuardHome
Published: Mar 11, 2026
Source: NVD
CVE-2026-32133 CRITICAL - 9.1

2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0, a blind SSRF vulnerability exists in 2FAuth that allows authenticated users to make arbitrary HTTP requests from the server to internal networks and cloud metadata endpoints. The...

Vendor: Bubka
Product: 2FAuth
Published: Mar 11, 2026
Source: NVD
CVE-2026-27591 CRITICAL - 9.9

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modifying the roles / permissions assigned to their accou...

Vendor: wintercms
Product: winter
Published: Mar 11, 2026
Source: NVD
CVE-2025-70041 CRITICAL - 9.8

An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.

Published: Mar 11, 2026
Source: NVD
CVE-2025-70024 CRITICAL - 9.8

An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benkeen generatedata 4.0.14.

Published: Mar 11, 2026
Source: NVD
CVE-2025-66956 CRITICAL - 9.9

Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachments via a computable URL.

Published: Mar 11, 2026
Source: NVD
CVE-2026-32096 CRITICAL - 9.3

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook handler. An unauthenticated attacker could send a crafted request that caused the server to make an arbitrary outbound HTTP GET request to any...

Vendor: useplunk
Product: plunk
Published: Mar 11, 2026
Source: NVD
CVE-2026-31976 CRITICAL - 9.8

xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml. The PRs were blocked by branch protection rules and never merged into the mai...

Vendor: xygeni
Product: xygeni-action
Published: Mar 11, 2026
Source: NVD
CVE-2026-31957 CRITICAL - 10.0

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentication is not tenant-scoped. In this mode, Himmelblau can accept authentication attempts for arbitrary...

Vendor: himmelblau-idm
Product: himmelblau
Published: Mar 11, 2026
Source: NVD