Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,960
Quick preset (or use dates below)
Clear Filters
Showing 2,241 - 2,260 of 3,576 CVEs
CVE-2026-31896 CRITICAL - 9.8

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produto_ocultar.php script uses extract($_REQUEST) to populate local variables and then directly concatenates these variables into a SQL que...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Mar 11, 2026
Source: NVD
CVE-2026-27478 CRITICAL - 9.1

Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens). The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to...

Vendor: unitycatalog
Product: unitycatalog
Published: Mar 11, 2026
Source: NVD
CVE-2026-31877 CRITICAL - 9.8

Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result in SQL injection, allowing an attacker to extract information they wouldn't otherwise be able to. This vulnerability is fixed in 15.84.0 and 14.99....

Vendor: frappe
Product: frappe
Published: Mar 11, 2026
Source: NVD
CVE-2026-31874 CRITICAL - 9.8

Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly validate or restrict the role parameter during the user registration process. An attacker can manually modify the request payload and assign themselve...

Vendor: Taskosaur
Product: Taskosaur
Published: Mar 11, 2026
Source: NVD
CVE-2019-25487 CRITICAL - 9.8

SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execut...

Vendor: Sapido
Product: RB-1732
Published: Mar 11, 2026
Source: NVD
CVE-2019-25471 CRITICAL - 9.8

FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint. Attackers can upload ZIP files containing PHP shells, use the unzip functionality to extract them into accessible directories, and e...

Vendor: filethingie
Product: FileThingie
Published: Mar 11, 2026
Source: NVD
CVE-2019-25468 CRITICAL - 9.8

NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test.jsp endpoint. Attackers can send POST requests with shell commands embedded in the 'content...

Vendor: NetGain Systems
Product: NetGain EM Plus
Published: Mar 11, 2026
Source: NVD
CVE-2018-25159 CRITICAL - 9.8

Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting malicious OGNL expressions. Attackers can send crafted requests to the login.action endpoint with OGN...

Vendor: Epross
Product: AVCON6 systems management platform
Published: Mar 11, 2026
Source: NVD
CVE-2026-31852 CRITICAL - 10.0

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due to the workflow's elevated permissions (nearly all write permissions), this vulnerability enab...

Vendor: jellyfin
Product: code-quality.yml
Published: Mar 11, 2026
Source: NVD
CVE-2025-70082 CRITICAL - 9.8

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

Published: Mar 11, 2026
Source: NVD
CVE-2025-67041 CRITICAL - 9.8

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary one with root privileges.

Published: Mar 11, 2026
Source: NVD
CVE-2025-67039 CRITICAL - 9.1

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.

Published: Mar 11, 2026
Source: NVD
CVE-2025-67038 CRITICAL - 9.8

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the use...

Published: Mar 11, 2026
Source: NVD
CVE-2025-67035 CRITICAL - 9.8

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such as server keys, user...

Published: Mar 11, 2026
Source: NVD
CVE-2026-30741 CRITICAL - 9.8

A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack.

Vendor: openclaw
Product: openclaw
Published: Mar 11, 2026
Source: NVD
CVE-2026-27897 CRITICAL - 10.0

Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload containing a filename and content. While the developer intended for a native UI dial...

Vendor: WanderingAstronomer
Product: Vociferous
Published: Mar 11, 2026
Source: NVD
CVE-2026-30903 CRITICAL - 9.6

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

Vendor: Zoom Communications
Product: Zoom Workplace
Published: Mar 11, 2026
Source: NVD
CVE-2026-3826 CRITICAL - 9.8

IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

Vendor: wellchoose
Product: organization_portal_system
Published: Mar 11, 2026
Source: NVD
CVE-2026-2631 CRITICAL - 9.8

The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform...

Published: Mar 11, 2026
Source: NVD
CVE-2026-27842 CRITICAL - 9.8

Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configuration.

Vendor: Micro Research Ltd.
Product: MR-GM5L-S1, MR-GM5A-L1
Published: Mar 11, 2026
Source: NVD