Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,040
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,261 - 2,280 of 3,450 CVEs
CVE-2026-24448 CRITICAL - 9.8

Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.

Vendor: Micro Research Ltd.
Product: MR-GM5L-S1, MR-GM5A-L1
Published: Mar 11, 2026
Source: NVD
CVE-2023-27573 CRITICAL - 9.0

netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). In practice on the public Internet, almost all users changed the password but only about 90% changed the tok...

Vendor: netbox-community
Product: netbox-docker
Published: Mar 11, 2026
Source: NVD
CVE-2026-23813 CRITICAL - 9.8

A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

Vendor: Hewlett Packard Enterprise (HPE)
Product: AOS-CX
Published: Mar 11, 2026
Source: NVD
CVE-2026-31975 CRITICAL - 9.8

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shell. Both projectPath and initialCommand in server/index.js are taken directly from the WebSocket message payload and interpolated into ...

Vendor: npm
Product: @siteboon/claude-code-ui
Published: Mar 11, 2026
Source: GitHub
CVE-2026-31871 CRITICAL - 9.8

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., sta...

Vendor: npm
Product: parse-server
Published: Mar 11, 2026
Source: GitHub
CVE-2026-31856 CRITICAL - 9.8

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter). The amount value is in...

Vendor: npm
Product: parse-server
Published: Mar 11, 2026
Source: GitHub
CVE-2026-31862 CRITICAL - 9.1

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, multiple Git-related API endpoints use execAsync() with string interpolation of user-controlled parameters (file, branch, message, commit), allowing authenticated attackers ...

Vendor: npm
Product: @siteboon/claudecodeui
Published: Mar 11, 2026
Source: GitHub
CVE-2026-30966 CRITICAL - 10.0

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field mappings such as role memberships, can be directly accessed via the REST API or GraphQL API by an...

Vendor: parse-community
Product: parse-server
Published: Mar 10, 2026
Source: NVD
CVE-2026-30965 CRITICAL - 9.1

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltrate session tokens of other users by exploiti...

Vendor: parse-community
Product: parse-server
Published: Mar 10, 2026
Source: NVD
CVE-2026-0120 CRITICAL - 9.8

In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 10, 2026
Source: NVD
CVE-2026-0116 CRITICAL - 9.8

In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 10, 2026
Source: NVD
CVE-2026-0114 CRITICAL - 9.8

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 10, 2026
Source: NVD
CVE-2026-0113 CRITICAL - 9.8

In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 10, 2026
Source: NVD
CVE-2026-0111 CRITICAL - 9.8

In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 10, 2026
Source: NVD
CVE-2026-0110 CRITICAL - 9.8

In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 10, 2026
Source: NVD

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, Socket.IO clients can send arbitrary JavaScript objects as the id argument to any service method (get, patch, update, remove). The transport layer performs no type ...

Vendor: @feathersjs
Product: mongodb
Published: Mar 10, 2026
Source: NVD

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, an unauthenticated attacker can send a crafted GET request directly to /oauth/:provider/callback with a forged profile in the query string. The OAuth service's ...

Vendor: feathersjs, @feathersjs
Product: feathers, authentication-oauth
Published: Mar 10, 2026
Source: NVD
CVE-2026-28495 CRITICAL - 9.6

GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php configuration file with arbitrary PHP code via the gsconfig editor module. The form lacks CSRF protection, enabling ...

Vendor: GetSimpleCMS-CE
Product: GetSimpleCMS-CE
Published: Mar 10, 2026
Source: NVD
CVE-2025-48611 CRITICAL - 10.0

In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: Google
Product: Android
Published: Mar 10, 2026
Source: NVD
CVE-2026-28292 CRITICAL - 9.8

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains...

Vendor: steveukx
Product: simple-git
Published: Mar 10, 2026
Source: NVD