Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,852
Quick preset (or use dates below)
Clear Filters
Showing 2,281 - 2,300 of 3,578 CVEs
CVE-2026-28292 CRITICAL - 9.8

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains...

Vendor: steveukx
Product: simple-git
Published: Mar 10, 2026
Source: NVD
CVE-2026-27825 CRITICAL - 9.1

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.17.0, the `confluence_download_attachment` MCP tool accepts a `download_path` parameter that is written to without any directory boundary enforcement. An attacker who can call this...

Vendor: pip
Product: mcp-atlassian
Published: Mar 10, 2026
Source: GitHub
CVE-2026-31840 CRITICAL - 9.8

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject SQL into the PostgreSQL database through an improper escapin...

Vendor: npm
Product: parse-server
Published: Mar 10, 2026
Source: GitHub
CVE-2026-3843 CRITICAL - 9.8

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-f...

Published: Mar 10, 2026
Source: NVD
CVE-2026-30970 CRITICAL - 9.1

Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, Coral Server allowed the creation of agent sessions through the /api/v1/sessions endpoint without strong authentication. This endpoint performs r...

Vendor: Coral-Protocol
Product: coral-server
Published: Mar 10, 2026
Source: NVD
CVE-2026-30969 CRITICAL - 9.1

Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, Coral Server did not enforce strong authentication between agents and the server within an active session. This could allow an attacker who obtai...

Vendor: Coral-Protocol
Product: coral-server
Published: Mar 10, 2026
Source: NVD
CVE-2026-30968 CRITICAL - 9.8

Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, the SSE endpoint (/sse/v1/...) in Coral Server did not strongly validate that a connecting agent was a legitimate participant in the session. Thi...

Vendor: Coral-Protocol
Product: coral-server
Published: Mar 10, 2026
Source: NVD
CVE-2025-69615 CRITICAL - 9.1

Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-24, fixed 2025-11-03.

Published: Mar 10, 2026
Source: NVD
CVE-2025-69614 CRITICAL - 9.4

Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-27, fixed 2025-10-31.

Published: Mar 10, 2026
Source: NVD
CVE-2025-56422 CRITICAL - 9.8

A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.

Published: Mar 10, 2026
Source: NVD
CVE-2025-41709 CRITICAL - 9.8

[PROBLEMTYPE] in [COMPONENT] in [VENDOR] [PRODUCT] [VERSION] on [PLATFORMS] allows [ATTACKER] to [IMPACT] via [VECTOR]

Vendor: Janitza, Weidmueller
Product: UMG 96RM-E 24V(5222063), UMG 96RM-E 230V(5222062), ENERGY METER 750-230 (2540910000), ENERGY METER 750-24 (2540900000)
Published: Mar 10, 2026
Source: NVD
CVE-2025-40943 CRITICAL - 9.6

Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering a legitimate user to import a specially crafted trace file

Published: Mar 10, 2026
Source: NVD
CVE-2026-30862 CRITICAL - 9.0

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The root cause is a lack of HTML sanitization in the React component rendering pipeline, allowing malicious attributes to be in...

Vendor: appsmithorg
Product: appsmith
Published: Mar 10, 2026
Source: NVD
CVE-2026-27685 CRITICAL - 9.1

SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.

Vendor: SAP_SE
Product: SAP NetWeaver Enterprise Portal Administration
Published: Mar 10, 2026
Source: NVD
CVE-2026-0953 CRITICAL - 9.8

The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon. This is due to the plugin failing to verify that the email provided in the authentication request matches the email from the validated OAuth token. Th...

Published: Mar 10, 2026
Source: NVD
CVE-2025-11158 CRITICAL - 9.1

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.

Vendor: Hitachi Vantara
Product: Pentaho Data Integration and Analytics
Published: Mar 10, 2026
Source: NVD

rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical methods support and physics simulations functionalities. The vulnerability exists in the JIT (Just-In-Time) compilation engine, which is fully exposed via the CFFI (Foreign Functi...

Vendor: rust
Product: rssn
Published: Mar 10, 2026
Source: GitHub
CVE-2026-30957 CRITICAL - 10.0

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authenticated project user to execute arbitrary commands on the oneuptime-probe server/container. The root cause is that untrusted Synthetic Monitor code is exec...

Vendor: npm
Product: @oneuptime/common
Published: Mar 10, 2026
Source: GitHub
CVE-2026-30956 CRITICAL - 10.0

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isolation in OneUptime v10.0.20 and earlier by sending a forged is-multi-tenant-query header together with a controlled projectid header. Because the serve...

Vendor: npm
Product: @oneuptime/common
Published: Mar 10, 2026
Source: GitHub
CVE-2026-31816 CRITICAL - 9.1

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any r...

Vendor: Budibase
Product: budibase
Published: Mar 09, 2026
Source: NVD