Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,007
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,301 - 2,320 of 3,450 CVEs
CVE-2025-70039 CRITICAL - 9.8

An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.

Vendor: linagora
Product: twake
Published: Mar 09, 2026
Source: NVD
CVE-2026-25041 CRITICAL - 7.2

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration constructs shell commands using user-controlled configuration values (database name, host, password, etc.) without proper sanitization. The password and other ...

Vendor: npm
Product: @budibase/server
Published: Mar 09, 2026
Source: GitHub
CVE-2025-70046 CRITICAL - 9.8

An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master.

Vendor: miazzy
Product: oa-font-service
Published: Mar 09, 2026
Source: NVD
CVE-2025-70042 CRITICAL - 9.8

An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.

Published: Mar 09, 2026
Source: NVD
CVE-2025-40639 CRITICAL - 9.8

A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.

Vendor: EVENTOBOT
Product: Eventobot
Published: Mar 09, 2026
Source: NVD
CVE-2026-24713 CRITICAL - 9.8

Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache IoTDB
Published: Mar 09, 2026
Source: NVD
CVE-2026-24015 CRITICAL - 9.8

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache IoTDB
Published: Mar 09, 2026
Source: NVD
CVE-2025-41765 CRITICAL - 9.1

Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary data. This includes, but is not limited to, contact images, HTTPS certificates, system backups for restoration, server peer configurations, and BACnet/S...

Vendor: MBS
Product: UBR-01 Mk II, UBR-02, UBR-LON
Published: Mar 09, 2026
Source: NVD
CVE-2025-41764 CRITICAL - 9.1

Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary updates.

Vendor: MBS
Product: UBR-01 Mk II, UBR-02, UBR-LON
Published: Mar 09, 2026
Source: NVD
CVE-2026-3630 CRITICAL - 9.8

Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.

Vendor: deltaww
Product: commgr2
Published: Mar 09, 2026
Source: NVD
CVE-2026-3703 CRITICAL - 9.8

A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. The attack may be performed from remote. The exploit has been published and may be used. Upgrading th...

Vendor: wavlink
Product: wl-nu516u1_firmware
Published: Mar 08, 2026
Source: NVD
CVE-2026-30909 CRITICAL - 9.8

Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encrypt_afternm and seal functions do not check that output size will be less than SIZE_MAX, which could lead to integer wraparound causing an undersized output buffer. Encountering thi...

Vendor: TIMLEGGE
Product: Crypt::NaCl::Sodium
Published: Mar 08, 2026
Source: NVD
CVE-2026-30863 CRITICAL - 9.8

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook authentication adapters use JWT verification to validate identity tokens. When the adapter's audience configuratio...

Vendor: parse-community
Product: parse-server
Published: Mar 07, 2026
Source: NVD
CVE-2026-30921 CRITICAL - 10.0

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project users to submit custom Playwright code that is executed on the oneuptime-probe service. In the current implementation, this untrusted code is run inside No...

Vendor: npm
Product: @oneuptime/common
Published: Mar 07, 2026
Source: GitHub
CVE-2026-30887 CRITICAL - 10.0

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. However, the system executes this untrusted user code inside the insecure Node.js vm module. By le...

Vendor: npm
Product: @oneuptime/common
Published: Mar 07, 2026
Source: GitHub
CVE-2026-30869 CRITICAL - 9.3

SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By exploiting double‑encoded traversal sequences, an attacker can access sensitive files such as conf/conf....

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 07, 2026
Source: GitHub
CVE-2026-30861 CRITICAL - 10.0

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated remote code execution (RCE) vulnerability exists in the MCP stdio configuration validation. The application allows unrestricted user re...

Vendor: go
Product: github.com/Tencent/WeKnora
Published: Mar 07, 2026
Source: GitHub
CVE-2026-25072 CRITICAL - 9.8

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote attackers to hijack authenticated sessions. Attackers can predict session identifiers using insufficiently random cookie ...

Vendor: Anhui Seeker Electronic Technology Co., LTD.
Product: XikeStor SKS8310-8X
Published: Mar 07, 2026
Source: NVD
CVE-2026-25070 CRITICAL - 9.8

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary operating system commands. Attackers can inject malicious commands through the d...

Vendor: Anhui Seeker Electronic Technology Co., LTD.
Product: XikeStor SKS8310-8X
Published: Mar 07, 2026
Source: NVD
CVE-2026-30860 CRITICAL - 10.0

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. The validation system fails to recursively inspect child nodes with...

Vendor: go
Product: github.com/Tencent/WeKnora
Published: Mar 06, 2026
Source: GitHub