Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,007
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,321 - 2,340 of 3,450 CVEs
CVE-2026-30855 CRITICAL - 9.8

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID. Since account registra...

Vendor: go
Product: github.com/Tencent/WeKnora
Published: Mar 06, 2026
Source: GitHub
CVE-2026-30832 CRITICAL - 9.1

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to internal/private IP addresses by running repo import with a crafted --lfs-endpoint URL. The initial batch request is bli...

Vendor: go
Product: github.com/charmbracelet/soft-serve
Published: Mar 06, 2026
Source: GitHub
CVE-2026-29789 CRITICAL - 9.9

Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authorization check in workflow site-creation actions allows an authenticated attacker with workflow write access in one project to create/manage si...

Vendor: vitodeploy
Product: vito
Published: Mar 06, 2026
Source: NVD
CVE-2026-30831 CRITICAL - 9.8

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chat's enterprise DDP Streamer service. The Account.login method exposed through the DDP S...

Vendor: RocketChat
Product: Rocket.Chat
Published: Mar 06, 2026
Source: NVD
CVE-2026-26288 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then is...

Vendor: Everon
Product: api.everon.io
Published: Mar 06, 2026
Source: NVD
CVE-2026-26051 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then is...

Vendor: Mobiliti
Product: e-mobi.hu
Published: Mar 06, 2026
Source: NVD
CVE-2026-2331 CRITICAL - 9.8

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without ...

Published: Mar 06, 2026
Source: NVD
CVE-2026-2330 CRITICAL - 9.4

An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could plac...

Published: Mar 06, 2026
Source: NVD
CVE-2026-28795 CRITICAL - 9.8

OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze, and visualize data through natural language conversations. Prior to version 0.2.2, the save_report tool in openchatbi/tool/save_report.py suffers from a critical path traversal vu...

Vendor: zhongyu09
Product: openchatbi
Published: Mar 06, 2026
Source: NVD
CVE-2026-2446 CRITICAL - 9.8

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users

Published: Mar 06, 2026
Source: NVD
CVE-2026-28794 CRITICAL - 9.8

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.6, a prototype pollution vulnerability exists in the RPC JSON deserializer of the @orpc/client package. The vulnerability allows unauthenticated, remote attackers to inject arbi...

Vendor: middleapi
Product: orpc
Published: Mar 06, 2026
Source: NVD
CVE-2026-28785 CRITICAL - 9.8

Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary SQL commands via the getHistorical() method, potentially allowing them to read, modify, or delete sensitive financial data for all users in the databas...

Vendor: ghostfolio
Product: ghostfolio
Published: Mar 06, 2026
Source: NVD
CVE-2026-28680 CRITICAL - 9.3

Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform a full-read SSRF, allowing them to exfiltrate sensitive cloud metadata (IMDS) or probe internal network services. This issue has been patched in versi...

Vendor: ghostfolio
Product: ghostfolio
Published: Mar 06, 2026
Source: NVD
CVE-2026-27005 CRITICAL - 9.8

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3, an unauthenticated attacker can inject arbitrary SQL into queries executed against databases connected to Chartbrew (MySQL, PostgreSQL). This allows ...

Vendor: chartbrew
Product: chartbrew
Published: Mar 06, 2026
Source: NVD
CVE-2025-59543 CRITICAL - 9.0

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course description field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript code in the c...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 06, 2026
Source: NVD
CVE-2025-59542 CRITICAL - 9.0

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course learning path Settings field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript co...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 06, 2026
Source: NVD
CVE-2026-22552 CRITICAL - 9.4

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then is...

Vendor: ePower
Product: epower.ie
Published: Mar 06, 2026
Source: NVD
CVE-2026-21536 CRITICAL - 9.8

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

Published: Mar 05, 2026
Source: NVD
CVE-2026-28484 CRITICAL - 9.8

OpenClaw versions prior to 2026.2.15 contain an option injection vulnerability in the git-hooks/pre-commit hook that allows attackers to stage ignored files by creating maliciously-named files beginning with dashes. The hook fails to use a -- separator when piping filenames through xargs to git add,...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28474 CRITICAL - 9.8

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud display name to match an allowlisted user ID an...

Vendor: OpenClaw
Product: nextcloud-talk
Published: Mar 05, 2026
Source: NVD