Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,635
Quick preset (or use dates below)
Clear Filters
Showing 2,361 - 2,380 of 3,578 CVEs
CVE-2025-70230 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 05, 2026
Source: NVD
CVE-2025-70229 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 05, 2026
Source: NVD
CVE-2025-13476 CRITICAL - 9.8

Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0โ€“v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking extension diversity, allowing Deep Packet Inspection (DPI) systems to trivially identify and block proxy traffic, undermining censorship circumvention. (CW...

Vendor: Rakuten Viber
Product: Rakuten Viber Cloak - Android, Rakuten Viber Cloak - Windows
Published: Mar 05, 2026
Source: NVD
CVE-2026-2599 CRITICAL - 9.8

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it possible for unauthenticated attackers to in...

Published: Mar 05, 2026
Source: NVD
CVE-2026-2743 CRITICAL - 9.8

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before

Vendor: seppmail
Product: seppmail
Published: Mar 05, 2026
Source: NVD
CVE-2026-28536 CRITICAL - 9.6

Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

Vendor: Huawei
Product: HarmonyOS
Published: Mar 05, 2026
Source: NVD
CVE-2026-1678 CRITICAL - 9.4

dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, and the final null terminator can be written past the buffer. With assertions disabled (default), a malicious DNS response can trigger an out-of-bounds ...

Vendor: zephyrproject
Product: zephyr
Published: Mar 05, 2026
Source: NVD
CVE-2026-2418 CRITICAL - 9.1

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

Published: Mar 05, 2026
Source: NVD
CVE-2026-29128 CRITICAL - 10.0

IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files (e.g., zebra.conf, bgpd.conf, ospfd.conf, ripd.conf) contain hardcoded or otherwise in...

Vendor: International Datacasting Corporation
Product: SFX2100 Satellite Receiver
Published: Mar 05, 2026
Source: NVD
CVE-2026-28115 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_AttractiveDonationsSystem allows Blind SQL Injection.This issue affects WP Attractive Donations System - Easy ...

Vendor: loopus
Product: WP Attractive Donations System - Easy Stripe & Paypal donations
Published: Mar 05, 2026
Source: NVD
CVE-2026-28114 CRITICAL - 9.1

Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell to a Web Server.This issue affects WooCommerce License Manager: from n/a through <= 7.0.6.

Vendor: firassaidi
Product: WooCommerce License Manager
Published: Mar 05, 2026
Source: NVD
CVE-2026-28105 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a through <= 1.7.7.

Vendor: ThemeREX
Product: Good Energy
Published: Mar 05, 2026
Source: NVD
CVE-2026-28074 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a through <= 1.4.0.

Vendor: ThemeREX
Product: Pizza House
Published: Mar 05, 2026
Source: NVD
CVE-2026-28043 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Healer - Doctor, Clinic & Medical WordPress Theme healer allows PHP Local File Inclusion.This issue affects Healer - Doctor, Clinic & Medical WordPress ...

Vendor: ThemeREX
Product: Healer - Doctor, Clinic & Medical WordPress Theme
Published: Mar 05, 2026
Source: NVD
CVE-2026-27984 CRITICAL - 9.0

Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This issue affects Widget Options: from n/a through <= 4.1.3.

Vendor: Marketing Fire
Product: Widget Options
Published: Mar 05, 2026
Source: NVD
CVE-2026-27983 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escalation.This issue affects LMS Elementor Pro: from n/a through <= 1.0.4.

Vendor: designthemes
Product: LMS Elementor Pro
Published: Mar 05, 2026
Source: NVD
CVE-2026-27439 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through <= 1.5.

Vendor: ThemeREX
Product: Dentario
Published: Mar 05, 2026
Source: NVD
CVE-2026-27438 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects Kingler: from n/a through <= 1.7.

Vendor: ThemeREX
Product: Kingler
Published: Mar 05, 2026
Source: NVD
CVE-2026-27437 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This issue affects Tennis Club: from n/a through <= 1.2.3.

Vendor: ThemeREX
Product: Tennis Club
Published: Mar 05, 2026
Source: NVD
CVE-2026-27417 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue affects Sweet Date: from n/a through < 4.0.1.

Vendor: SeventhQueen
Product: Sweet Date
Published: Mar 05, 2026
Source: NVD