Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,973
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,401 - 2,420 of 3,450 CVEs
CVE-2025-40931 CRITICAL - 9.1

Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id. Apache::Session::Generate::MD5 generates session ids insecurely. The default session id generator returns a MD5 hash seeded with the built-in rand() function, the epoch time, and the PID. The PID will come fro...

Vendor: CHORNY
Product: Apache::Session::Generate::MD5
Published: Mar 05, 2026
Source: NVD
CVE-2025-40926 CRITICAL - 9.8

Plack::Middleware::Session::Simple versions through 0.04 for Perl generates session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be gue...

Vendor: KAZEBURO
Product: Plack::Middleware::Session::Simple
Published: Mar 05, 2026
Source: NVD
CVE-2026-2835 CRITICAL - 9.1

An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1.0 request bodies to be close-delimited and incorrect handling of multiple Transfer-Encoding values, allowing attac...

Vendor: rust
Product: pingora-core
Published: Mar 05, 2026
Source: NVD
CVE-2026-2833 CRITICAL - 9.1

An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing an Upgrade header, causing the proxy to pass through the rest of the bytes on the connection to a backend before th...

Vendor: rust
Product: pingora-core
Published: Mar 05, 2026
Source: NVD
CVE-2026-29191 CRITICAL - 9.3

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered that allowed a possible account takeover via XSS in /saml-post Endpoint. This issue has been patched in version 4.12.0.

Vendor: go
Product: github.com/zitadel/zitadel
Published: Mar 04, 2026
Source: GitHub
CVE-2026-29000 CRITICAL - 10.0

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers who possess the server's RSA public key can create a JWE-wrapped PlainJWT ...

Vendor: pac4j
Product: pac4j-jwt
Published: Mar 04, 2026
Source: NVD
CVE-2025-70222 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuthCode.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 04, 2026
Source: NVD
CVE-2026-29183 CRITICAL - 9.3

SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET /api/icon/getDynamicIcon" when type=8, attacker-controlled content is embedded into SVG output without escaping. Because the...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 04, 2026
Source: GitHub
CVE-2025-70225 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfig component

Vendor: dlink
Product: dir-513_firmware
Published: Mar 04, 2026
Source: NVD
CVE-2025-70221 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 04, 2026
Source: NVD
CVE-2025-46108 CRITICAL - 9.8

D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 04, 2026
Source: NVD
CVE-2026-3545 CRITICAL - 9.6

Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Mar 04, 2026
Source: NVD
CVE-2025-70219 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 04, 2026
Source: NVD
CVE-2025-70226 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 04, 2026
Source: NVD
CVE-2025-70223 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 04, 2026
Source: NVD
CVE-2026-20131 CRITICAL - 10.0

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Ja...

Vendor: Cisco
Product: Cisco Secure Firewall Management Center (FMC)
Published: Mar 04, 2026
Source: NVD
CVE-2026-20079 CRITICAL - 10.0

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is du...

Vendor: Cisco
Product: Cisco Secure Firewall Management Center (FMC)
Published: Mar 04, 2026
Source: NVD
CVE-2025-70220 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 04, 2026
Source: NVD
CVE-2025-70218 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 04, 2026
Source: NVD
CVE-2025-69969 CRITICAL - 9.6

A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a connection. This is ...

Vendor: pebblepower
Product: pebble_prism_ultra_firmware
Published: Mar 04, 2026
Source: NVD