Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,971
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,421 - 2,440 of 3,450 CVEs
CVE-2025-66944 CRITICAL - 9.8

SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint

Vendor: databasir
Product: databasir
Published: Mar 04, 2026
Source: NVD
CVE-2025-66678 CRITICAL - 9.8

An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request.

Vendor: faintsnow
Product: hardware_read_\&_write_utility
Published: Mar 04, 2026
Source: NVD
CVE-2026-26478 CRITICAL - 9.8

A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account.

Vendor: mobvoi
Product: tichome_mini_firmware
Published: Mar 04, 2026
Source: NVD
CVE-2025-59786 CRITICAL - 9.8

2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.

Vendor: 2N Telekomunikace a.s.
Product: 2N Access Commander
Published: Mar 04, 2026
Source: NVD
CVE-2026-27446 CRITICAL - 9.8

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This coul...

Vendor: Apache Software Foundation
Product: Apache Artemis, Apache ActiveMQ Artemis
Published: Mar 04, 2026
Source: NVD
CVE-2026-27441 CRITICAL - 9.8

SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.

Vendor: SEPPmail
Product: Secure Email Gateway
Published: Mar 04, 2026
Source: NVD
CVE-2026-28775 CRITICAL - 9.8

An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP ...

Vendor: International Datacasting Corporation (IDC)
Product: SFX2100 Series SuperFlex SatelliteReceiver
Published: Mar 04, 2026
Source: NVD
CVE-2026-3266 CRITICAL - 9.8

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. This issue affects Filr: through 25.1.2.

Vendor: opentext
Product: filr
Published: Mar 03, 2026
Source: NVD
CVE-2026-28289 CRITICAL - 10.0

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a mali...

Vendor: freescout-help-desk
Product: freescout
Published: Mar 03, 2026
Source: NVD
CVE-2026-26266 CRITICAL - 9.3

AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an alias, the HTML content is rendered in a...

Vendor: aliasvault
Product: aliasvault
Published: Mar 03, 2026
Source: NVD
CVE-2026-3224 CRITICAL - 9.8

Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).

Vendor: devolutions
Product: devolutions_server
Published: Mar 03, 2026
Source: NVD
CVE-2026-3204 CRITICAL - 9.8

Improper input validation in the error message page in Devolutions Server 2025.3.15 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.

Vendor: devolutions
Product: devolutions_server
Published: Mar 03, 2026
Source: NVD
CVE-2026-3130 CRITICAL - 9.8

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and performing a bulk deletion.

Vendor: devolutions
Product: devolutions_server
Published: Mar 03, 2026
Source: NVD
CVE-2026-2590 CRITICAL - 9.8

Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information to other users, by c...

Vendor: devolutions
Product: remote_desktop_manager
Published: Mar 03, 2026
Source: NVD
CVE-2026-25146 CRITICAL - 9.6

OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary ...

Vendor: openemr
Product: openemr
Published: Mar 03, 2026
Source: NVD
CVE-2026-24898 CRITICAL - 10.0

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the practice's MedEx API tokens, leading to comp...

Vendor: openemr
Product: openemr
Published: Mar 03, 2026
Source: NVD
CVE-2026-24848 CRITICAL - 9.9

OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() method in EtherFaxActions.php allows authenticated users to write arbitrary content to arbitrary locations on the server filesystem. This vulnerability...

Vendor: openemr
Product: openemr
Published: Mar 03, 2026
Source: NVD
CVE-2026-3485 CRITICAL - 9.8

A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability onl...

Vendor: dlink
Product: dir-868l_firmware
Published: Mar 03, 2026
Source: NVD
CVE-2025-70240 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 03, 2026
Source: NVD
CVE-2025-70239 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 03, 2026
Source: NVD