Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,961
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,441 - 2,460 of 3,450 CVEs
CVE-2025-70234 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 03, 2026
Source: NVD
CVE-2026-28697 CRITICAL - 9.1

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the craft.app.fs.writ...

Vendor: composer
Product: craftcms/cms
Published: Mar 03, 2026
Source: GitHub
CVE-2025-70241 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 03, 2026
Source: NVD
CVE-2025-70237 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 03, 2026
Source: NVD
CVE-2025-70236 CRITICAL - 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 03, 2026
Source: NVD
CVE-2025-66945 CRITICAL - 9.1

A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /api/extract, files may be written outside the intended directory, leading to arbitrary file overwrite and potentially remote code execution

Vendor: zdir
Product: zdir
Published: Mar 03, 2026
Source: NVD
CVE-2024-55020 CRITICAL - 9.8

A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.

Vendor: weintek
Product: easyweb
Published: Mar 03, 2026
Source: NVD
CVE-2026-29058 CRITICAL - 9.8

AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full server compromise, data exfiltration (e.g., configuration sec...

Vendor: composer
Product: wwbn/avideo
Published: Mar 03, 2026
Source: GitHub
CVE-2026-27012 CRITICAL - 9.8

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly calling modules/ute...

Vendor: composer
Product: devcode-it/openstamanager
Published: Mar 03, 2026
Source: GitHub
CVE-2026-26279 CRITICAL - 9.1

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings in the panel...

Vendor: composer
Product: froxlor/froxlor
Published: Mar 03, 2026
Source: GitHub
CVE-2026-3136 CRITICAL - 9.8

An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment. This vulnerability was patched on 26 January 2026, and no customer action is needed.

Vendor: google
Product: cloud_build
Published: Mar 03, 2026
Source: NVD
CVE-2026-24103 CRITICAL - 9.8

A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.

Vendor: tenda
Product: ac15_firmware
Published: Mar 03, 2026
Source: NVD
CVE-2026-22891 CRITICAL - 9.8

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability...

Vendor: The Biosig Project
Product: libbiosig
Published: Mar 03, 2026
Source: NVD
CVE-2025-70821 CRITICAL - 9.8

renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component

Vendor: renren
Product: renren-security
Published: Mar 03, 2026
Source: NVD
CVE-2021-25320 CRITICAL - 10.0

A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This issue affects: Rancher versions prior to 2.5.9...

Vendor: go
Product: github.com/rancher/rancher
Published: Mar 03, 2026
Source: GitHub
CVE-2022-31247 CRITICAL - 9.1

An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner permission in another p...

Vendor: go
Product: github.com/rancher/rancher
Published: Mar 03, 2026
Source: GitHub
CVE-2021-36783 CRITICAL - 10.0

A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This issue affects: SUSE Ranch...

Vendor: go
Product: github.com/rancher/rancher
Published: Mar 03, 2026
Source: GitHub
CVE-2025-59059 CRITICAL - 9.8

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

Vendor: Apache Software Foundation
Product: Apache Ranger
Published: Mar 03, 2026
Source: NVD
CVE-2026-22886 CRITICAL - 9.8

OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login, the server continues to...

Vendor: Eclipse Foundation
Product: Eclipse OpenMQ
Published: Mar 03, 2026
Source: NVD
CVE-2026-1492 CRITICAL - 9.8

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting...

Published: Mar 03, 2026
Source: NVD