Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

1,961
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,461 - 2,480 of 3,450 CVEs
CVE-2026-2628 CRITICAL - 9.8

The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.

Published: Mar 03, 2026
Source: NVD
CVE-2026-27971 CRITICAL - 9.8

Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where ...

Vendor: npm
Product: @builder.io/qwik
Published: Mar 02, 2026
Source: GitHub

Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CSRF protection on the URL unfurl service endpoint to be trivially bypassed by any unauthenticated remote attacker. Combined with the absence of a login requirement on the endpoint i...

Vendor: composer
Product: idno/known
Published: Mar 02, 2026
Source: GitHub

WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVideo related to the plugin upload/import functionality. The issue allowed an authenticated administrator to upload a specially crafted ZIP archive conta...

Vendor: composer
Product: wwbn/avideo
Published: Mar 02, 2026
Source: GitHub
CVE-2026-28501 CRITICAL - 9.8

WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. The application fails to properly sanitize the catName parameter when it is supplied via a JSON-fo...

Vendor: composer
Product: wwbn/avideo
Published: Mar 02, 2026
Source: GitHub
CVE-2026-26713 CRITICAL - 9.8

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.

Vendor: carmelo
Product: simple_food_order_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26712 CRITICAL - 9.8

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.

Vendor: carmelo
Product: simple_food_order_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26711 CRITICAL - 9.8

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.

Vendor: carmelo
Product: simple_food_order_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26710 CRITICAL - 9.8

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.

Vendor: carmelo
Product: simple_food_order_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26709 CRITICAL - 9.8

code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.

Vendor: carmelo
Product: simple_gym_management_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-0029 CRITICAL - 9.8

In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2026-0006 CRITICAL - 9.8

In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2025-48609 CRITICAL - 9.1

In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities due to a path traversal error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed...

Vendor: Google
Product: Android
Published: Mar 02, 2026
Source: NVD
CVE-2026-26707 CRITICAL - 9.8

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26706 CRITICAL - 9.8

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26705 CRITICAL - 9.8

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26704 CRITICAL - 9.8

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26708 CRITICAL - 9.8

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-26700 CRITICAL - 9.8

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php.

Vendor: jon-remus-sevellejo
Product: personnel_property_equipment_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-24105 CRITICAL - 9.8

An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a command injection vulnerability if injected into doSystemCmd.

Vendor: tenda
Product: ac15_firmware
Published: Mar 02, 2026
Source: NVD