Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 461 - 480 of 897 CVEs

Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the package and lower. The component re-inserted text in the input element back into the input element as unes...

Vendor: leanprover
Product: vscode-lean4
Published: Mar 16, 2026
Source: NVD

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, in multi-user mode, AnythingLLM blocks suspended users on the normal JWT-backed session path, but it does not block them on the browser extension API key...

Vendor: Mintplex-Labs
Product: anything-llm
Published: Mar 16, 2026
Source: NVD

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The two generic system-preferences endpoints allow manager role access, while every other surface that touches the same settings is restricted to admin o...

Vendor: Mintplex-Labs
Product: anything-llm
Published: Mar 16, 2026
Source: NVD

Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Mar 16, 2026
Source: NVD

Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Mar 16, 2026
Source: NVD
CVE-2026-0849 LOW - 3.8

Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised device or bus attacker to corrupt kernel memory and potentially hijack execution.

Published: Mar 16, 2026
Source: NVD
CVE-2026-0639 LOW - 3.3

in OpenHarmony v6.0 and prior versions allow a local attacker case DOS through missing release of memory.

Vendor: openatom
Product: openharmony
Published: Mar 16, 2026
Source: NVD

Mumble before 1.6.870 is prone to an out-of-bounds array access, which may result in denial of service (client crash).

Vendor: Mumble
Product: Mumble
Published: Mar 16, 2026
Source: NVD

Raytha CMS is vulnerable to Server-Side Request Forgery in the “Themes - Import from URL” feature. It allows an attacker with high privileges to provide the URL for redirecting server-side HTTP request. This issue was fixed in version 1.4.6.

Vendor: Raytha
Product: Raytha
Published: Mar 16, 2026
Source: NVD

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information improper input. This vulnerability can be exploited only in restricted scenarios.

Vendor: OpenHarmony
Product: OpenHarmony
Published: Mar 16, 2026
Source: NVD

IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.

Vendor: IBM
Product: Aspera Console
Published: Mar 16, 2026
Source: NVD

Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.35.5.

Vendor: Elementor
Product: Elementor Website Builder
Published: Mar 13, 2026
Source: NVD

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library This vulnerability is fixed in 3.24.0.

Vendor: FreeRDP
Product: FreeRDP
Published: Mar 13, 2026
Source: NVD

wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a malicious cookie value that, when processed through urldecode() and passed to wp_mail() ...

Vendor: gVectors
Product: wpDiscuz
Published: Mar 13, 2026
Source: NVD

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

Vendor: IBM
Product: Sterling Partner Engagement Manager
Published: Mar 13, 2026
Source: NVD

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.

Vendor: IBM
Product: Sterling Partner Engagement Manager
Published: Mar 13, 2026
Source: NVD
CVE-2026-4045 LOW - 3.7

A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php. Executing a manipulation of the argument ldap_email can lead to observable response discrepancy. The attack can be executed remotely. A high complexity level is associated with t...

Published: Mar 12, 2026
Source: NVD
CVE-2026-4044 LOW - 3.8

A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a manipulation of the argument files[] results in path traversal. Remote exploitation of the attack is possible. The exploit is now ...

Published: Mar 12, 2026
Source: NVD

Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vulnerability exists in @backstage/plugin-auth-backend when auth.experimentalClientIdMetadataDocuments.enabled is set to true. The CIMD metadata fetch validates the initial client_id ...

Vendor: npm
Product: @backstage/plugin-auth-backend
Published: Mar 12, 2026
Source: GitHub

Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses String.includes(), which is case-sensitive. Browsers treat URI schemes case-insensitively. DATA:text/css,... is the same as data:text/css,... to the browser, but 'DATA:...'.in...

Vendor: npm
Product: unhead
Published: Mar 12, 2026
Source: GitHub