Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 501 - 520 of 897 CVEs

Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and Anytype Desktop 0.54.5.

Vendor: go
Product: github.com/anyproto/anytype-heart
Published: Mar 11, 2026
Source: GitHub
CVE-2026-3946 LOW - 3.5

A vulnerability was detected in PHPEMS 11.0. The affected element is an unknown function of the file /index.php?ask=app-ask. Performing a manipulation of the argument askcontent results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be u...

Published: Mar 11, 2026
Source: NVD

Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modifying specific fields at precise offsets within an otherwise valid .EGP file, an attacker can trigger an out-of-bounds memory read during parsing. This results in an unhandled access...

Published: Mar 11, 2026
Source: NVD
CVE-2026-3911 LOW - 2.7

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user could improperly retrieve user attributes that were configured to be hidden. This unauthorized informat...

Vendor: maven
Product: org.keycloak:keycloak-services
Published: Mar 11, 2026
Source: NVD

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of ...

Vendor: Adobe
Product: Adobe Commerce
Published: Mar 11, 2026
Source: NVD

Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTML tags (angle brackets) -- it does not inspect or filter URL ...

Vendor: composer
Product: craftcms/cms
Published: Mar 11, 2026
Source: GitHub
CVE-2026-0121 LOW - 2.9

In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 10, 2026
Source: NVD
CVE-2026-0115 LOW - 2.1

In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could lead to physical information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

Vendor: google
Product: android
Published: Mar 10, 2026
Source: NVD

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Craft Commerce Order details. Malicious JavaScript can be injected via the Shipping Method Name, Order Reference, or Site Name. When a user opens the orde...

Vendor: composer
Product: craftcms/commerce
Published: Mar 10, 2026
Source: GitHub

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without proper escaping, allowing script execution to occur. This vulnera...

Vendor: composer
Product: craftcms/commerce
Published: Mar 10, 2026
Source: GitHub

Craft is a content management system (CMS). Prior to 4.17.4 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not require POST and does not enforce a CSRF token, an att...

Vendor: composer
Product: craftcms/cms
Published: Mar 10, 2026
Source: GitHub

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP reque...

Vendor: Fortinet
Product: FortiWeb
Published: Mar 10, 2026
Source: NVD

An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4...

Vendor: Fortinet
Product: FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, FortiManager Cloud
Published: Mar 10, 2026
Source: NVD

HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL

Vendor: HCL
Product: Sametime
Published: Mar 10, 2026
Source: NVD

A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the char...

Vendor: Siemens
Product: Heliox Flex 180 kW EV Charging Station, Heliox Mobile DC 40 kW EV Charging Station
Published: Mar 10, 2026
Source: NVD

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidential...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server for ABAP
Published: Mar 10, 2026
Source: NVD

A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values. It is possible to launch the attack...

Product: open-webui
Published: Mar 09, 2026
Source: NVD
CVE-2026-3766 LOW - 3.5

A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of the argument fullname results in cross site scripting. The attack may be initiated remotely. The exploit...

Vendor: senior-walter
Product: web-based_pharmacy_product_management_system
Published: Mar 08, 2026
Source: NVD
CVE-2026-3743 LOW - 3.5

A flaw has been found in YiFang CMS 2.0.5. This affects the function update of the file app/db/admin/D_singlePageGroup.php. Executing a manipulation of the argument Name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. Th...

Vendor: yifangcms
Product: yifang
Published: Mar 08, 2026
Source: NVD
CVE-2026-3742 LOW - 3.5

A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a manipulation of the argument Title results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may ...

Vendor: yifangcms
Product: yifang
Published: Mar 08, 2026
Source: NVD