Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 521 - 540 of 897 CVEs
CVE-2026-3741 LOW - 3.5

A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argument linkName leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed pub...

Vendor: yifangcms
Product: yifang
Published: Mar 08, 2026
Source: NVD
CVE-2026-3721 LOW - 3.5

A weakness has been identified in 1024-lab/lab1024 SmartAdmin up to 3.29. The affected element is an unknown function of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/helpdoc/domain/form/HelpDocAddForm.java of the component Help Documentation Module. This manipulation causes cros...

Vendor: lab1024
Product: smartadmin
Published: Mar 08, 2026
Source: NVD
CVE-2026-3720 LOW - 3.5

A security flaw has been discovered in 1024-lab/lab1024 SmartAdmin up to 3.29. Impacted is an unknown function of the file smart-admin-web-javascript/src/views/business/oa/notice/components/notice-form-drawer.vue of the component Notice Module. The manipulation results in cross site scripting. The a...

Vendor: lab1024
Product: smartadmin
Published: Mar 08, 2026
Source: NVD
CVE-2026-3716 LOW - 2.4

A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This vulnerability affects the function sub_401AD4 of the file /cgi-bin/adm.cgi. Executing a manipulation of the argument Hostname can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publi...

Vendor: wavlink
Product: wl-wn579x3-c_firmware
Published: Mar 08, 2026
Source: NVD
CVE-2026-3706 LOW - 3.7

A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to h...

Published: Mar 08, 2026
Source: NVD
CVE-2026-3671 LOW - 3.3

A flaw has been found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function TokenBalanceContentProvider of the component org.ethereumphone.walletmanager.testing123. Executing a manipulation can lead to improper authorization. The attack requires local access. The ex...

Published: Mar 07, 2026
Source: NVD
CVE-2026-2671 LOW - 3.1

A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sensitive information. The attack can only be performed from the lo...

Published: Mar 07, 2026
Source: NVD
CVE-2026-3668 LOW - 3.1

A weakness has been identified in Freedom Factory dGEN1 up to 20260221. This affects the function AndroidEthereum of the component org.ethosmobile.webpwaemul. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The attack is considered to have high compl...

Published: Mar 07, 2026
Source: NVD
CVE-2026-3665 LOW - 3.3

A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xlsx_consumer::read_office_document of the file source/detail/serialization/xlsx_consumer.cpp of the component XLSX File Parser. The manipulation leads to null pointer dereference. T...

Vendor: xlnt-community
Product: xlnt
Published: Mar 07, 2026
Source: NVD
CVE-2026-3664 LOW - 3.3

A vulnerability was determined in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_document::read_directory of the file source/detail/cryptography/compound_document.cpp of the component Encrypted XLSX File Parser. Executing a manipulation can lead to out-of-bounds rea...

Vendor: xlnt-community
Product: xlnt
Published: Mar 07, 2026
Source: NVD
CVE-2026-3663 LOW - 3.3

A vulnerability was found in xlnt-community xlnt up to 1.6.1. This issue affects the function xlnt::detail::compound_document_istreambuf::xsgetn of the file source/detail/cryptography/compound_document.cpp of the component XLSX File Parser. Performing a manipulation results in out-of-bounds read. Th...

Vendor: xlnt-community
Product: xlnt
Published: Mar 07, 2026
Source: NVD

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.9, an attacker may be able to bypass escaping for the shell being used. This can result, for example, in exposure of sensitive information. This impacts users of Shescape that configure their shell to point to a file on disk that...

Vendor: npm
Product: shescape
Published: Mar 07, 2026
Source: GitHub

On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the fil...

Vendor: Go standard library
Product: os
Published: Mar 06, 2026
Source: NVD

Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDepth limit on GraphQL subscription queries received over WebSocket connections. The depth check is correctly applied to HTTP queries and mutations, but subscription queries are parsed...

Vendor: npm
Product: mercurius
Published: Mar 06, 2026
Source: GitHub

Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolates image src and alt attributes directly into an HTML string without escaping. An attacker can use a " in the alt attribute to break out of the attribute context and inject ev...

Vendor: npm
Product: defuddle
Published: Mar 06, 2026
Source: GitHub

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator might leak cleartext paths into the log file. This can reveal meta information about the files stored inside a vault at a time, where the actual vault is closed. Not every cleartext...

Vendor: cryptomator
Product: cryptomator
Published: Mar 06, 2026
Source: NVD
CVE-2026-3606 LOW - 3.3

A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this atta...

Published: Mar 05, 2026
Source: NVD

OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without homeserver validation. Remote Matrix users can impersonate allo...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD

The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from ...

Vendor: Eclipse Foundation
Product: Eclipse Jetty
Published: Mar 05, 2026
Source: NVD

HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.

Vendor: HCLSoftware
Product: Sametime for iOS
Published: Mar 05, 2026
Source: NVD