Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 541 - 560 of 897 CVEs

Permission control vulnerability in the resource scheduling module.ย Impact: Successful exploitation of this vulnerability may affect service integrity.

Vendor: Huawei
Product: HarmonyOS
Published: Mar 05, 2026
Source: NVD

dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.37.3, a path traversal vulnerability exists in dbt-common's safe_extract() function used when extracting tarball archives. The function uses os.path.commonprefix() to validate ...

Vendor: pip
Product: dbt-common
Published: Mar 05, 2026
Source: GitHub

Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server's Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting...

Vendor: go
Product: github.com/bishopfox/sliver
Published: Mar 05, 2026
Source: GitHub

Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in version 3.1.4.

Vendor: npm
Product: @backstage/plugin-scaffolder-backend
Published: Mar 05, 2026
Source: GitHub

Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths. When these URLs were processed by integration functions that co...

Vendor: npm
Product: @backstage/integration
Published: Mar 05, 2026
Source: GitHub

Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet files. In order to analyze cross-origin style sheets (stored on websites different from the original ...

Vendor: npm
Product: darkreader
Published: Mar 04, 2026
Source: GitHub

Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Conditions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service.

Vendor: Dell
Product: Device Management Agent (DDMA)
Published: Mar 04, 2026
Source: NVD

Dell PowerScale OneFS, versions 9.10.0.0 through 9.10.1.5 and versions 9.11.0.0 through 9.12.0.1, contains an external control of system or configuration setting vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to protection mechanism ...

Vendor: Dell
Product: PowerScale OneFS
Published: Mar 04, 2026
Source: NVD

Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php.

Vendor: oretnom23
Product: simple_logistic_hub_parcel\'s_management_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 03, 2026
Source: NVD

An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may a...

Vendor: nokia
Product: impact_mobile
Published: Mar 03, 2026
Source: NVD

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /admin/services/manage_service.php.

Vendor: oretnom23
Product: simple_online_men\'s_salon_management_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_service.

Vendor: oretnom23
Product: simple_online_men\'s_salon_management_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view_appointment.php.

Vendor: oretnom23
Product: simple_online_men\'s_salon_management_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Simple Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=delete_appointment.

Vendor: oretnom23
Product: simple_online_men\'s_salon_management_system
Published: Mar 03, 2026
Source: NVD
CVE-2026-3465 LOW - 3.1

A vulnerability was determined in Tuya App and SDK 24.07.11 on Android. Affected by this vulnerability is an unknown functionality of the component JSON Data Point Handler. This manipulation of the argument cruise_time causes denial of service. Remote exploitation of the attack is possible. The comp...

Published: Mar 03, 2026
Source: NVD

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. Race condition in file-system storage and file-based cache backends in Django allows an attacker to cause file system objects to be created with incorrect permissions via concurrent requests, where one thread'...

Vendor: djangoproject
Product: Django
Published: Mar 03, 2026
Source: NVD