Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 561 - 580 of 897 CVEs
CVE-2026-3463 LOW - 3.3

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::binary_writer::append of the file source/detail/binary.hpp of the component Compound Document Parser. This manipulation causes heap-based buffer overflow. The attack can only be executed locally...

Published: Mar 03, 2026
Source: NVD

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of cryptographic signature. The attack can be initiat...

Vendor: Dataease
Product: SQLBot
Published: Mar 03, 2026
Source: NVD
CVE-2026-3449 LOW - 3.3

Versions of the package @tootallnate/once before 3.0.1 are vulnerable to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely. This ...

Published: Mar 03, 2026
Source: NVD

Improper Locking vulnerability (CWE-667) in Gallagher Morpho integration allows a privileged operator to cause a limited denial-of-service in the Command Centre Server. This issue affects Command Centre Server: 9.40 prior to vEL9.40.1976(MR1), 9.30 prior to vEL9.30.3382 (MR4), 9.20 prior to vEL...

Vendor: Gallagher
Product: Command Centre Server
Published: Mar 03, 2026
Source: NVD

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.

Vendor: nocodb
Product: nocodb
Published: Mar 02, 2026
Source: NVD

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint returned different responses for registered and unregistered emails, allowing user enumeration. This issue has been patched in version 0.301.3.

Vendor: nocodb
Product: nocodb
Published: Mar 02, 2026
Source: NVD
CVE-2026-0995 LOW - 3.6

An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to ensure the completion of memory accesses related to SME.

Published: Mar 02, 2026
Source: NVD
CVE-2026-3407 LOW - 3.3

A vulnerability was determined in YosysHQ yosys up to 0.62. This affects the function Yosys::RTLIL::Const::set of the file kernel/rtlil.h of the component BLIF File Parser. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has bee...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3405 LOW - 3.1

A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitabi...

Vendor: jeesite
Product: jeesite
Published: Mar 02, 2026
Source: NVD
CVE-2026-3403 LOW - 2.4

A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The explo...

Vendor: phpgurukul
Product: student_record_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-3402 LOW - 2.4

A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The explo...

Vendor: phpgurukul
Product: student_record_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-3401 LOW - 3.1

A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of an attack is rather high. It is indicated that the exploitabi...

Vendor: senior-walter
Product: web-based_pharmacy_product_management_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-3394 LOW - 3.3

A vulnerability was detected in jarikomppa soloud up to 20200207. This affects the function SoLoud::Wav::loadwav of the file src/audiosource/wav/soloud_wav.cpp of the component WAV File Parser. Performing a manipulation results in memory corruption. The attack must be initiated from a local position...

Vendor: solhsa
Product: soloud
Published: Mar 01, 2026
Source: NVD
CVE-2026-3393 LOW - 3.3

A security vulnerability has been detected in jarikomppa soloud up to 20200207. The impacted element is the function SoLoud::Wav::loadflac of the file src/audiosource/wav/soloud_wav.cpp of the component Audio File Handler. Such manipulation leads to heap-based buffer overflow. The attack must be car...

Published: Mar 01, 2026
Source: NVD
CVE-2026-3392 LOW - 3.3

A weakness has been identified in FascinatedBox lily up to 2.3. The affected element is the function eval_tree of the file src/lily_emitter.c. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been made available to the public and could b...

Vendor: lily-lang
Product: lily
Published: Mar 01, 2026
Source: NVD
CVE-2026-3391 LOW - 3.3

A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been released to the public and may be used for ...

Vendor: lily-lang
Product: lily
Published: Mar 01, 2026
Source: NVD
CVE-2026-3390 LOW - 3.3

A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error Reporting. The manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is ...

Vendor: lily-lang
Product: lily
Published: Mar 01, 2026
Source: NVD
CVE-2026-3389 LOW - 3.3

A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference. The attack can only be executed locally. The exploit has been publicly disclosed and ma...

Vendor: squirrel-lang
Product: squirrel
Published: Mar 01, 2026
Source: NVD
CVE-2026-3388 LOW - 3.3

A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolled recursion. The attack needs to be approached locally. The exploit has been made public and could be...

Vendor: squirrel-lang
Product: squirrel
Published: Mar 01, 2026
Source: NVD
CVE-2026-3387 LOW - 3.3

A vulnerability has been found in wren-lang wren up to 0.4.0. Affected by this issue is the function getByteCountForArguments of the file src/vm/wren_compiler.c. Such manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to t...

Vendor: wren
Product: wren
Published: Mar 01, 2026
Source: NVD