Total CVEs

119,913

Critical Severity

1,691

High Severity

5,751

Last 7 Days

1,586
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 41 - 60 of 16,318 CVEs
CVE-2026-34555 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a stack-buffer-overflow (SBO) in CIccTagFixedNum<>::GetValues() and a related bug chain. The primary crash is an AddressSanitizer-reported WRITE of size 4 that overfl...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34554 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a heap-buffer-overflow (HBO) in CIccApplyCmmSearch::costFunc() can be triggered via malformed JSON configuration input to the iccApplySearch tool. AddressSanitizer reports an out-of...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34553 MEDIUM - 4.0

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a defect in LUT dump/iteration logic affecting CIccCLUT::Iterate() and output produced by CIccMBB::Describe() (via CLUT dumping). This issue has been patched in version 2.3...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34552 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) issue in IccTagLut.cpp where the code performs member access through a null pointer of type CIccApplyCLUT. This issue has been patched in version...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34551 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a null-pointer dereference (NPD) in CIccTagLut16::Write() can be triggered when processing a crafted ICC profile (embedded in a TIFF and extracted during iccTiffDump). This issue ha...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34550 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in IccProfLib/IccIO.cpp caused by an implicit conversion from a negative signed integer to size_t (unsigned), which changes the value. ...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34549 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in IccUtil.cpp triggered by a crafted input profile. Under UndefinedBehaviorSanitizer, the issue is reported as invalid left shift oper...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34548 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is an Undefined Behavior (UB) condition in the XML conversion tooling path (iccToXml) caused by an implicit conversion from a negative signed integer to icUInt32Number (unsign...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34547 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, an Undefined Behavior (UB) condition in IccUtil.cpp can be triggered by a crafted ICC profile when running iccDumpProfile. This issue has been patched in version 2.3.1.6.

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34546 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted TIFF input can trigger Undefined Behavior (UB) due to division by zero in the TIFF handling code paths used by iccTiffDump. This issue has been patched in version 2.3.1.6.

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-2480 MEDIUM - 6.4

The WP Shortcodes Plugin โ€” Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'max_width' attribute of the `su_box` shortcode in all versions up to, and including, 7.4.10 due to insufficient input sanitization and output escaping on user supplied ...

Published: Mar 31, 2026
Source: NVD

FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability

Vendor: pip
Product: fastmcp
Published: Mar 31, 2026
Source: GitHub

phpMyFAQ is Vulnerable to Stored XSS via Unsanitized Email Field in Admin FAQ Editor

Vendor: composer
Product: thorsten/phpmyfaq
Published: Mar 31, 2026
Source: GitHub

onnx Vulnerable to Path Traversal via Symlink

Vendor: pip
Product: onnx
Published: Mar 31, 2026
Source: GitHub

FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities

Vendor: pip
Product: fastmcp
Published: Mar 31, 2026
Source: GitHub
CVE-2026-25726 HIGH - 8.1

Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding)

Vendor: go
Product: github.com/cloudreve/Cloudreve/v4
Published: Mar 31, 2026
Source: GitHub
CVE-2025-64340 MEDIUM - 6.7

FastMCP has a Command Injection vulnerability - Gemini CLI

Vendor: pip
Product: fastmcp
Published: Mar 31, 2026
Source: GitHub
CVE-2026-5215 MEDIUM - 4.3

A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgi...

Published: Mar 31, 2026
Source: NVD
CVE-2026-5214 HIGH - 8.8

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgi_addgroup_get_gro...

Published: Mar 31, 2026
Source: NVD

SiYuan is a personal knowledge management system. From version 3.6.0 to before version 3.6.2, the SanitizeSVG function introduced in version 3.6.0 to fix XSS in the unauthenticated /api/icon/getDynamicIcon endpoint can be bypassed by using namespace-prefixed element names such as <x:script xmlns:...

Vendor: siyuan-note
Product: siyuan
Published: Mar 31, 2026
Source: NVD