Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 41 - 60 of 157 CVEs
CVE-2026-34585 HIGH - 8.6

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special characters. An attacker can embed a malicious IAL value inside a .sy document, packag...

Vendor: siyuan-note
Product: siyuan
Published: Mar 31, 2026
Source: NVD
CVE-2026-34449 CRITICAL - 9.6

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a JavaS...

Vendor: siyuan-note
Product: siyuan
Published: Mar 31, 2026
Source: NVD
CVE-2026-34448 CRITICAL - 9.0

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with β€œCover From -> Asset Field” enabled. The vulnerable code accepts arbitrar...

Vendor: siyuan-note
Product: siyuan
Published: Mar 31, 2026
Source: NVD
CVE-2026-34740 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page visit. The URL is validated only with PHP's FI...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-33976 CRITICAL - 9.6

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source p...

Vendor: streetwriters
Product: Notesnook Web/Desktop, Notesnook iOS/Android
Published: Mar 27, 2026
Source: NVD
CVE-2026-33955 HIGH - 8.6

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when an attacker-controlled note header is displayed using ...

Vendor: streetwriters
Product: Notesnook Web/Desktop
Published: Mar 27, 2026
Source: NVD
CVE-2026-34056 HIGH - 7.7

OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including version 8.0.0.3 allows low-privilege users to view and download Ensora eRx error logs without proper authorization checks. Thi...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-34055 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` without verifying that the note belongs to a patient the ...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-34053 HIGH - 7.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint `interface/forms/procedure_order/handle_deletions.php` allows any authenticated user, regardless of role, to irrevers...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-34051 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Export functionality, allowing unauthorized users to perform import and export actions through direct request manipulation ...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33934 MEDIUM - 4.3

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal user to retrieve the drawn signature image of any...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33933 MEDIUM - 6.1

OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute arbitrary JavaScript in ...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33932 HIGH - 7.6

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CCDA document to execute arbitrary JavaScript in a c...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33931 MEDIUM - 6.5

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other patients' paymen...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33918 HIGH - 7.6

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid session and CSRF token, but does not check any ACL pe...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33917 HIGH - 8.8

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input va...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33915 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, five insurance company REST API routes are missing the `RestConfig::request_authorization_check()` call that every other data-modifying route in the standard API uses. T...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33914 HIGH - 7.2

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the PostCalendar module contains a blind SQL injection vulnerability in the `categoriesUpdate` administrative function. The `dels` POST parameter is read via `pnVarClean...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33913 HIGH - 7.7

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:include href="file:///etc/passwd" parse=...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD
CVE-2026-33912 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim, executes arbitrary JavaScript in the victim's browser session. Version 8.0....

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD