Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,257
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,341 - 7,360 of 12,781 CVEs
CVE-2026-34731 HIGH - 7.5

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the Live plugin allows unauthenticated users to terminate any active live stream. The endpoint processes RTMP callback events to mark streams as finished in the database, but performs...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34394 HIGH - 8.1

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks any CSRF token validation. There is no call to isGlobalTokenValid() or verifyToken() before processing the request. Combined with the application�...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34381 HIGH - 7.5

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded documents. The Docker image ships with AllowOverride None in the Apache configuration, which causes Apache to silently ignor...

Vendor: Admidio
Product: admidio
Published: Mar 31, 2026
Source: NVD
CVE-2026-34367 HIGH - 7.6

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Invoice PDF generation module. User-supplied HTML in the invoice Notes fiel...

Vendor: InvoiceShelf
Product: InvoiceShelf
Published: Mar 31, 2026
Source: NVD
CVE-2026-34366 HIGH - 7.6

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Payment receipt PDF generation module. User-supplied HTML in the payment No...

Vendor: InvoiceShelf
Product: InvoiceShelf
Published: Mar 31, 2026
Source: NVD
CVE-2026-5211 HIGH - 8.8

A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This vulnerability affects the function UPnP_AV_S...

Vendor: dlink
Product: dnr-202l_firmware
Published: Mar 31, 2026
Source: NVD
CVE-2026-4800 HIGH - 8.1

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink. When an application passes un...

Vendor: npm
Product: lodash
Published: Mar 31, 2026
Source: NVD
CVE-2026-34784 HIGH - 7.5

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its validators on storage adapters that support streaming (e.g. the ...

Vendor: parse-community
Product: parse-server
Published: Mar 31, 2026
Source: NVD
CVE-2026-34365 HIGH - 7.6

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Estimate PDF generation module. User-supplied HTML in the estimate Notes fi...

Vendor: InvoiceShelf
Product: InvoiceShelf
Published: Mar 31, 2026
Source: NVD
CVE-2026-30290 HIGH - 8.4

An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Vendor: intouchapp
Product: intouch_contacts_\&_caller_id
Published: Mar 31, 2026
Source: NVD
CVE-2026-5210 HIGH - 7.3

A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a manipulation of the argument page results in file inclusion. Remote exploitation of the attack is possible. The exploit is now public and may be used.

Published: Mar 31, 2026
Source: NVD
CVE-2026-5190 HIGH - 7.5

Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. To remediate this issue, users ...

Published: Mar 31, 2026
Source: NVD
CVE-2026-32726 HIGH - 8.1

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a simple string-prefix comparison when checking whether a requested resource path was co...

Vendor: scitokens
Product: scitokens-cpp
Published: Mar 31, 2026
Source: NVD
CVE-2026-32725 HIGH - 8.3

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before authorization and collapses "...

Vendor: scitokens
Product: scitokens-cpp
Published: Mar 31, 2026
Source: NVD
CVE-2026-30279 HIGH - 8.4

An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Vendor: squareapps
Product: my_location
Published: Mar 31, 2026
Source: NVD
CVE-2026-30277 HIGH - 8.4

An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Vendor: triumph-adler
Product: mobile_print
Published: Mar 31, 2026
Source: NVD
CVE-2026-2123 HIGH - 7.8

A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerabi...

Vendor: microfocus
Product: operations_agent
Published: Mar 31, 2026
Source: NVD
CVE-2026-24165 HIGH - 7.8

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: BioNeMo Framework
Published: Mar 31, 2026
Source: NVD
CVE-2026-24164 HIGH - 8.8

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: BioNeMo Framework
Published: Mar 31, 2026
Source: NVD
CVE-2026-24154 HIGH - 7.6

NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, data tampering, and information dis...

Vendor: NVIDIA
Product: Jetson Xavier Series, Jetson Orin Series and Jetson Thor
Published: Mar 31, 2026
Source: NVD