Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,421 - 7,440 of 12,781 CVEs
CVE-2026-29924 HIGH - 7.6

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

Vendor: getgrav
Product: grav
Published: Mar 30, 2026
Source: NVD
CVE-2026-34377 HIGH - 8.1

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid...

Vendor: rust
Product: zebrad
Published: Mar 30, 2026
Source: GitHub
CVE-2026-4046 HIGH - 7.5

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by removing the IBM1390 an...

Published: Mar 30, 2026
Source: NVD
CVE-2026-33030 HIGH - 8.8

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify, and delete resources belonging to other users. The application's base Model st...

Vendor: 0xJacky
Product: nginx-ui
Published: Mar 30, 2026
Source: NVD
CVE-2026-33028 HIGH - 7.5

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent requests lead to the severe corruption of the primar...

Vendor: 0xJacky
Product: nginx-ui
Published: Mar 30, 2026
Source: NVD
CVE-2026-30077 HIGH - 7.5

OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for particular inputs. An example input in hex stream is 80 00 00 0E 00 00 01 00 0F 80 02 02 40 00 58 00 01 88.

Vendor: openairinterface
Product: openairinterface
Published: Mar 30, 2026
Source: NVD
CVE-2026-29872 HIGH - 8.2

A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19). The affected Streamlit-based GitHub MCP Agent stores user-supplied API tokens in process-wide environment variables using os.environ without pr...

Vendor: theunwindai
Product: awesome_llm_apps
Published: Mar 30, 2026
Source: NVD
CVE-2026-34363 HIGH - 5.3

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers process each subscriber concurrently using shared mutable objects. T...

Vendor: npm
Product: parse-server
Published: Mar 30, 2026
Source: GitHub
CVE-2026-34359 HIGH - 7.4

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authentication credential dispatch. Because configured ...

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.core
Published: Mar 30, 2026
Source: GitHub
CVE-2026-29954 HIGH - 7.6

In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field is only URL-encoded without validating the target address. More critically, when kubeconfiggenerator uses wget to downl...

Vendor: cloudark
Product: kubeplus
Published: Mar 30, 2026
Source: NVD
CVE-2026-33949 HIGH - 8.1

Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql allows unauthenticated users to write and overwrite arbitrary files within the project root. This is achieved by manipulating the relativePath parameter in GraphQL mutations. The ...

Vendor: npm
Product: @tinacms/graphql
Published: Mar 30, 2026
Source: GitHub
CVE-2026-33641 HIGH - 7.8

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic configuration values in which substrings enclosed in backticks are executed as system commands during configuration parsing. This behavior occurs in Config.get_value() and is implemented...

Vendor: pip
Product: Glances
Published: Mar 30, 2026
Source: GitHub
CVE-2026-33533 HIGH - 6.5

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP response. Because the XML-RPC handler does not validate the Content-Type header, an a...

Vendor: pip
Product: Glances
Published: Mar 30, 2026
Source: GitHub

Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case or uppercase URL schemes. This issue has been patched in version 8.29.0.

Vendor: go
Product: github.com/gotenberg/gotenberg/v8
Published: Mar 30, 2026
Source: GitHub
CVE-2026-34472 HIGH - 7.1

Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows unauthenticated attackers on the local network to retrieve sensitive credentials from the router's web management interface, including the default administrator password, WLAN ...

Published: Mar 30, 2026
Source: NVD
CVE-2026-33643 HIGH - 7.4

SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file plugins/mysql/lib/column.go.

Vendor: schemahero
Product: schemahero
Published: Mar 30, 2026
Source: NVD
CVE-2026-2285 HIGH - 7.5

CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.

Vendor: crewai
Product: crewai
Published: Mar 30, 2026
Source: NVD
CVE-2026-29953 HIGH - 7.4

SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the columnAsInsert function in file plugins/postgres/lib/column.go.

Vendor: schemahero
Product: schemahero
Published: Mar 30, 2026
Source: NVD
CVE-2026-33373 HIGH - 8.8

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client due to the issuance of authentication tokens without CSRF protection during certain account state transitions. Specifically, tokens generated after opera...

Published: Mar 30, 2026
Source: NVD
CVE-2026-34219 HIGH - 5.9

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an attacker-controlled, n...

Vendor: rust
Product: libp2p-gossipsub
Published: Mar 30, 2026
Source: GitHub