Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,441 - 7,460 of 12,781 CVEs
CVE-2019-25654 HIGH - 7.5

Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an application...

Vendor: Coreftp
Product: Core FTP/SFTP Server
Published: Mar 30, 2026
Source: NVD
CVE-2026-4416 HIGH - 7.8

The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation.

Published: Mar 30, 2026
Source: NVD
CVE-2026-4415 HIGH - 8.1

Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation.

Published: Mar 30, 2026
Source: NVD
CVE-2026-3945 HIGH - 7.5

An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol() without properly validatin...

Published: Mar 30, 2026
Source: NVD
CVE-2026-2328 HIGH - 7.5

An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, resulting in exposure of sensitive information.

Published: Mar 30, 2026
Source: NVD
CVE-2026-3124 HIGH - 7.5

The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.7 via the executePayment() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to complete arbitrary pen...

Published: Mar 30, 2026
Source: NVD
CVE-2026-2370 HIGH - 8.1

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations that could have allowed an authenticated user with minimal workspace permissions to obtain installation credentials and imp...

Vendor: gitlab
Product: gitlab
Published: Mar 30, 2026
Source: NVD
CVE-2026-4946 HIGH - 8.8

Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data, resulting in arbitrary command execution when an analyst interacts with the UI. Specifically, the @execute annotation (which is intended for trusted, user-authored comments) is a...

Published: Mar 29, 2026
Source: NVD
CVE-2026-0562 HIGH - 8.3

A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in `backend/routers/friends.py` does not implement proper authorization checks, enabling Insecure Dir...

Vendor: lollms
Product: lollms
Published: Mar 29, 2026
Source: NVD
CVE-2026-0560 HIGH - 7.5

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in `backend/routers/files.py` fails to validate user-controlled URLs, allowing attackers to make ar...

Vendor: lollms
Product: lollms
Published: Mar 29, 2026
Source: NVD
CVE-2026-0558 HIGH - 7.5

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other file-related endpoints, and lacks the `Depends(get_current_activ...

Vendor: lollms
Product: lollms
Published: Mar 29, 2026
Source: NVD
CVE-2026-34005 HIGH - 8.8

In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon configuration handler, because system() is used.

Vendor: Xiongmai
Product: DVR/NVR devices
Published: Mar 29, 2026
Source: NVD
CVE-2026-34221 HIGH - 9.1

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used internally by MikroORM when merging object structures. The function did not prevent spe...

Vendor: npm
Product: @mikro-orm/core
Published: Mar 29, 2026
Source: GitHub
CVE-2026-5046 HIGH - 8.8

A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component Parameter Handler. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit ...

Vendor: tenda
Product: fh1201_firmware
Published: Mar 29, 2026
Source: NVD
CVE-2026-34215 HIGH - 6.5

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data, including MFA TOTP secrets, recovery codes, and OAuth access tokens. An attacker w...

Vendor: npm
Product: parse-server
Published: Mar 29, 2026
Source: GitHub
CVE-2026-34214 HIGH - 7.7

Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users that have write privilege on SQL level. This issue has been patc...

Vendor: maven
Product: io.trino:trino-iceberg
Published: Mar 29, 2026
Source: GitHub
CVE-2026-34209 HIGH - 7.5

mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative close handler validated the close voucher amount using "<" instead of "<=" against the on-chain settled amount. An attacker could submit a close voucher exac...

Vendor: npm
Product: mppx
Published: Mar 29, 2026
Source: GitHub
CVE-2026-5045 HIGH - 8.8

A vulnerability was detected in Tenda FH1201 1.2.0.14(408). This impacts the function WrlclientSet of the file /goform/WrlclientSet of the component Parameter Handler. Performing a manipulation of the argument GO results in stack-based buffer overflow. The attack is possible to be carried out remote...

Vendor: tenda
Product: fh1201_firmware
Published: Mar 29, 2026
Source: NVD
CVE-2026-5044 HIGH - 8.8

A security vulnerability has been detected in Belkin F9K1122 1.00.33. This affects the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handler. Such manipulation of the argument webpage leads to stack-based buffer overflow. The attack can be executed...

Vendor: belkin
Product: f9k1122_firmware
Published: Mar 29, 2026
Source: NVD
CVE-2026-33575 HIGH - 7.5

OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair endpoint and OpenClaw qr command. Attackers with access to leaked setup codes from chat history, logs, or screenshots can recover and reuse the shared gateway credential outside ...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 29, 2026
Source: NVD