Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,230
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,561 - 7,580 of 12,781 CVEs
CVE-2026-30529 HIGH - 8.8

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker to inject m...

Vendor: oretnom23
Product: online_food_ordering_system
Published: Mar 27, 2026
Source: NVD
CVE-2026-5027 HIGH - 8.8

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

Published: Mar 27, 2026
Source: NVD
CVE-2026-4984 HIGH - 8.2

The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' parameters) using HTTP requests that include the integration's Twilio credenti...

Published: Mar 27, 2026
Source: NVD
CVE-2026-4956 HIGH - 7.3

A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown function of the file /DevicePrint.do?Action=ReadTask of the component Parameter Handler. The manipulation of the argument State results in sql injection. The attack can be launched ...

Published: Mar 27, 2026
Source: NVD
CVE-2026-4955 HIGH - 7.3

A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the file /OperateStatistic.do. The manipulation of the argument VehicleID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be ...

Published: Mar 27, 2026
Source: NVD
CVE-2026-4953 HIGH - 7.3

A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible to...

Published: Mar 27, 2026
Source: NVD
CVE-2026-33755 HIGH - 8.8

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in the JMAP `Contact/query` endpoint allows any authenticated user with basic addressbook access to extract arbitrary data ...

Vendor: Intermesh
Product: groupoffice
Published: Mar 27, 2026
Source: NVD
CVE-2026-30689 HIGH - 7.5

A blog.admin v.8.0 and before system's getinfobytoken API interface contains an improper access control which leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security.

Vendor: anjoy8
Product: blog.admin
Published: Mar 27, 2026
Source: NVD
CVE-2026-30637 HIGH - 7.5

Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before. The vulnerability allows remote attackers to craft HTTP requests, without authentication, containing a URL pointing to internal services or any remote server

Vendor: otcms
Product: otcms
Published: Mar 27, 2026
Source: NVD
CVE-2026-29871 HIGH - 7.5

A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19) in the Beifong AI News and Podcast Agent backend in FastAPI backend, stream-audio endpoint, in file routers/podcast_router.py, in function stream_audio. The stream-au...

Vendor: theunwindai
Product: awesome_llm_apps
Published: Mar 27, 2026
Source: NVD
CVE-2026-27880 HIGH - 7.5

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

Vendor: Grafana
Product: Grafana
Published: Mar 27, 2026
Source: NVD
CVE-2025-69986 HIGH - 7.2

A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application fails to validate the length of the Protocol parameter inside the Transport element. By sending a specially crafted SOAP request containing an oversized protocol string, an attacke...

Published: Mar 27, 2026
Source: NVD
CVE-2026-25099 HIGH - 8.8

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.

Vendor: Bludit
Product: Bludit
Published: Mar 27, 2026
Source: NVD
CVE-2026-27858 HIGH - 7.5

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicl...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2026-27856 HIGH - 7.4

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, in...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2026-24031 HIGH - 7.7

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2025-59032 HIGH - 7.5

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed ...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2026-33280 HIGH - 7.2

Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.

Vendor: BUFFALO INC.
Product: BUFFALO Wi-Fi router products
Published: Mar 27, 2026
Source: NVD
CVE-2026-32678 HIGH - 7.5

Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings without authentication.

Vendor: BUFFALO INC.
Product: BUFFALO Wi-Fi router products
Published: Mar 27, 2026
Source: NVD
CVE-2026-32669 HIGH - 8.8

Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products.

Vendor: BUFFALO INC.
Product: BUFFALO Wi-Fi router products
Published: Mar 27, 2026
Source: NVD