Total CVEs

139,939

Critical Severity

3,664

High Severity

13,195

Last 7 Days

1,711
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,621 - 7,640 of 12,892 CVEs
CVE-2026-4248 HIGH - 8.0

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[um_loggedin]' shortcode, which gen...

Published: Mar 27, 2026
Source: NVD
CVE-2026-33991 HIGH - 8.8

WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 and directly concatenates the `$id_tag` variable into SQL queries on lines 16-17 without prepared statements or sanitization. Version 3.6.7 p...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Mar 27, 2026
Source: NVD
CVE-2026-34204 HIGH - 7.1

MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-Minio-Replication-* he...

Vendor: go
Product: github.com/minio/minio
Published: Mar 27, 2026
Source: GitHub
CVE-2026-34172 HIGH - 8.8

Giskard is an open-source Python library for testing and evaluating agentic systems. Prior to versions 0.3.4 and 1.0.2b1, ChatWorkflow.chat(message) passes its string argument directly as a Jinja2 template source to a non-sandboxed Environment. A developer who passes user input to this method enable...

Vendor: pip
Product: giskard-agents
Published: Mar 27, 2026
Source: GitHub
CVE-2026-4990 HIGH - 7.3

A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the component Signup Endpoint. Such manipulation of the argument signupEnabled with the input true leads to improper authorization. The attack can be executed re...

Published: Mar 27, 2026
Source: NVD
CVE-2026-34226 HIGH - 7.5

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9 may attach cookies from the current page origin (`window.location`) instead of the request target URL when `fetch(..., { credentials: "include" })` is used. This can lea...

Vendor: capricorn86
Product: happy-dom
Published: Mar 27, 2026
Source: NVD
CVE-2026-33955 HIGH - 8.6

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when an attacker-controlled note header is displayed using ...

Vendor: streetwriters
Product: Notesnook Web/Desktop
Published: Mar 27, 2026
Source: NVD
CVE-2026-33953 HIGH - 8.5

LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP literals, but still performs server-side requests to internal-only resources when those resources are referenced through an internal hostname. This allows an authenticated user to t...

Vendor: Kovah
Product: LinkAce
Published: Mar 27, 2026
Source: NVD
CVE-2026-27309 HIGH - 7.8

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Substance3D - Stager
Published: Mar 27, 2026
Source: NVD
CVE-2019-25652 HIGH - 7.5

UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMT...

Vendor: Ubiquiti
Product: UniFi Network Controller
Published: Mar 27, 2026
Source: NVD
CVE-2019-25651 HIGH - 8.3

Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesse...

Vendor: Ubiquiti
Product: UniFi Network Controller, UniFi UAP Firmware, UniFi UAP-AC Firmware, UniFi USW Firmware, UniFi USG Firmware
Published: Mar 27, 2026
Source: NVD
CVE-2026-4976 HIGH - 8.8

A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack can be launched remotely. The exploit has been made public and cou...

Vendor: totolink
Product: lr350_firmware
Published: Mar 27, 2026
Source: NVD
CVE-2026-33874 HIGH - 7.8

Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authen...

Vendor: gematik
Product: app-Authenticator
Published: Mar 27, 2026
Source: NVD
CVE-2026-4975 HIGH - 8.8

A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been...

Vendor: tenda
Product: ac15_firmware
Published: Mar 27, 2026
Source: NVD
CVE-2026-4974 HIGH - 8.8

A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg of the component POST Request Handler. Executing a manipulation of the argument Time can lead to stack-based buffer overflow. It is possible to launch the attack re...

Vendor: tenda
Product: ac7_firmware
Published: Mar 27, 2026
Source: NVD
CVE-2026-34391 HIGH - 7.5

Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM commands intended for other devices, potentially exposing sensitive configuration data such as WiFi credentials, VPN secre...

Vendor: fleetdm
Product: fleet
Published: Mar 27, 2026
Source: NVD
CVE-2026-32241 HIGH - 7.5

Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extension backend that allows users to easily prototype new backend types. In versions of Flannel prior to 0.28.2, this Extension backend is vulnerable to a command injection that allow...

Vendor: flannel-io
Product: flannel
Published: Mar 27, 2026
Source: NVD
CVE-2026-31945 HIGH - 7.7

LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side request forgery (SSRF) attack when using agent actions or MCP. Although a previous SSRF vulnerability (https://github.com/danny-avila/LibreChat/security/advisories/GHSA-rgjq-4q58-m...

Vendor: danny-avila
Product: LibreChat
Published: Mar 27, 2026
Source: NVD
CVE-2026-31943 HIGH - 8.5

LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in their hex-normalized form, allowing any authenticated user to bypass SSRF protection and make the server issue HTTP reques...

Vendor: danny-avila
Product: LibreChat
Published: Mar 27, 2026
Source: NVD
CVE-2026-34076 HIGH - 7.4

Clerk JavaScript is the official JavaScript repository for Clerk authentication. In @clerk/hono from versions 0.1.0 to before 0.1.5, @clerk/express from versions 2.0.0 to before 2.0.7, @clerk/backend from versions 3.0.0 to before 3.2.3, and @clerk/fastify from versions 3.1.0 to before 3.1.5, the cle...

Vendor: npm
Product: @clerk/backend
Published: Mar 27, 2026
Source: GitHub