Total CVEs

139,939

Critical Severity

3,664

High Severity

13,195

Last 7 Days

1,674
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,681 - 7,700 of 12,892 CVEs
CVE-2026-29871 HIGH - 7.5

A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19) in the Beifong AI News and Podcast Agent backend in FastAPI backend, stream-audio endpoint, in file routers/podcast_router.py, in function stream_audio. The stream-au...

Vendor: theunwindai
Product: awesome_llm_apps
Published: Mar 27, 2026
Source: NVD
CVE-2026-27880 HIGH - 7.5

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

Vendor: Grafana
Product: Grafana
Published: Mar 27, 2026
Source: NVD
CVE-2025-69986 HIGH - 7.2

A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application fails to validate the length of the Protocol parameter inside the Transport element. By sending a specially crafted SOAP request containing an oversized protocol string, an attacke...

Published: Mar 27, 2026
Source: NVD
CVE-2026-25099 HIGH - 8.8

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.

Vendor: Bludit
Product: Bludit
Published: Mar 27, 2026
Source: NVD
CVE-2026-27858 HIGH - 7.5

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicl...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2026-27856 HIGH - 7.4

Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm http service port, in...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2026-24031 HIGH - 7.7

Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No publicly available exploits...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2025-59032 HIGH - 7.5

ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively upgrade to a fixed ...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2026-33280 HIGH - 7.2

Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.

Vendor: BUFFALO INC.
Product: BUFFALO Wi-Fi router products
Published: Mar 27, 2026
Source: NVD
CVE-2026-32678 HIGH - 7.5

Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings without authentication.

Vendor: BUFFALO INC.
Product: BUFFALO Wi-Fi router products
Published: Mar 27, 2026
Source: NVD
CVE-2026-32669 HIGH - 8.8

Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products.

Vendor: BUFFALO INC.
Product: BUFFALO Wi-Fi router products
Published: Mar 27, 2026
Source: NVD
CVE-2026-27650 HIGH - 8.8

OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.

Vendor: BUFFALO INC.
Product: BUFFALO Wi-Fi router products
Published: Mar 27, 2026
Source: NVD
CVE-2026-22744 HIGH - 7.5

In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value for a TAG field, stringValue() inserts the value directly into the @field:{VALUE} RediSearch TAG block without escaping characters.This issue affects Spring AI: from 1.0.0 before 1.0...

Vendor: Spring
Product: Spring AI
Published: Mar 27, 2026
Source: NVD
CVE-2026-22743 HIGH - 7.5

Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. When a user-controlled string is passed as a filter expression key in Neo4jVectorFilterExpressionConverter of spring-ai-neo4j-store, doKey() embeds the key into a backtick-delimi...

Vendor: Spring
Product: Spring AI
Published: Mar 27, 2026
Source: NVD
CVE-2026-22742 HIGH - 8.6

Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requ...

Vendor: Spring
Product: Spring AI
Published: Mar 27, 2026
Source: NVD
CVE-2026-4910 HIGH - 7.3

A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an unknown function of the file /RemoteFormat.do of the component Endpoint. Such manipulation of the argument State leads to sql injection. It is possible to launch the attack remotely...

Published: Mar 27, 2026
Source: NVD
CVE-2026-4908 HIGH - 7.3

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /modstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in sql injection. The attack may be performed from remote. The exploit ha...

Vendor: code-projects
Product: simple_laundry_system
Published: Mar 27, 2026
Source: NVD
CVE-2026-4906 HIGH - 8.8

A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remot...

Vendor: tenda
Product: ac5_firmware
Published: Mar 27, 2026
Source: NVD
CVE-2026-33935 HIGH - 7.5

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated attacker can lock out administrator and visitor accounts from password-based authentication by triggering failed login attempts. The application exposes three password verification en...

Vendor: franklioxygen
Product: MyTube
Published: Mar 27, 2026
Source: NVD
CVE-2026-33745 HIGH - 7.4

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Token, and Digest Auth credentials to arbitrary hosts when following cross-origin HTTP redirects (301/302/307/308). A malicious or comprom...

Vendor: yhirose
Product: cpp-httplib
Published: Mar 27, 2026
Source: NVD