Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,490
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,681 - 7,700 of 13,564 CVEs
CVE-2026-34539 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile and TIFF input can trigger a heap-buffer-overflow (HBO) in CTiffImg::WriteLine(). The issue is observable under AddressSanitizer as an out-of-bounds heap read ...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34537 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger Undefined Behavior (UB) in CIccOpDefEnvVar::Exec() due to invalid enum values being loaded for icSigCmmEnvVar. The issue is observable under UBSan ...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34536 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a stack overflow (SO) in SIccCalcOp::ArgsUsed(). The issue is observable under AddressSanitizer as a stack-overflow when iccApplyProfiles processes...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34535 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a segmentation fault (SEGV) in CIccTagArray::Cleanup(). The issue is observable under UBSan/ASan as misaligned member access / misaligned pointer l...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34534 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger a heap-buffer-overflow (HBO) in CIccMpeSpectralMatrix::Describe(). The issue is observable under AddressSanitizer as an out-of-bounds heap read whe...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD
CVE-2026-34533 MEDIUM - 6.2

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, a crafted ICC profile can trigger Undefined Behavior (UB) in CIccCalculatorFunc::ApplySequence() due to invalid enum values being loaded for icChannelFuncSignature. The issue is obs...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 31, 2026
Source: NVD

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the async local filesystem memory tool in the Anthropic Python SDK validated that model-supplied paths resolved inside the sandboxed memory directory, but then returned...

Vendor: anthropics
Product: anthropic-sdk-python
Published: Mar 31, 2026
Source: NVD

Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated model-supplied paths using a string prefix check that did not a...

Vendor: anthropics
Product: anthropic-sdk-typescript
Published: Mar 31, 2026
Source: NVD

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the local filesystem memory tool in the Anthropic Python SDK created memory files with mode 0o666, leaving them world-readable on systems with a standard umask and worl...

Vendor: anthropics
Product: anthropic-sdk-python
Published: Mar 31, 2026
Source: NVD
CVE-2026-34442 MEDIUM - 5.4

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This leads to External ...

Vendor: freescout-help-desk
Product: freescout
Published: Mar 31, 2026
Source: NVD
CVE-2026-34441 MEDIUM - 4.8

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib is vulnerable to HTTP Request Smuggling. The server's static file handler serves GET responses without consuming the request body. On HTTP/1.1 keep-alive connections, the unrea...

Vendor: yhirose
Product: cpp-httplib
Published: Mar 31, 2026
Source: NVD
CVE-2026-34405 MEDIUM - 6.1

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a vulnerability that allows injection of arbitrary attributes into the HTML page body. This issue has been patched in...

Vendor: nuxt-modules
Product: og-image
Published: Mar 31, 2026
Source: NVD

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in older versions, /og-image/) contains a Denial of Service (DoS) vulnerability. The issue arises because there is no restriction on the width and height par...

Vendor: nuxt-modules
Product: og-image
Published: Mar 31, 2026
Source: NVD
CVE-2026-34401 MEDIUM - 6.5

XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. There is a well known attack related to...

Vendor: microsoft
Product: XmlNotepad
Published: Mar 31, 2026
Source: NVD
CVE-2026-3468 MEDIUM - 4.8

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.

Published: Mar 31, 2026
Source: NVD
CVE-2026-34740 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page visit. The URL is validated only with PHP's FI...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34739 MEDIUM - 6.1

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's testIP.php page reflects the ip request parameter directly into an HTML input element without applying htmlspecialchars() or any other output encoding. This allows an attacker to inject arbitrar...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34738 MEDIUM - 4.3

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "active" (a). This bypasses the admin-controlled...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34737 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads and triggers subscription operations, including c...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34733 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteSystemdPrivate.php contains a PHP operator precedence bug in its CLI-only access guard. The script is intended to run exclusively from the command line, but the guard condition !php...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD