Total CVEs

139,939

Critical Severity

3,664

High Severity

13,195

Last 7 Days

1,642
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,701 - 7,720 of 12,892 CVEs
CVE-2026-33735 HIGH - 8.8

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to ...

Vendor: franklioxygen
Product: MyTube
Published: Mar 27, 2026
Source: NVD
CVE-2026-33725 HIGH - 7.2

Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1.54.22, 1.55.22, 1.56.22, 1.57.16, 1.58.10, and 1.59.4, authenticated admins on Metabase Enterprise Edition can achieve Remote Code Execution (RCE) and Arbitrary File Read via the ...

Vendor: metabase
Product: metabase
Published: Mar 27, 2026
Source: NVD
CVE-2026-4905 HIGH - 8.8

A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsOOB of the component POST Request Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. Remote exploitation of the attack is possible. The...

Vendor: tenda
Product: ac5_firmware
Published: Mar 27, 2026
Source: NVD
CVE-2026-4904 HIGH - 8.8

A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. Such manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has...

Vendor: tenda
Product: ac5_firmware
Published: Mar 27, 2026
Source: NVD
CVE-2026-33898 HIGH - 8.8

Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, ...

Vendor: lxc
Product: incus
Published: Mar 27, 2026
Source: NVD
CVE-2026-33697 HIGH - 7.5

Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulnerable to a relay attack affecting all versions from v0.4.0 through v0.8.2. This vulnerability is present in both the AMD SEV-SNP and Intel TDX deployment targets supported by CoCoS....

Vendor: ultravioletrs
Product: cocos
Published: Mar 27, 2026
Source: NVD
CVE-2026-28788 HIGH - 7.1

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.6, any authenticated user can overwrite any file's content by ID through the `POST /api/v1/retrieval/process/files/batch` endpoint. The endpoint performs no ownership check, s...

Vendor: open-webui
Product: open-webui
Published: Mar 27, 2026
Source: NVD
CVE-2026-27893 HIGH - 8.8

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the user's explicit `--trust-remote-code=False` security opt-...

Vendor: vllm-project
Product: vllm
Published: Mar 27, 2026
Source: NVD
CVE-2026-4903 HIGH - 8.8

A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. This manipulation of the argument PPPOEPassword causes stack-based buffer overflow. The attack may be initiated remotely. The e...

Vendor: tenda
Product: ac5_firmware
Published: Mar 26, 2026
Source: NVD
CVE-2026-4902 HIGH - 8.8

A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat of the file /goform/addressNat of the component POST Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now ...

Vendor: tenda
Product: ac5_firmware
Published: Mar 26, 2026
Source: NVD
CVE-2026-34352 HIGH - 8.5

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, because of incorrect permissions.

Vendor: TigerVNC
Product: TigerVNC
Published: Mar 26, 2026
Source: NVD
CVE-2026-33542 HIGH - 4.8

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker cont...

Vendor: lxc
Product: incus
Published: Mar 26, 2026
Source: NVD
CVE-2026-33943 HIGH - 8.8

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection vulnerability in `ECMAScriptModuleCompiler` allows an attacker to achieve Remote Code Execution (RCE) by injecting arbitrary JavaScript expressions ins...

Vendor: npm
Product: happy-dom
Published: Mar 26, 2026
Source: GitHub
CVE-2026-3650 HIGH - 7.5

A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously craft...

Published: Mar 26, 2026
Source: NVD
CVE-2026-33664 HIGH - 7.3

Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields โ€” description, inputs[].displayName, inputs[].description โ€” through the Markdown.vue component instantiated with html: true. The resulting HTML is injected ...

Vendor: kestra-io
Product: kestra
Published: Mar 26, 2026
Source: NVD
CVE-2026-28377 HIGH - 7.5

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability.

Vendor: Grafana
Product: Tempo
Published: Mar 26, 2026
Source: NVD
CVE-2025-12805 HIGH - 8.1

A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPolicy restricts access to the llama-stack service endpoint. As a result, a user in...

Vendor: Red Hat
Product: Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI)
Published: Mar 26, 2026
Source: NVD
CVE-2026-33906 HIGH - 7.2

Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents. A NetworkManager could replace the production database with a tampered ...

Vendor: go
Product: github.com/ellanetworks/core
Published: Mar 26, 2026
Source: GitHub
CVE-2026-33896 HIGH - 7.4

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` exte...

Vendor: npm
Product: node-forge
Published: Mar 26, 2026
Source: GitHub
CVE-2026-33895 HIGH - 7.5

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S +...

Vendor: npm
Product: node-forge
Published: Mar 26, 2026
Source: GitHub