Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,543
Quick preset (or use dates below)
Clear Filters
Showing 7,701 - 7,720 of 13,935 CVEs
CVE-2026-34206 MEDIUM - 6.1

Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes are detected from that subnet. Prior to version 1.12.2, a reflected cross-site scripting (XSS) vulnerability exists in github.com/libops/captcha-protect. The challenge page accepted...

Vendor: libops
Product: captcha-protect
Published: Mar 31, 2026
Source: NVD
CVE-2026-30280 MEDIUM - 5.3

An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

Vendor: rareprob
Product: video_player
Published: Mar 31, 2026
Source: NVD
CVE-2026-2950 MEDIUM - 6.5

Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check b...

Vendor: npm
Product: lodash
Published: Mar 31, 2026
Source: NVD
CVE-2026-30521 MEDIUM - 6.5

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific interest rates. While the frontend interface prevents users from entering negative numbers,...

Vendor: oretnom23
Product: loan_management_system
Published: Mar 31, 2026
Source: NVD
CVE-2026-5206 MEDIUM - 6.3

A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argument Payment_id/Amount/customer_id/payment_type/customer_name leads to sql injection. Remote exploitatio...

Published: Mar 31, 2026
Source: NVD
CVE-2026-33415 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from categories they were not ...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-33073 MEDIUM - 5.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the discourse-subscriptions plugin leaks stripe API keys across sites in a multisite cluster resulting in the potential for s...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-32951 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated user can obtain shared draft topic titles by sending an inline onebox request with a category_id parameter m...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-32618 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user search without authorization. This issue has been patched in ve...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-32273 MEDIUM - 5.4

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, updating a category description via API is not sanitizing the description string, which can lead to XSS attacks. This issue h...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-32243 MEDIUM - 6.1

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an attacker with the ability to create shared AI conversations could inject arbitrary HTML and JavaScript via crafted convers...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-32113 MEDIUM - 6.1

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the enter action in StaticController reads the sso_destination_url cookie and redirects to it with allow_other_host: true wit...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-30520 MEDIUM - 4.8

A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specifically the save_loan action). The application fails to properly sanitize user input supplied to the "borrower_id" parameter in a POST request, ...

Vendor: oretnom23
Product: loan_management_system
Published: Mar 31, 2026
Source: NVD
CVE-2026-5205 MEDIUM - 6.3

A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remote...

Published: Mar 31, 2026
Source: NVD
CVE-2026-24153 MEDIUM - 5.2

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.

Vendor: NVIDIA
Product: Jetson Xavier Series, Jetson Orin Series and Jetson Thor
Published: Mar 31, 2026
Source: NVD
CVE-2026-5203 MEDIUM - 4.7

A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserGuide Module XML Import. The manipulation results in path traversal. It is possible to launch the atta...

Published: Mar 31, 2026
Source: NVD
CVE-2026-4819 MEDIUM - 4.9

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

Vendor: search-guard
Product: flx
Published: Mar 31, 2026
Source: NVD
CVE-2026-4818 MEDIUM - 6.8

In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.

Vendor: search-guard
Product: flx
Published: Mar 31, 2026
Source: NVD
CVE-2026-34595 MEDIUM - 4.3

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields class-level permission setting on LiveQuery subscriptions. By sen...

Vendor: parse-community
Product: parse-server
Published: Mar 31, 2026
Source: NVD
CVE-2026-34574 MEDIUM - 5.4

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by sending a null value in a PUT request to the sess...

Vendor: parse-community
Product: parse-server
Published: Mar 31, 2026
Source: NVD