Total CVEs

140,426

Critical Severity

3,747

High Severity

13,550

Last 7 Days

1,488
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,721 - 7,740 of 13,565 CVEs
CVE-2026-32273 MEDIUM - 5.4

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, updating a category description via API is not sanitizing the description string, which can lead to XSS attacks. This issue h...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-32243 MEDIUM - 6.1

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an attacker with the ability to create shared AI conversations could inject arbitrary HTML and JavaScript via crafted convers...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-32113 MEDIUM - 6.1

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the enter action in StaticController reads the sso_destination_url cookie and redirects to it with allow_other_host: true wit...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-30520 MEDIUM - 4.8

A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specifically the save_loan action). The application fails to properly sanitize user input supplied to the "borrower_id" parameter in a POST request, ...

Vendor: oretnom23
Product: loan_management_system
Published: Mar 31, 2026
Source: NVD
CVE-2026-5205 MEDIUM - 6.3

A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remote...

Published: Mar 31, 2026
Source: NVD
CVE-2026-24153 MEDIUM - 5.2

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.

Vendor: NVIDIA
Product: Jetson Xavier Series, Jetson Orin Series and Jetson Thor
Published: Mar 31, 2026
Source: NVD
CVE-2026-5203 MEDIUM - 4.7

A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserGuide Module XML Import. The manipulation results in path traversal. It is possible to launch the atta...

Published: Mar 31, 2026
Source: NVD
CVE-2026-4819 MEDIUM - 4.9

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

Vendor: search-guard
Product: flx
Published: Mar 31, 2026
Source: NVD
CVE-2026-4818 MEDIUM - 6.8

In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.

Vendor: search-guard
Product: flx
Published: Mar 31, 2026
Source: NVD
CVE-2026-34595 MEDIUM - 4.3

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields class-level permission setting on LiveQuery subscriptions. By sen...

Vendor: parse-community
Product: parse-server
Published: Mar 31, 2026
Source: NVD
CVE-2026-34574 MEDIUM - 5.4

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by sending a null value in a PUT request to the sess...

Vendor: parse-community
Product: parse-server
Published: Mar 31, 2026
Source: NVD
CVE-2026-34227 MEDIUM - 8.8

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH ...

Vendor: BishopFox
Product: sliver
Published: Mar 31, 2026
Source: NVD
CVE-2026-34218 MEDIUM - 5.5

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during which only the single compile-time baseline rule was enforced by opfilter. All managed (MDM-delivered) and user-defined fi...

Vendor: craigjbass
Product: clearancekit
Published: Mar 31, 2026
Source: NVD
CVE-2026-22569 MEDIUM - 5.4

An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.

Vendor: Zscaler
Product: Zscaler Client Connector
Published: Mar 31, 2026
Source: NVD
CVE-2026-4799 MEDIUM - 4.3

In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.

Vendor: search-guard
Product: flx
Published: Mar 31, 2026
Source: NVD
CVE-2026-33581 MEDIUM - 6.5

OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using mediaUrl and fileUrl alias parameters that bypass localRoots validation. Remote attackers can exploit this by routing file requests through unvalidated a...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 31, 2026
Source: NVD
CVE-2026-33580 MEDIUM - 6.5

OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication that allows attackers to brute-force weak shared secrets. Attackers who can reach the webhook endpoint can exploit this to forge inbound webhook events by repeatedly attempting authe...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 31, 2026
Source: NVD
CVE-2026-33578 MEDIUM - 4.3

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution flaw to bypass sender restrictions and interact with bots desp...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 31, 2026
Source: NVD
CVE-2026-33576 MEDIUM - 6.5

OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subsequently rejected.

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 31, 2026
Source: NVD
CVE-2026-33276 MEDIUM - 5.4

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Unified Search feature.

Vendor: Checkmk GmbH
Product: Checkmk
Published: Mar 31, 2026
Source: NVD