Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,501
Quick preset (or use dates below)
Clear Filters
Showing 7,901 - 7,920 of 13,945 CVEs
CVE-2026-33993 MEDIUM - 9.8

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function in `locutus/php/var/unserialize` assigns deserialized keys to plain objects via bracket notation without filtering the `__proto__` key. When a PHP seria...

Vendor: npm
Product: locutus
Published: Mar 27, 2026
Source: GitHub
CVE-2026-33997 MEDIUM - 6.8

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a p...

Vendor: go
Product: github.com/docker/docker
Published: Mar 27, 2026
Source: GitHub
CVE-2026-4964 MEDIUM - 6.3

A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_message_create_to_message of the file letta/helpers/message_helper.py of the component File URL Handler. Such manipulation of the argument ImageContent leads to server-side request f...

Published: Mar 27, 2026
Source: NVD
CVE-2026-4963 MEDIUM - 6.3

A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/local_python_executor.py of the component Incomplete Fix CVE-2025-9959. This manipulation causes code injection. It is possible to...

Published: Mar 27, 2026
Source: NVD
CVE-2026-34411 MEDIUM - 5.3

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata, license information, and unsalted SHA-256 hashes...

Vendor: Appsmith
Product: Appsmith
Published: Mar 27, 2026
Source: NVD
CVE-2026-34362 MEDIUM - 5.4

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This all...

Vendor: WWBN
Product: AVideo
Published: Mar 27, 2026
Source: NVD
CVE-2026-34247 MEDIUM - 5.4

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authenticated user to overwrite the poster image for any scheduled live stream by supplying an arbitrary `live_schedule_id`. The endpoint only checks `User::isLo...

Vendor: WWBN
Product: AVideo
Published: Mar 27, 2026
Source: NVD
CVE-2026-34245 MEDIUM - 6.3

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming permission to create or modify broadcast schedules targeting any playlist on the platform, regardless...

Vendor: WWBN
Product: AVideo
Published: Mar 27, 2026
Source: NVD
CVE-2026-30571 MEDIUM - 6.1

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_category.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted ...

Vendor: ahsanriaz26gmailcom
Product: inventory_system
Published: Mar 27, 2026
Source: NVD
CVE-2026-30570 MEDIUM - 6.1

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_sales.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL

Vendor: ahsanriaz26gmailcom
Product: inventory_system
Published: Mar 27, 2026
Source: NVD
CVE-2026-30569 MEDIUM - 6.1

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_stock_availability.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arb...

Vendor: ahsanriaz26gmailcom
Product: inventory_system
Published: Mar 27, 2026
Source: NVD
CVE-2025-15616 MEDIUM - 6.7

Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow attackers to execute arbitrary commands through various components including logcollector configuration, maild SMTP server tags, and Kaspersky AR scri...

Vendor: Wazuh
Product: wazuh-agent, wazuh-manager
Published: Mar 27, 2026
Source: NVD
CVE-2025-15615 MEDIUM - 5.8

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack o...

Vendor: Wazuh
Product: wazuh-manager
Published: Mar 27, 2026
Source: NVD
CVE-2026-32983 MEDIUM - 5.8

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack o...

Vendor: Wazuh
Product: wazuh-manager
Published: Mar 27, 2026
Source: NVD
CVE-2026-30527 MEDIUM - 5.4

A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within the admin panel. The application fails to properly sanitize user input supplied to the "Category Name" field when creating or updating a cate...

Vendor: oretnom23
Product: online_food_ordering_system
Published: Mar 27, 2026
Source: NVD
CVE-2026-33936 MEDIUM - 5.3

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Prior to version 0.19.2, an issue in the low-...

Vendor: pip
Product: ecdsa
Published: Mar 27, 2026
Source: GitHub
CVE-2026-5025 MEDIUM - 6.5

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active_user') without any privilege checks (e.g., 'is_superuser').

Published: Mar 27, 2026
Source: NVD
CVE-2026-4980 MEDIUM - 6.3

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.

Published: Mar 27, 2026
Source: NVD
CVE-2026-4954 MEDIUM - 6.3

A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has...

Published: Mar 27, 2026
Source: NVD
CVE-2026-33433 MEDIUM - 8.8

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField` is configured with a non-canonical HTTP header name (e.g., `x-auth-user` instead of `X-Auth-User`), an authenticated attacker can inject their own canonical version of that heade...

Vendor: traefik
Product: traefik
Published: Mar 27, 2026
Source: NVD