Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,701
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 7,921 - 7,940 of 13,009 CVEs
CVE-2026-4329 HIGH - 7.2

The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() when capturing bot data (whic...

Published: Mar 26, 2026
Source: NVD
CVE-2026-2931 HIGH - 8.8

The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authe...

Published: Mar 26, 2026
Source: NVD
CVE-2026-4839 HIGH - 7.3

A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file /purchase.php of the component Parameter Handler. The manipulation of the argument custom leads to sql injection. The attack can be initiated remotely. The exploit has been disclos...

Published: Mar 26, 2026
Source: NVD
CVE-2026-4838 HIGH - 7.3

A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the file /display.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used....

Published: Mar 26, 2026
Source: NVD
CVE-2026-3328 HIGH - 7.2

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31. This is due to the use of WordPress's `maybe_unserialize()` function without class r...

Published: Mar 26, 2026
Source: NVD
CVE-2025-15101 HIGH - 8.8

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Web management interface of certain ASUS router models. This vulnerability potentially allows actions to be performed with the existing privileges of an authenticated user on the affected device, including the ability to ex...

Vendor: ASUS
Product: Router
Published: Mar 26, 2026
Source: NVD
CVE-2026-33526 HIGH - 7.5

Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol...

Vendor: squid-cache
Product: squid
Published: Mar 26, 2026
Source: NVD
CVE-2026-32748 HIGH - 7.5

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denia...

Vendor: squid-cache
Product: squid
Published: Mar 26, 2026
Source: NVD
CVE-2026-4758 HIGH - 8.8

The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up to, and including, 2.4.9. This makes it possible for authenticated attackers, with Subscri...

Published: Mar 26, 2026
Source: NVD
CVE-2026-34056 HIGH - 7.7

OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including version 8.0.0.3 allows low-privilege users to view and download Ensora eRx error logs without proper authorization checks. Thi...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-34055 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` without verifying that the note belongs to a patient the ...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-34053 HIGH - 7.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint `interface/forms/procedure_order/handle_deletions.php` allows any authenticated user, regardless of role, to irrevers...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33932 HIGH - 7.6

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CCDA document to execute arbitrary JavaScript in a c...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33918 HIGH - 7.6

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid session and CSRF token, but does not check any ACL pe...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33917 HIGH - 8.8

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input va...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33914 HIGH - 7.2

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the PostCalendar module contains a blind SQL injection vulnerability in the `categoriesUpdate` administrative function. The `dels` POST parameter is read via `pnVarClean...

Vendor: openemr
Product: openemr
Published: Mar 26, 2026
Source: NVD
CVE-2026-33913 HIGH - 7.7

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated user with access to the Carecoordination module can upload a crafted CCDA document containing `<xi:include href="file:///etc/passwd" parse=...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD
CVE-2026-33910 HIGH - 7.2

OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that can be exploited by authenticated attackers. The vulnerability exists due to insuf...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD
CVE-2026-33348 HIGH - 8.7

OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form are displayed on the encounter page and in the visit history for the users with ...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD
CVE-2026-29187 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulnerability exists in the Patient Search functionality (/interface/new/new_search_popup.php). The vulnerability allows an authenticated attacker ...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD