Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,498
Quick preset (or use dates below)
Clear Filters
Showing 7,921 - 7,940 of 13,945 CVEs
CVE-2026-33206 MEDIUM - 6.3

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based files allowing an attacker to include arbitrary files from t...

Vendor: kovidgoyal
Product: calibre
Published: Mar 27, 2026
Source: NVD
CVE-2026-33205 MEDIUM - 5.5

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbit...

Vendor: kovidgoyal
Product: calibre
Published: Mar 27, 2026
Source: NVD
CVE-2026-28375 MEDIUM - 6.5

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

Vendor: Grafana
Product: Grafana
Published: Mar 27, 2026
Source: NVD
CVE-2026-27879 MEDIUM - 6.5

A resample query can be used to trigger out-of-memory crashes in Grafana.

Vendor: Grafana
Product: Grafana
Published: Mar 27, 2026
Source: NVD
CVE-2026-27877 MEDIUM - 6.5

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improv...

Vendor: Grafana
Product: Grafana
Published: Mar 27, 2026
Source: NVD
CVE-2025-69988 MEDIUM - 6.5

BS Producten Petcam 33.1.0.0818 is vulnerable to Incorrect Access Control. An unauthenticated attacker in physical proximity can associate with this open network. Once connected, the attacker gains access to the camera's private network interface and can retrieve sensitive information, includin...

Published: Mar 27, 2026
Source: NVD
CVE-2025-61190 MEDIUM - 6.1

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover filtering functionality. The vulnerability exists due to improper sanitization of user-supplied input via the filter_type_1 parameter.

Vendor: lyrasis
Product: dspace
Published: Mar 27, 2026
Source: NVD
CVE-2026-32859 MEDIUM - 5.4

ByteDance Deer-Flow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts API that allows attackers to execute arbitrary scripts by uploading malicious HTML or script content as artifacts. Attackers can store malicious content that executes in the brow...

Vendor: Bytedance Inc.
Product: DeerFlow
Published: Mar 27, 2026
Source: NVD
CVE-2026-32695 MEDIUM - 7.7

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider builds router rules by interpolating user-controlled values into backtick-delimited rule expressions without escaping. In live cluster validation, Knative `rules[].hosts[]` wa...

Vendor: traefik
Product: traefik
Published: Mar 27, 2026
Source: NVD
CVE-2026-25100 MEDIUM - 5.4

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges (such as Author, Editor, or Administrator) can upload an SVG file containing a malicious payload, which is executed when a victim visits the URL of th...

Vendor: Bludit
Product: Bludit
Published: Mar 27, 2026
Source: NVD
CVE-2023-7339 MEDIUM - 6.5

Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers. This issue affects pnGate: through 1.30 epGate: through 1.30 mbGate: through 1.30 smartLink HW-DP: through 1.30 smartLink HW-PN: through 1.01.

Published: Mar 27, 2026
Source: NVD
CVE-2026-27859 MEDIUM - 5.3

A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. Use MTA capabilities to limit RFC 2231 MIME parameters in mail messages, or upgrade to fixed ve...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2026-27857 MEDIUM - 4.3

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnection. This 1 MB can be left allocated for longer time periods by not sending the command ending LF. So attacker could connect possibly from e...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2026-27855 MEDIUM - 6.8

Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and username is altered in passdb, then OTP credentials can be cached so that same OTP reply is valid. An attacker able to observe an OTP exchange is able to log in as the user. If authenti...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2026-0394 MEDIUM - 5.3

When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading /etc/passwd (or some other path...

Published: Mar 27, 2026
Source: NVD
CVE-2025-59031 MEDIUM - 4.3

Dovecot has provided a script to use for attachment to text conversion. This script unsafely handles zip-style attachments. Attacker can use specially crafted OOXML documents to cause unintended files on the system to be indexed and subsequently ending up in FTS indexes. Do not use the provided scri...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2025-59028 MEDIUM - 5.3

When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in login processes (heavy...

Vendor: Open-Xchange GmbH
Product: OX Dovecot Pro
Published: Mar 27, 2026
Source: NVD
CVE-2026-4948 MEDIUM - 5.5

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leadi...

Published: Mar 27, 2026
Source: NVD
CVE-2026-34353 MEDIUM - 5.9

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.

Vendor: OCaml
Product: OCaml
Published: Mar 27, 2026
Source: NVD
CVE-2026-33559 MEDIUM - 5.4

WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the affected version of the plugin enabled, a logged-in user with a page-creating/editing privilege can embed some malicious script with a crafted HTTP request. When a victim u...

Vendor: MiKa
Product: OpenStreetMap
Published: Mar 27, 2026
Source: NVD