Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,696
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,941 - 7,960 of 13,009 CVEs
CVE-2026-4824 HIGH - 7.0

A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Backup Job Configuration File Handler. The manipulation leads to improper privilege management. The attack must be carried out locally. The attack is con...

Published: Mar 25, 2026
Source: NVD
CVE-2026-33718 HIGH - 7.6

OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in the `get_git_diff()` method at `openhands/runtime/utils/git_handler.py:134`. The `path` parameter from the `/api/conversations/{conversation_id}/git/diff` API endpoint is passed un...

Vendor: pip
Product: openhands
Published: Mar 25, 2026
Source: GitHub
CVE-2026-4822 HIGH - 7.0

A vulnerability was detected in Enter Software Iperius Backup up to 8.7.3. Affected is an unknown function of the file C:\ProgramData\IperiusBackup\Jobs\ of the component Backup Service. Performing a manipulation results in creation of temporary file with insecure permissions. The attack is only pos...

Published: Mar 25, 2026
Source: NVD
CVE-2026-30976 HIGH - 8.6

Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr process. These include application configuration files (containing API keys and database credentials), Windows ...

Vendor: Sonarr
Product: Sonarr
Published: Mar 25, 2026
Source: NVD
CVE-2026-30975 HIGH - 8.1

Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authentication Required set to: `Disabled for Local Addresses`) without a reverse proxy running in front of Sonarr th...

Vendor: Sonarr
Product: Sonarr
Published: Mar 25, 2026
Source: NVD
CVE-2025-36258 HIGH - 7.1

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 product stores user credentials and other sensitive information in plain text which can be read by a local user.

Vendor: IBM
Product: InfoSphere Information Server
Published: Mar 25, 2026
Source: NVD
CVE-2026-33671 HIGH - 7.5

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlap...

Vendor: npm
Product: picomatch
Published: Mar 25, 2026
Source: GitHub
CVE-2026-33686 HIGH - 8.8

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil class. The application fails to sanitize file extensions properly, allowing path separators to be passed into the storage layer. In `src/Utils/FileUti...

Vendor: composer
Product: code16/sharp
Published: Mar 25, 2026
Source: GitHub
CVE-2026-33687 HIGH - 8.8

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint that allows authenticated users to bypass all file type restrictions. The upload endpoint within the `ApiFormUploadController` accepts a client-control...

Vendor: composer
Product: code16/sharp
Published: Mar 25, 2026
Source: GitHub
CVE-2026-33673 HIGH - 7.7

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, c...

Vendor: composer
Product: prestashop/prestashop
Published: Mar 25, 2026
Source: GitHub
CVE-2026-33661 HIGH - 8.6

Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `verify_wechat_sign()` function in `src/Functions.php` unconditionally skips all signature verification when the PSR-7 request reports `localhost` as the host. An attacker can explo...

Vendor: composer
Product: yansongda/pay
Published: Mar 25, 2026
Source: GitHub
CVE-2026-33722 HIGH - 6.3

n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without permission to list external secrets could reference a secret by the external name in a credential and retrieve its plaintext value when saving the credential. This bypassed the `ex...

Vendor: n8n-io
Product: n8n
Published: Mar 25, 2026
Source: NVD
CVE-2026-27602 HIGH - 7.2

Modoboa is a mail hosting and management platform. Prior to version 2.7.1, `exec_cmd()` in `modoboa/lib/sysutils.py` always runs subprocess calls with `shell=True`. Since domain names flow directly into shell command strings without any sanitization, a Reseller or SuperAdmin can include shell metach...

Vendor: modoboa
Product: modoboa
Published: Mar 25, 2026
Source: NVD
CVE-2025-70952 HIGH - 7.5

pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.

Vendor: pf4j_project
Product: pf4j
Published: Mar 25, 2026
Source: NVD
CVE-2025-70887 HIGH - 8.8

An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components

Vendor: ralphje
Product: signify
Published: Mar 25, 2026
Source: NVD
CVE-2026-33713 HIGH - 10.0

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could exploit a SQL injection vulnerability in the Data Table Get node. On default SQLite DB, single statements can be manipulated a...

Vendor: n8n-io
Product: n8n
Published: Mar 25, 2026
Source: NVD
CVE-2026-33665 HIGH - 8.2

n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is enabled, n8n automatically linked an LDAP identity to an existing local account if the LDAP email attribute matched the local account's email. An authenticated LDAP user who coul...

Vendor: n8n-io
Product: n8n
Published: Mar 25, 2026
Source: NVD
CVE-2026-33663 HIGH - 10.0

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` role could exploit chained authorization flaws in n8n's credential pipeline to steal plaintext secrets from generic HTTP credentials (`httpBasicAuth...

Vendor: n8n-io
Product: n8n
Published: Mar 25, 2026
Source: NVD
CVE-2026-27496 HIGH - 6.5

n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user with permission to create or modify workflows could use the JavaScript Task Runner to allocate uninitialized memory buffers. Uninitialized buffers may contain residual data from t...

Vendor: n8n-io
Product: n8n
Published: Mar 25, 2026
Source: NVD
CVE-2025-67030 HIGH - 8.8

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

Vendor: codehaus-plexus
Product: plexus-utils
Published: Mar 25, 2026
Source: NVD