Total CVEs

140,279

Critical Severity

3,710

High Severity

13,344

Last 7 Days

1,816
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 8,201 - 8,220 of 13,041 CVEs
CVE-2025-33254 HIGH - 7.5

NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause internal state corruption. A successful exploit of this vulnerability may lead to a denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: Mar 24, 2026
Source: NVD
CVE-2025-33248 HIGH - 7.8

NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data ta...

Vendor: NVIDIA
Product: Megatron LM
Published: Mar 24, 2026
Source: NVD
CVE-2025-33247 HIGH - 7.8

NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: Megatron LM
Published: Mar 24, 2026
Source: NVD
CVE-2025-33238 HIGH - 7.5

NVIDIA Triton Inference Server Sagemaker HTTP server contains a vulnerability where an attacker may cause an exception. A successful exploit of this vulnerability may lead to denial of service.

Vendor: NVIDIA
Product: Triton Inference Server
Published: Mar 24, 2026
Source: NVD
CVE-2026-33247 HIGH - 7.4

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any user who can see the m...

Vendor: go
Product: github.com/nats-io/nats-server/v2
Published: Mar 24, 2026
Source: GitHub
CVE-2026-33330 HIGH - 7.1

FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integration allows an authenticated user with read-only access to obtain a signed save callbackUrl for a file and then directly forge the ONLYOFFICE save c...

Vendor: error311
Product: FileRise
Published: Mar 24, 2026
Source: NVD
CVE-2026-33329 HIGH - 8.1

FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableIdentifier parameter in the Resumable.js chunked upload handler (UploadModel::handleUpload()) is concatenated directly into filesystem paths without any sanitization. An authenticate...

Vendor: error311
Product: FileRise
Published: Mar 24, 2026
Source: NVD
CVE-2026-22559 HIGH - 8.8

An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the account owner is socially engineered into clicking a malicious link. Affected Products: UniFi Network Server (Version 10.1.85 and earlier) Mitigation: Update UniFi Netwo...

Vendor: Ubiquiti Inc
Product: UniFi Network Server
Published: Mar 24, 2026
Source: NVD
CVE-2026-33627 HIGH - 6.5

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, an authenticated user calling GET /users/me receives unsanitized auth data, including sensitive credentials such as MFA TOTP secrets and recovery codes...

Vendor: parse-community
Product: parse-server
Published: Mar 24, 2026
Source: NVD
CVE-2026-33539 HIGH - 7.2

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.59 and 9.6.0-alpha.53, an attacker with master key access can execute arbitrary SQL statements on the PostgreSQL database by injecting SQL metacharacters into field name para...

Vendor: parse-community
Product: parse-server
Published: Mar 24, 2026
Source: NVD
CVE-2026-33538 HIGH - 7.5

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.58 and 9.6.0-alpha.52, an unauthenticated attacker can cause denial of service by sending authentication requests with arbitrary, unconfigured provider names. The server exec...

Vendor: parse-community
Product: parse-server
Published: Mar 24, 2026
Source: NVD
CVE-2026-30932 HIGH - 8.8

Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file direc...

Vendor: froxlor
Product: froxlor
Published: Mar 24, 2026
Source: NVD
CVE-2026-1995 HIGH - 7.8

IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any standard user logged into the syst...

Published: Mar 24, 2026
Source: NVD
CVE-2026-33399 HIGH - 7.7

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-30839 and CVE-2026-30840 is incomplete. The validate_webhook_url_for_ssrf() protection was added to the test* notification endpoints but not to the corres...

Vendor: ellite
Product: Wallos
Published: Mar 24, 2026
Source: NVD
CVE-2026-33157 HIGH - 7.2

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated user with control panel access. This is a bypass of a previous fix. The existing patches add cleanseC...

Vendor: craftcms
Product: cms
Published: Mar 24, 2026
Source: NVD
CVE-2026-32854 HIGH - 7.5

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of service by sending specially crafted HTTP requests. Attackers can exploit...

Vendor: LibVNC
Product: LibVNCServer
Published: Mar 24, 2026
Source: NVD
CVE-2026-32853 HIGH - 8.1

LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a malicious VNC server to cause information disclosure or application crash. Attackers can exploit improper bounds checking in the HandleUltra...

Vendor: LibVNC
Product: LibVNCServer
Published: Mar 24, 2026
Source: NVD
CVE-2026-33680 HIGH - 7.5

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` method allows link share authenticated users to list all link shares for a project, including their secret hashes. While `LinkSharing.CanRead()` correctly blocks link share users from ...

Vendor: go-vikunja
Product: vikunja
Published: Mar 24, 2026
Source: NVD
CVE-2026-33678 HIGH - 8.1

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queries attachments by ID only (`WHERE id = ?`), ignoring the task ID from the URL path. The permission check in `CanRead()` validates access to the task specified in the URL, but `Read...

Vendor: go-vikunja
Product: vikunja
Published: Mar 24, 2026
Source: NVD
CVE-2026-33668 HIGH - 8.1

Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, when a user account is disabled or locked, the status check is only enforced on the local login and JWT token refresh paths. Three other authentication paths — API tokens, CalDAV ba...

Vendor: go-vikunja
Product: vikunja
Published: Mar 24, 2026
Source: NVD