Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,818
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,301 - 8,320 of 13,041 CVEs
CVE-2026-22739 HIGH - 8.6

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3....

Vendor: Spring
Product: Spring Cloud
Published: Mar 24, 2026
Source: NVD
CVE-2026-4615 HIGH - 7.3

A vulnerability was identified in SourceCodester Online Catering Reservation 1.0. Impacted is an unknown function of the file /search.php. Such manipulation of the argument rcode leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

Published: Mar 24, 2026
Source: NVD
CVE-2026-4613 HIGH - 7.3

A vulnerability was found in SourceCodester E-Commerce Site 1.0. This vulnerability affects unknown code of the file /products.php. The manipulation of the argument Search results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

Published: Mar 24, 2026
Source: NVD
CVE-2026-4021 HIGH - 8.1

The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email s...

Published: Mar 24, 2026
Source: NVD
CVE-2026-3533 HIGH - 8.8

The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_popup_templates() function as well as insufficient file type validation in the upload_files() function in all versions up to, and including, 4.14.1. This makes it possible for Authent...

Published: Mar 24, 2026
Source: NVD
CVE-2026-33250 HIGH - 7.5

Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specially-crafted packets. A remote attacker can use this to take down any public server. A malicious server can use this to crash the game on the player...

Vendor: longturn
Product: freeciv21
Published: Mar 24, 2026
Source: NVD
CVE-2026-4306 HIGH - 7.5

The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, and including, 2.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for ...

Published: Mar 23, 2026
Source: NVD
CVE-2026-33046 HIGH - 8.8

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to vulnerabilities in TeXLive and obscure LaTeX syntax that allowed circumventing Indico's LaTeX sanitizer, it is possible to use specially-crafted L...

Vendor: indico
Product: indico
Published: Mar 23, 2026
Source: NVD
CVE-2026-4612 HIGH - 7.3

A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the file /hotel/admin/mod_users/index.php?view=edit&id=8 of the component Parameter Handler. The manipulation of the argument account_id leads to sql injection. Remote exploitation o...

Published: Mar 23, 2026
Source: NVD
CVE-2026-4611 HIGH - 7.2

A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely.

Published: Mar 23, 2026
Source: NVD
CVE-2026-32300 HIGH - 8.1

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the My Page profile update feature may allow modification of arbitrary user information. Versions 1.41.1 ...

Vendor: opensource-workshop
Product: connect-cms
Published: Mar 23, 2026
Source: NVD
CVE-2026-32299 HIGH - 7.5

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an improper authorization issue in the page content retrieval feature may allow retrieval of non-public information. Versions 1.41.1 and 2.4...

Vendor: opensource-workshop
Product: connect-cms
Published: Mar 23, 2026
Source: NVD
CVE-2026-32278 HIGH - 8.2

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Versions 1.41.1 and 2.41.1 contain a patch.

Vendor: opensource-workshop
Product: connect-cms
Published: Mar 23, 2026
Source: NVD
CVE-2026-32277 HIGH - 8.7

Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch.

Vendor: opensource-workshop
Product: connect-cms
Published: Mar 23, 2026
Source: NVD
CVE-2026-32276 HIGH - 8.8

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated user may be able to execute arbitrary code in the Code Study Plugin. Versions 1.41.1 and 2.41.1 contain a patch.

Vendor: opensource-workshop
Product: connect-cms
Published: Mar 23, 2026
Source: NVD
CVE-2025-60947 HIGH - 8.8

Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibly leading to remote code execution. Fixed in 8.1.0 alpha.

Vendor: Census
Product: CSWeb
Published: Mar 23, 2026
Source: NVD
CVE-2025-60946 HIGH - 8.8

Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file directories. Fixed in 8.1.0 alpha.

Vendor: Census
Product: CSWeb
Published: Mar 23, 2026
Source: NVD
CVE-2026-33430 HIGH - 7.3

Briefcase is a tool for converting a Python project into a standalone native application. Starting in version 0.3.0 and prior to version 0.3.26, if a developer uses Briefcase to produce an Windows MSI installer for a project, and that project is installed for All Users (i.e., per-machine scope), the...

Vendor: pip
Product: briefcase
Published: Mar 23, 2026
Source: GitHub
CVE-2026-33195 HIGH - 9.8

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing pat...

Vendor: rubygems
Product: activestorage
Published: Mar 23, 2026
Source: GitHub
CVE-2026-23882 HIGH - 7.2

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying arbitrary commands and arguments, which are executed when testing the connection. This issue has been patched in version 1.8.4.

Vendor: blinkospace
Product: blinko
Published: Mar 23, 2026
Source: NVD