Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,811
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 8,401 - 8,420 of 13,041 CVEs
CVE-2026-1800 HIGH - 7.5

The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedFnt’ parameter in all versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. T...

Published: Mar 21, 2026
Source: NVD
CVE-2026-1648 HIGH - 7.2

The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it...

Published: Mar 21, 2026
Source: NVD
CVE-2026-1313 HIGH - 8.3

The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plugin making outbound HTTP requests to user-controlled URLs without proper validation when the "Show file size" option is enabled. Th...

Published: Mar 21, 2026
Source: NVD
CVE-2025-14037 HIGH - 8.1

The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1.2.6. This is due to missing validation and sanitization in the 'createManageFeedPage' function. This makes it possible for authenticated admin...

Vendor: invelity
Product: Invelity Product Feeds
Published: Mar 21, 2026
Source: NVD
CVE-2026-4302 HIGH - 7.2

The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. This is due to the plugin exposing a publicly accessible REST API endpoint (optn/v1/integration-action) with a permission_callback of __return_true that ...

Published: Mar 21, 2026
Source: NVD
CVE-2026-32064 HIGH - 7.7

OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with ...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 21, 2026
Source: NVD
CVE-2026-32056 HIGH - 7.5

OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attackers to bypass command allowlist protections. Remote attackers can inject malicious startup files such as .bash_profile or .zshenv to achieve arbitrary...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 21, 2026
Source: NVD
CVE-2026-32055 HIGH - 7.6

OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files outside the workspace through in-workspace symlinks pointing to non-existent out-of-root targets. The vulnerability exists because the boundary check impr...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 21, 2026
Source: NVD
CVE-2026-32051 HIGH - 8.8

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform ...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 21, 2026
Source: NVD
CVE-2026-32049 HIGH - 7.5

OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple channel ingestion paths. Remote attackers can send oversized media payloads to trigger elevated memory usage and potential process instability.

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 21, 2026
Source: NVD
CVE-2026-32048 HIGH - 7.5

OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to create child processes under unsandboxed agents. An attacker with a sandboxed session can exploit this to spawn child runtimes with sandbox.mode set to...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 21, 2026
Source: NVD
CVE-2026-32042 HIGH - 8.8

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including operator.admin. Attackers with valid shared gateway authentication can present a ...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 21, 2026
Source: NVD
CVE-2026-3368 HIGH - 7.2

The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter names in all versions up to and including 1.2.9. This is due to insufficient input sanitization in the sanitize_ig_data() function which only sanitizes array values but not array keys,...

Published: Mar 21, 2026
Source: NVD
CVE-2026-33427 HIGH - 7.5

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthenticated attacker can cause a legitimate Discourse authorization page to display an attacker-controlled domain, facilitating social engineering attacks against users. Versions 2026...

Vendor: discourse
Product: discourse
Published: Mar 21, 2026
Source: NVD
CVE-2026-32666 HIGH - 7.5

WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated Auto...

Vendor: Automated Logic
Product: WebCTRL Premium Server
Published: Mar 21, 2026
Source: NVD
CVE-2026-25086 HIGH - 7.7

Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requiring code injection into the WebCTRL software.

Vendor: Automated Logic
Product: WebCTRL Premium Server
Published: Mar 21, 2026
Source: NVD
CVE-2026-4508 HIGH - 7.3

A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The...

Published: Mar 20, 2026
Source: NVD
CVE-2026-33476 HIGH - 7.5

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory traversal and read arbitrary files accessible to the server p...

Vendor: siyuan-note
Product: siyuan
Published: Mar 20, 2026
Source: NVD
CVE-2026-33243 HIGH - 8.2

barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were verified as part of a ...

Vendor: barebox
Product: barebox
Published: Mar 20, 2026
Source: NVD
CVE-2026-32663 HIGH - 7.3

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connecti...

Vendor: IGL-Technologies
Product: eParking.fi
Published: Mar 20, 2026
Source: NVD