Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,811
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,461 - 8,480 of 13,041 CVEs
CVE-2026-33010 HIGH - 8.1

mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP server is enabled (MCP_HTTP_ENABLED=true), the application configures FastAPI's CORSMiddleware with allow_origins=['*'], allow_credentials=True, allow_methods=["*&...

Vendor: doobidoo
Product: mcp-memory-service
Published: Mar 20, 2026
Source: NVD
CVE-2026-32710 HIGH - 8.5

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11.8.6 via a bug in JSON_SCHEMA_VALID() function. Under certain conditions it might be possible to turn the crash into a remote code execution. These con...

Vendor: MariaDB
Product: server
Published: Mar 20, 2026
Source: NVD
CVE-2026-32318 HIGH - 7.6

Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before ...

Vendor: cryptomator
Product: ios
Published: Mar 20, 2026
Source: NVD
CVE-2026-32317 HIGH - 7.6

Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Be...

Vendor: cryptomator
Product: android
Published: Mar 20, 2026
Source: NVD
CVE-2026-32309 HIGH - 7.5

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vault metadata without enforcing HTTPS. As a result, a vault configuration can drive OAuth and key-loading traffic over plai...

Vendor: cryptomator
Product: cryptomator
Published: Mar 20, 2026
Source: NVD
CVE-2026-4493 HIGH - 8.8

A vulnerability was determined in Tenda A18 Pro 02.03.02.28. The impacted element is the function sub_423B50 of the file /goform/setMacFilterCfg of the component MAC Filtering Configuration Endpoint. Executing a manipulation of the argument deviceList can lead to stack-based buffer overflow. The att...

Published: Mar 20, 2026
Source: NVD
CVE-2026-4492 HIGH - 8.8

A vulnerability was found in Tenda A18 Pro 02.03.02.28. The affected element is the function set_qosMib_list of the file /goform/formSetQosBand. Performing a manipulation of the argument list results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has b...

Published: Mar 20, 2026
Source: NVD
CVE-2026-32303 HIGH - 7.6

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub key loading mechanism. Before this fix, the client trusted endp...

Vendor: cryptomator
Product: cryptomator
Published: Mar 20, 2026
Source: NVD
CVE-2026-31836 HIGH - 8.1

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. In versions from 3.5.1 and prior, a mass assignment vulnerability in Checkmate's user profile update endpoint allows any...

Vendor: bluewave-labs
Product: Checkmate
Published: Mar 20, 2026
Source: NVD
CVE-2026-33331 HIGH - 8.2

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.9, a stored cross-site scripting (XSS) vulnerability exists in the OpenAPI documentation generation of orpc. If an attacker can control any field within the OpenAPI specificatio...

Vendor: npm
Product: @orpc/openapi
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33316 HIGH - 8.1

Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunjaโ€™s password reset logic allows disabled users to regain access to their accounts. The `ResetPassword()` function sets the userโ€™s status to `StatusActive` after a successful password reset without...

Vendor: go
Product: code.vikunja.io/api
Published: Mar 20, 2026
Source: GitHub
CVE-2026-4491 HIGH - 8.8

A vulnerability has been found in Tenda A18 Pro 02.03.02.28. Impacted is the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument list leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed to the public and ...

Published: Mar 20, 2026
Source: NVD
CVE-2026-4490 HIGH - 8.8

A flaw has been found in Tenda A18 Pro 02.03.02.28. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. This manipulation causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Published: Mar 20, 2026
Source: NVD
CVE-2026-4489 HIGH - 8.8

A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be ...

Published: Mar 20, 2026
Source: NVD
CVE-2026-4488 HIGH - 8.8

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected is the function strcpy of the file /goform/setSysAdm. Such manipulation of the argument GroupName leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might...

Published: Mar 20, 2026
Source: NVD
CVE-2026-32989 HIGH - 8.8

Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafted requests to a profile update endpoint handling file uploads. Attackers can exploit this to upload executable files to web-accessible locations, leadi...

Vendor: Precurio
Product: Precurio Intranet Portal
Published: Mar 20, 2026
Source: NVD
CVE-2025-67260 HIGH - 8.8

The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code. Vulnerable components include Terrapack TkWebCoreNG:: 1.0.20200914, Terrapack TKServerCGI 2.5.4.150, and Terrapack Tpk...

Published: Mar 20, 2026
Source: NVD
CVE-2025-46597 HIGH - 7.5

Bitcoin Core 0.13.0 through 29.x has an integer overflow.

Published: Mar 20, 2026
Source: NVD
CVE-2026-4487 HIGH - 8.8

A vulnerability was determined in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/websHostFilter. This manipulation causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

Published: Mar 20, 2026
Source: NVD
CVE-2026-4486 HIGH - 8.8

A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/formEasySetPassword of the component Web Service. The manipulation of the argument curTime results in stack-based buffer overflow. The attack may be performed from remote. The exploit ...

Published: Mar 20, 2026
Source: NVD