Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,811
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,481 - 8,500 of 13,041 CVEs
CVE-2026-4434 HIGH - 8.1

Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.

Published: Mar 20, 2026
Source: NVD
CVE-2026-33133 HIGH - 7.2

WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup archives without any content validation. An attacker can craft a backup archive containing arbitrary SQL statements that create rogue administrator acco...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Mar 20, 2026
Source: NVD
CVE-2026-32305 HIGH - 5.3

Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When a TLS ClientHello is fragmented across multiple records, Tra...

Vendor: traefik
Product: traefik
Published: Mar 20, 2026
Source: NVD
CVE-2026-33124 HIGH - 8.8

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-beta1 allow any authenticated user to change their own password without verifying the current password through the /users/{username}/password endpoint. Changing a password does not...

Vendor: blakeblackshear
Product: frigate
Published: Mar 20, 2026
Source: NVD
CVE-2026-22324 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Melania allows PHP Local File Inclusion.This issue affects Melania: from n/a through 2.5.0.

Vendor: ThemeREX
Product: Melania
Published: Mar 20, 2026
Source: NVD
CVE-2026-0677 HIGH - 7.2

Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite allows Object Injection.This issue affects TotalContest Lite: from n/a through 2.9.1.

Published: Mar 20, 2026
Source: NVD
CVE-2024-32537 HIGH - 7.1

Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This issue affects Flash Video Player: from n/a through 5.0.4.

Vendor: joshuae1974
Product: Flash Video Player
Published: Mar 20, 2026
Source: NVD
CVE-2026-33075 HIGH - 8.8

FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor. It uses pull_request_target (which runs with access to repository secrets) but checks out co...

Vendor: labring
Product: FastGPT
Published: Mar 20, 2026
Source: NVD
CVE-2026-33072 HIGH - 8.2

FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption key (default_please_change_this_key) is used for all cryptographic operations โ€” HMAC token generation, AES config encryption, and session tokens โ€” allowing any unauthenticated attac...

Vendor: error311
Product: FileRise
Published: Mar 20, 2026
Source: NVD
CVE-2026-33069 HIGH - 7.5

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading out-of-bounds heap read in pjsip_multipart_parse(). After boundary string matching, curptr is advanced past the delimiter without verifying it has not reached the buffer end. This ...

Vendor: pjsip
Product: pjproject
Published: Mar 20, 2026
Source: NVD
CVE-2026-32701 HIGH - 7.5

Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form field names during FormData parsing. By submitting mixed array-index and object-property keys for the same path, an attacker could cause user-controlled properties to be written o...

Vendor: QwikDev
Product: qwik
Published: Mar 20, 2026
Source: NVD
CVE-2026-27625 HIGH - 8.1

Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5.2, the /api/v1/convert/markdown/pdf endpoint extracts user-supplied ZIP entries without path checks. Any authenticated user can write files outside the intended temporary working ...

Vendor: Stirling-Tools
Product: Stirling-PDF
Published: Mar 20, 2026
Source: NVD
CVE-2026-4478 HIGH - 8.1

A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This impacts an unknown function of the file home/web/ipc of the component HTTP Firmware Update Handler. The manipulation leads to improper verification of cryptographic signature. The attack is possible to be car...

Published: Mar 20, 2026
Source: NVD
CVE-2026-4475 HIGH - 8.8

A vulnerability has been found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The affected element is an unknown function of the file home/web/ipc. Such manipulation leads to hard-coded credentials. Access to the local network is required for this attack to succeed. The exploit has been dis...

Published: Mar 20, 2026
Source: NVD
CVE-2026-33037 HIGH - 8.1

WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-compose.yml, env.example) ship with the admin password set to "password", which is automatically used to seed the admin account during installation, meaning any instance d...

Vendor: WWBN
Product: AVideo
Published: Mar 20, 2026
Source: NVD
CVE-2026-33025 HIGH - 8.8

AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_POST['sort'] array keys are used directly as SQL column identifiers inside an ORDER BY clause. Although real_escape_string() was applied, it o...

Vendor: WWBN
Product: AVideo-Encoder
Published: Mar 20, 2026
Source: NVD
CVE-2026-33013 HIGH - 7.5

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both 4.10.16 and 3.10.5 do not correctly handle descending array index order during form-urlencoded body binding in theJsonBeanPropertyBinder::expandArrayTo...

Vendor: micronaut-projects
Product: micronaut-core
Published: Mar 20, 2026
Source: NVD
CVE-2026-32954 HIGH - 7.1

ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpoints were vulnerable to time-based and boolean-based blind SQL injection due to insufficient parameter validation, allowing attackers to infer database information. This issue has ...

Vendor: frappe
Product: erpnext
Published: Mar 20, 2026
Source: NVD
CVE-2026-32950 HIGH - 8.8

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerability in the /api/v1/datasource/uploadExcel endpoint that enables Remote Code Execution (RCE), allowing any authenticated user (even the lowest-privile...

Vendor: dataease
Product: SQLBot
Published: Mar 20, 2026
Source: NVD
CVE-2026-32949 HIGH - 7.5

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to retrieve arbitrary system and application files from the server. An attacker can exploit the /api/v1/datas...

Vendor: dataease
Product: SQLBot
Published: Mar 20, 2026
Source: NVD