Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,804
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,561 - 8,580 of 13,041 CVEs
CVE-2026-33321 HIGH - 7.6

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An Out-of-Band Server-Side Req...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-33302 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `AclMain::zhAclCheck()` only checks for the presence of any "allow" (user or group). It never checks for explicit "deny" (allowed=0)....

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-33301 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An arbitrary file read vulner...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-32622 HIGH - 8.8

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any authenticated user to upload malicious terminology, un...

Vendor: dataease
Product: SQLBot
Published: Mar 19, 2026
Source: NVD
CVE-2026-26139 HIGH - 8.6

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: purview
Published: Mar 19, 2026
Source: NVD
CVE-2026-26138 HIGH - 8.6

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: purview
Published: Mar 19, 2026
Source: NVD
CVE-2026-26137 HIGH - 8.9

Server-side request forgery (ssrf) in Microsoft 365 Copilot's Business Chat allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: 365_copilot_chat
Published: Mar 19, 2026
Source: NVD
CVE-2026-23659 HIGH - 8.6

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

Published: Mar 19, 2026
Source: NVD
CVE-2026-23658 HIGH - 8.6

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

Published: Mar 19, 2026
Source: NVD
CVE-2026-33354 HIGH - 7.6

WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-controlled `chunkFile` parameter intended for staged upload chunks. Instead of restricting that path to trusted server-generated chunk locations, the endpoin...

Vendor: composer
Product: wwbn/avideo
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33353 HIGH - 6.5

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. T...

Vendor: go
Product: github.com/charmbracelet/soft-serve
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33344 HIGH - 8.1

Dagu is a workflow engine with a built-in Web user interface. From version 2.0.0 to before version 2.3.1, the fix for CVE-2026-27598 added ValidateDAGName to CreateNewDAG and rewrote generateFilePath to use filepath.Base. This patched the CREATE path. The remaining API endpoints - GET, DELETE, RENAM...

Vendor: go
Product: github.com/dagu-org/dagu
Published: Mar 19, 2026
Source: GitHub
CVE-2026-25667 HIGH - 7.5

ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.

Published: Mar 19, 2026
Source: NVD
CVE-2026-33282 HIGH - 7.5

Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP LocationReport message with `ue-presence-in-area-of-interest` event type and omitting the optional `UEPresenceInAreaOfInterestList` IE. An attacker able to send crafted NGAP messages...

Vendor: go
Product: github.com/ellanetworks/core
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33310 HIGH - 8.8

Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() syntax within parameter default values appears to be automatically expanded during the catalog parsing process. If a catalog contains a parameter default such as shell(<command>)...

Vendor: pip
Product: intake
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33228 HIGH - 9.8

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the...

Vendor: npm
Product: flatted
Published: Mar 19, 2026
Source: GitHub
CVE-2026-30403 HIGH - 7.5

There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can be used to read any file on the victim's server.

Published: Mar 19, 2026
Source: NVD
CVE-2026-33295 HIGH - 5.4

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title` field of a video record is interpolated directly into a JavaScript string literal without any e...

Vendor: composer
Product: wwbn/avideo
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33293 HIGH - 8.1

WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitization. An attacker with valid clone credentials can use path traversal sequences (e.g., `../../`) to del...

Vendor: composer
Product: wwbn/avideo
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33292 HIGH - 7.5

WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to stream any private or paid video on the platform. The `videoDirectory` GET parameter is used in two div...

Vendor: composer
Product: wwbn/avideo
Published: Mar 19, 2026
Source: GitHub