Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,803
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,581 - 8,600 of 13,041 CVEs
CVE-2026-33252 HIGH - 7.1

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without validating the `Origin` header and without requiring `Content-Type: application/json`. In deployments without Author...

Vendor: go
Product: github.com/modelcontextprotocol/go-sdk
Published: Mar 19, 2026
Source: GitHub
CVE-2026-32935 HIGH - 5.9

phpseclib is a PHP secure communications library. Projects using versions 1.0.26 and below, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50.

Vendor: composer
Product: phpseclib/phpseclib
Published: Mar 19, 2026
Source: GitHub
CVE-2026-27953 HIGH - 7.1

ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to skip all field validation by injecting "__pk_only__": true into a JSON request body. By injecting "__pk_only...

Vendor: pip
Product: ormar
Published: Mar 19, 2026
Source: GitHub
CVE-2026-30404 HIGH - 7.5

The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulnerability. This issue can be exploited to make the server send requests to probe the internal network, remotely download malicious files, and perform other dangerous operations.

Published: Mar 19, 2026
Source: NVD
CVE-2026-4427 HIGH - 7.5

A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.

Vendor: go
Product: github.com/jackc/pgproto3/v2
Published: Mar 19, 2026
Source: NVD
CVE-2026-4424 HIGH - 7.5

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR arch...

Published: Mar 19, 2026
Source: NVD
CVE-2026-30711 HIGH - 8.8

Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.inc.php file via the referer and user-agent.

Published: Mar 19, 2026
Source: NVD
CVE-2026-27043 HIGH - 7.2

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue affects Photography: from n/a through 7.7.5.

Vendor: ThemeGoods
Product: Photography
Published: Mar 19, 2026
Source: NVD
CVE-2026-22558 HIGH - 7.7

An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access to the network to escalate privileges.

Vendor: Ubiquiti Inc
Product: UniFi Network Application
Published: Mar 19, 2026
Source: NVD
CVE-2025-71260 HIGH - 8.8

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parame...

Vendor: BMC Software, Inc.
Product: FootPrints
Published: Mar 19, 2026
Source: NVD
CVE-2025-71257 HIGH - 7.3

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security filters on restricted REST API endpoints and servlets. Unauthenticated remote attackers can bypass access controls to invoke restricted functionality and ...

Vendor: BMC Software, Inc.
Product: FootPrints
Published: Mar 19, 2026
Source: NVD

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user suppli...

Vendor: rubygems
Product: json
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33241 HIGH - 7.5

Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading request bodies into memory. This allows attackers to cause Out-of-Memory (OOM) conditions by sending...

Vendor: rust
Product: salvo
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33242 HIGH - 7.5

Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated external attacker to bypass proxy routing constraints and access unintended backend paths (e.g., prote...

Vendor: rust
Product: salvo
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33236 HIGH - 8.1

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downloader does not validate the `subdir` and `id` attributes when processing remote XML index ...

Vendor: pip
Product: nltk
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33231 HIGH - 7.5

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet Browser HTTP server w...

Vendor: pip
Product: nltk
Published: Mar 19, 2026
Source: GitHub
CVE-2026-33068 HIGH - 8.8

Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determining whether to display the workspace trust confirmation dialog. A malicious repository could set permissions.defaultMo...

Vendor: npm
Product: @anthropic-ai/claude-code
Published: Mar 19, 2026
Source: GitHub
CVE-2026-3658 HIGH - 7.5

The Appointment Booking Calendar โ€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in all versions up to, and including, 1.6.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient pr...

Published: Mar 19, 2026
Source: NVD
CVE-2026-3511 HIGH - 8.6

Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable applicat...

Published: Mar 19, 2026
Source: NVD
CVE-2006-10002 HIGH - 7.5

XML::Parser versions through 2.47 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes. A :utf8 PerlIO layer, parse_stream() in Expat.xs could overflow the XML input buffer because Perl's read() returns decoded characters while S...

Vendor: TODDR
Product: XML::Parser
Published: Mar 19, 2026
Source: NVD