Total CVEs

140,343

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,769
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,601 - 8,620 of 13,215 CVEs
CVE-2026-23536 HIGH - 7.5

A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated remote attacker to read any file accessible to the server process. By sending a specially crafted HTTP POST request, an attacker can bypass intended access restrictions to pote...

Vendor: Red Hat
Product: Red Hat OpenShift AI (RHOAI)
Published: Mar 20, 2026
Source: NVD
CVE-2026-33509 HIGH - 7.5

pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API endpoint allows users with the non-admin SETTINGS permission to modify any configuration option without restriction. The reconnect.script config option ...

Vendor: pip
Product: pyload-ng
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33508 HIGH - 7.5

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.56 and 9.6.0-alpha.45, Parse Server's LiveQuery component does not enforce the requestComplexity.queryDepth configuration setting when processing WebSocket subscription ...

Vendor: npm
Product: parse-server
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33507 HIGH - 8.8

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing executable PHP code, but lacks any CSRF protection. Combined with the application explicitly setting `...

Vendor: composer
Product: wwbn/avideo
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33164 HIGH - 7.5

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.

Vendor: strukturag
Product: libde265
Published: Mar 20, 2026
Source: NVD
CVE-2026-33156 HIGH - 7.8

ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading via version.dll . When the portable executable is run from a user-writable directory, it loads version.dll from the application directory instead of the Windows System32 directory,...

Vendor: NickeManarin
Product: ScreenToGif
Published: Mar 20, 2026
Source: NVD
CVE-2026-33150 HIGH - 7.8

libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-free vulnerability in the io_uring subsystem of libfuse allows a local attacker to crash FUSE filesystem processes and potentially execute arbitrary code. When io_uring thread creatio...

Vendor: libfuse
Product: libfuse
Published: Mar 20, 2026
Source: NVD
CVE-2026-33147 HIGH - 7.3

GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions from 6.6.0 and prior, a stack-based buffer overflow vulnerability was identified in the gmt_remote_dataset_id function within src/gmt_remote.c. This issue occurs when a specially c...

Vendor: GenericMappingTools
Product: gmt
Published: Mar 20, 2026
Source: NVD
CVE-2025-63261 HIGH - 7.8

AWStats 8.0 is vulnerable to Command Injection via the open function

Published: Mar 20, 2026
Source: NVD
CVE-2025-55988 HIGH - 7.2

An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path.

Vendor: composer
Product: dreamfactory/df-core
Published: Mar 20, 2026
Source: NVD
CVE-2026-33498 HIGH - 7.5

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.55 and 9.6.0-alpha.44, an attacker can send an unauthenticated HTTP request with a deeply nested query containing logical operators to permanently hang the Parse Server proce...

Vendor: npm
Product: parse-server
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33497 HIGH - 7.5

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_profile_picture function of the /profile_pictures/{folder_name}/{file_name} endpoint, the folder_name and file_name parameters are not strictly filtered, which allows the secret_key...

Vendor: pip
Product: langflow
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33505 HIGH - 7.2

Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelationships API in Ory Keto is vulnerable to SQL injection due to flaws in its pagination implementation. Pagination tokens are encrypted using the secret configured in `secrets.pagin...

Vendor: go
Product: github.com/ory/keto
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33504 HIGH - 7.2

Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2ConsentSessions, and listTrustedOAuth2JwtGrantIssuers Admin APIs in Ory Hydra are vulnerable to SQL injection due to flaws in its pagination implementation. Pagination tokens are e...

Vendor: go
Product: github.com/ory/hydra
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33503 HIGH - 7.2

Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the ListCourierMessages Admin API in Ory Kratos is vulnerable to SQL injection due to flaws in its pagination implementation. Pagination tokens are encrypted using the secret configured ...

Vendor: go
Product: github.com/ory/kratos
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33496 HIGH - 8.1

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to authentication bypass due to cache key confusion. The `oauth2_introspection` authenticator cache does not di...

Vendor: go
Product: github.com/ory/oathkeeper
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33493 HIGH - 7.1

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled `fileURI` POST parameter with only a regex check that the value ends in `.mp4`. Unlike `objects/listFiles.json.php`, which was hardened with a `realpat...

Vendor: composer
Product: wwbn/avideo
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33492 HIGH - 7.3

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them as the active PHP session. A session regeneration bypass exists for specific blacklisted endpoin...

Vendor: composer
Product: wwbn/avideo
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33488 HIGH - 7.4

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA keys, which have been publicly factorable since 1999. An attacker who obtains a target user's public key can fac...

Vendor: composer
Product: wwbn/avideo
Published: Mar 20, 2026
Source: GitHub
CVE-2026-33468 HIGH - 8.1

Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes single quotes by doubling them (`'` โ†’ `''`) but does not escape backslashes. When used with the MySQL dialect (where `NO_BACKSLASH_ES...

Vendor: npm
Product: kysely
Published: Mar 20, 2026
Source: GitHub