Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,803
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,641 - 8,660 of 13,041 CVEs
CVE-2026-33080 HIGH - 7.3

Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and 5.0.0 through 5.3.4 have two Filament Table summarizers (Range, Values) that render raw database values without escaping HTML. If there is a lack of validation for the data in the ...

Vendor: composer
Product: filament/tables
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33064 HIGH - 7.5

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2 are vulnerable to procedure panic caused by Nil Pointer Dereference in the /sdm-subscriptions endpoint. A remote attacker can cause the UDM service to panic and crash by sending a...

Vendor: go
Product: github.com/free5gc/udm
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33063 HIGH - 7.5

free5GC is an open source 5G core network. free5GC AUSF prior to version 1.4.2 has is an Improper Null Check vulnerability leading to Denial of Service. All deployments of free5GC v4.0.1 using the AUSF UE authentication service (`/nausf-auth/v1/ue-authentications` endpoint) are affected. A remote at...

Vendor: go
Product: github.com/free5gc/ausf
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33062 HIGH - 7.5

free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerability leading to Denial of Service. All deployments of free5GC using the NRF discovery service are affected. The `EncodeGroupId` function attempts to access array indices [0], [1], ...

Vendor: go
Product: github.com/free5gc/nrf
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33172 HIGH - 8.7

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset reuploads allows authenticated users with asset upload permissions to bypass SVG sanitization and inject malicious JavaScript that executes when the ass...

Vendor: composer
Product: statamic/cms
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33040 HIGH - 7.5

libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, the Gossipsub implementation accepts attacker-controlled PRUNE backoff values and may perform unchecked time arithmetic when storing backoff state. A specially crafted PRUNE control ...

Vendor: rust
Product: libp2p-gossipsub
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33166 HIGH - 8.6

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator prior to version 2.38.0 is vulnerable to an arbitrary file read via path traversal when processing test results. An attacker can craft a malicious result file (-result.json, -contai...

Vendor: maven
Product: io.qameta.allure:allure-generator
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33163 HIGH - 6.5

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the LiveQuery server leaks protected fields and `authData` to all subscribers of tha...

Vendor: npm
Product: parse-server
Published: Mar 18, 2026
Source: GitHub
CVE-2026-32730 HIGH - 8.1

ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incorrect MongoDB query that allows incomplete login tokens โ€” where the password was verified but TOTP/MF...

Vendor: npm
Product: apostrophe
Published: Mar 18, 2026
Source: GitHub
CVE-2026-31965 HIGH - 8.2

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function called while reading CRAM records, validation of the reference id field occurred too late, allowing two out of bounds r...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD
CVE-2026-31964 HIGH - 7.5

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. While most alignment records store DNA sequence and quality values, the format also allows them to omit...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD
CVE-2026-31963 HIGH - 8.1

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant data, CRAM uses reference-based compression so that instead of storing the full sequence for each alignment record it sto...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD
CVE-2025-58112 HIGH - 8.8

Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting...

Published: Mar 18, 2026
Source: NVD
CVE-2026-31962 HIGH - 8.8

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most alignment records store DNA sequence and quality values, the format also allows them to omit this data in certain cases to save space. Due to some...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD
CVE-2026-29858 HIGH - 7.5

A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensitive information exposure.

Vendor: aapanel
Product: aapanel
Published: Mar 18, 2026
Source: NVD
CVE-2026-29856 HIGH - 7.5

An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression Denial of Service (ReDoS) via a crafted input.

Vendor: aapanel
Product: aapanel
Published: Mar 18, 2026
Source: NVD
CVE-2026-27135 HIGH - 7.5

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They migh...

Vendor: nghttp2
Product: nghttp2
Published: Mar 18, 2026
Source: NVD
CVE-2026-26740 HIGH - 8.2

Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.

Vendor: giflib_project
Product: giflib
Published: Mar 18, 2026
Source: NVD
CVE-2026-32937 HIGH - 6.5

free5GC is an open source 5G core network. free5GC CHF prior to version 1.2.2 has an out-of-bounds slice access vulnerability in the CHF `nchf-convergedcharging` service. A valid authenticated request to PUT `/nchf-convergedcharging/v3/recharging/:ueId?ratingGroup=...` can trigger a server-side pani...

Vendor: go
Product: github.com/free5gc/chf
Published: Mar 18, 2026
Source: GitHub

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server ru...

Vendor: npm
Product: socket.io-parser
Published: Mar 18, 2026
Source: GitHub