Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,803
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,661 - 8,680 of 13,041 CVEs
CVE-2026-33143 HIGH - 7.5

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp X-Hub-Signature-256 HMAC signature, allowing any unauthenticat...

Vendor: npm
Product: oneuptime
Published: Mar 18, 2026
Source: GitHub
CVE-2026-30345 HIGH - 7.5

A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitrary files outside the intended directories via supplying a crafted import.

Published: Mar 18, 2026
Source: NVD
CVE-2026-1463 HIGH - 8.8

The Photo Gallery, Sliders, Proofing and Themes โ€“ NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.3 via the 'template' parameter in gallery shortcodes. This makes it possible for authenticated attackers, with Author-level...

Published: Mar 18, 2026
Source: NVD
CVE-2026-33142 HIGH - 8.1

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-32306 (ClickHouse SQL injection via aggregate query parameters) added column name validation to the _aggregateBy method but did not apply the same validation to three other query const...

Vendor: npm
Product: oneuptime
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33139 HIGH - 7.8

PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PySpector versions 0.1.6 and prior are affected by a security validation bypass in the plugin system. The validate_plugin_code() function in plugin_system.py, performs static AST anal...

Vendor: pip
Product: pyspector
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33131 HIGH - 7.4

H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which extends FastURL) which allows middleware bypass. When event.url, event.url.hostname, or event.url._url is accessed, such as in a logging middleware, the _u...

Vendor: npm
Product: h3
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33128 HIGH - 7.5

H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent Events (SSE) injection due to missing newline sanitization in formatEventStreamMessage() and formatEventStreamComment(). An attacker who controls any pa...

Vendor: npm
Product: h3
Published: Mar 18, 2026
Source: GitHub
CVE-2026-3090 HIGH - 7.2

The Post SMTP โ€“ Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜event_typeโ€™ parameter in all versions up to, and including, 3.8.0 due to insufficient input sanitization an...

Published: Mar 18, 2026
Source: NVD
CVE-2026-33002 HIGH - 7.5

Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable ...

Vendor: Jenkins Project
Product: Jenkins
Published: Mar 18, 2026
Source: NVD
CVE-2026-33001 HIGH - 8.8

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkin...

Vendor: Jenkins Project
Product: Jenkins
Published: Mar 18, 2026
Source: NVD
CVE-2026-2992 HIGH - 8.2

The KiviCare โ€“ Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthentica...

Published: Mar 18, 2026
Source: NVD
CVE-2026-24063 HIGH - 8.2

When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When uninstalling a plugin via the Arturia Software Center the Pr...

Vendor: Arturia
Product: Software Center
Published: Mar 18, 2026
Source: NVD
CVE-2026-24062 HIGH - 7.8

The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects.ย This leads to an attacker being able to connect to the helper and execute privileged actions leading to local privilege escalation.

Vendor: Arturia
Product: Software Center
Published: Mar 18, 2026
Source: NVD
CVE-2025-55046 HIGH - 8.1

MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a simple CSRF attack. The vulnerable cTrash.empty function lacks CSRF token validation, enabling malicious websites to forge requests that irrever...

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2025-55045 HIGH - 7.1

The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function lacks CSRF token validation, enabling malicious websites to forge requests that add, modify, or delete user addresses wh...

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2025-55044 HIGH - 8.8

The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CSRF. The vulnerable cTrash.restore function lacks CSRF token validation, enabling malicious websites to forge requests that restore content to...

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2025-55041 HIGH - 8.0

MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attackers to escalate privileges by adding any user to any group without proper authorization checks. The vulnerable function lacks CSRF token valida...

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2025-55040 HIGH - 8.8

The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token validation, enabling malicious websites to forge file upload requests that install attacker...

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2026-33125 HIGH - 7.1

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and below, users with the viewer role can delete admin and low-privileged user accounts. Exploitation can lead to DoS and affect data integrity. This issue has been patched in version 0....

Vendor: pip
Product: frigate
Published: Mar 18, 2026
Source: GitHub
CVE-2026-32693 HIGH - 8.8

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation at...

Vendor: Canonical
Product: Juju
Published: Mar 18, 2026
Source: NVD