Total CVEs

140,303

Critical Severity

3,711

High Severity

13,353

Last 7 Days

1,802
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 8,681 - 8,700 of 13,050 CVEs
CVE-2026-24063 HIGH - 8.2

When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When uninstalling a plugin via the Arturia Software Center the Pr...

Vendor: Arturia
Product: Software Center
Published: Mar 18, 2026
Source: NVD
CVE-2026-24062 HIGH - 7.8

The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects. This leads to an attacker being able to connect to the helper and execute privileged actions leading to local privilege escalation.

Vendor: Arturia
Product: Software Center
Published: Mar 18, 2026
Source: NVD
CVE-2025-55046 HIGH - 8.1

MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a simple CSRF attack. The vulnerable cTrash.empty function lacks CSRF token validation, enabling malicious websites to forge requests that irrever...

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2025-55045 HIGH - 7.1

The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function lacks CSRF token validation, enabling malicious websites to forge requests that add, modify, or delete user addresses wh...

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2025-55044 HIGH - 8.8

The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CSRF. The vulnerable cTrash.restore function lacks CSRF token validation, enabling malicious websites to forge requests that restore content to...

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2025-55041 HIGH - 8.0

MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attackers to escalate privileges by adding any user to any group without proper authorization checks. The vulnerable function lacks CSRF token valida...

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2025-55040 HIGH - 8.8

The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token validation, enabling malicious websites to forge file upload requests that install attacker...

Vendor: murasoftware
Product: mura_cms
Published: Mar 18, 2026
Source: NVD
CVE-2026-33125 HIGH - 7.1

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and below, users with the viewer role can delete admin and low-privileged user accounts. Exploitation can lead to DoS and affect data integrity. This issue has been patched in version 0....

Vendor: pip
Product: frigate
Published: Mar 18, 2026
Source: GitHub
CVE-2026-32693 HIGH - 8.8

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation at...

Vendor: Canonical
Product: Juju
Published: Mar 18, 2026
Source: NVD
CVE-2026-32692 HIGH - 7.6

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient information, an attacker can poison any existing secret revision within the...

Vendor: Canonical
Product: Juju
Published: Mar 18, 2026
Source: NVD
CVE-2026-32875 HIGH - 7.5

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer overflow or infinite loop through large indent handling. ujson.dumps() crashes the Python interpreter (segmentation fault) when the product of the inden...

Vendor: pip
Product: ujson
Published: Mar 18, 2026
Source: GitHub
CVE-2026-32874 HIGH - 7.5

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.11.0 contain an accumulating memory leak in JSON parsing large (outside of the range [-2^63, 2^64 - 1]) integers. The leaked memory is a copy of the string form of the integer plus ...

Vendor: pip
Product: ujson
Published: Mar 18, 2026
Source: GitHub
CVE-2026-32811 HIGH - 8.2

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. When using Heimdall in envoy gRPC decision API mode with versions 0.7.0-alpha through 0.17.10, wrong encoding of the query URL string allows rules with non-wildcard path expressions to be bypassed. Envoy splits the ...

Vendor: go
Product: github.com/dadrus/heimdall
Published: Mar 18, 2026
Source: GitHub
CVE-2026-32763 HIGH - 8.2

Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation for MySQL and SQLite dialects. The `visitJSONPathLeg()` function appends user-controlled values from `.key()` and `.at()` directly into single-quoted JS...

Vendor: npm
Product: kysely
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33053 HIGH - 8.8

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_api_key_route() endpoint accepts an api_key_id path parameter and deletes it with only a generic authentication check (get_current_active_user dependency). However, the delete_api_ke...

Vendor: pip
Product: langflow
Published: Mar 18, 2026
Source: GitHub
CVE-2025-41258 HIGH - 8.0

LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.

Vendor: danny-avila
Product: LibreChat
Published: Mar 18, 2026
Source: NVD
CVE-2026-22730 HIGH - 8.8

A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization.

Vendor: VMware
Product: Spring AI
Published: Mar 18, 2026
Source: NVD
CVE-2026-22729 HIGH - 8.6

A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated into JSONPath queries without prope...

Vendor: VMware
Product: Spring AI
Published: Mar 18, 2026
Source: NVD
CVE-2026-22323 HIGH - 7.1

A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into sending unauthorized POST requests to the device by luring them to a malicious webpage. This can silently alter the device’s configuration without the vict...

Published: Mar 18, 2026
Source: NVD
CVE-2026-22322 HIGH - 7.1

A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to create a trunk entry containing malicious HTML/JavaScript code. When the affected page is viewed, the injected script executes in the context of the victim’s...

Published: Mar 18, 2026
Source: NVD