Total CVEs

140,303

Critical Severity

3,711

High Severity

13,353

Last 7 Days

1,802
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 8,701 - 8,720 of 13,050 CVEs
CVE-2026-22317 HIGH - 7.2

A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacker to send crafted HTTP POST requests that result in arbitrary command execution on the underlying Linux OS with root privileges.

Published: Mar 18, 2026
Source: NVD
CVE-2026-2603 HIGH - 8.1

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (IdP) to the Keycloak SAML endpoint for IdP-initiated broker logins. This allows the attacker to complete broker logins even when the SAML Identity Provi...

Vendor: maven
Product: org.keycloak:keycloak-services
Published: Mar 18, 2026
Source: NVD
CVE-2026-2092 HIGH - 7.7

A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion can exploit this by crafting a malicious SAML response....

Vendor: maven
Product: org.keycloak:keycloak-saml-adapter-core
Published: Mar 18, 2026
Source: NVD
CVE-2026-29056 HIGH - 8.8

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registration endpoint (`UserInviteController::register()`) accepts all POST parameters and passes them to `UserModel::create()` without filtering out the `role` field. An attacker who ...

Vendor: kanboard
Product: kanboard
Published: Mar 18, 2026
Source: NVD
CVE-2026-22175 HIGH - 7.1

OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always grants could be circumvented through unrecognized multiplexer shell wrappers like busybox and toybox sh -c commands. Attackers can exploit this by invoking arbitrary payloads under...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 18, 2026
Source: NVD
CVE-2026-22171 HIGH - 8.2

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpolated directly into temporary file paths in extensions/feishu/src/media.ts. An attacker who can control Feishu media key values returned to the client c...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 18, 2026
Source: NVD
CVE-2026-28674 HIGH - 7.2

xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the `AdminPaymentPluginUpload` endpoint lets admins upload any file to `plugins/payment/`. It only checks a hardcoded password (`qweasd123456`) and ignores file content. ...

Vendor: danvei233
Product: xiaoheiFS
Published: Mar 18, 2026
Source: NVD
CVE-2026-28673 HIGH - 7.2

xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and including 0.3.15, the standard plugin system allows admins to upload a ZIP file containing a binary and a `manifest.json`. The server trusts the `binaries` field in the manifest and execut...

Vendor: danvei233
Product: xiaoheiFS
Published: Mar 18, 2026
Source: NVD
CVE-2026-27894 HIGH - 8.8

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was detected in the PDF export that allows users to include local PHP files and this way execute code. In combination with GH...

Vendor: LDAPAccountManager
Product: lam
Published: Mar 18, 2026
Source: NVD
CVE-2026-27811 HIGH - 8.8

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability exists in the `/config/compare/<service>/<server_ip>/show` endpoint, allowed authenticated users to execute arbitrary system commands on the ...

Vendor: roxy-wi
Product: roxy-wi
Published: Mar 18, 2026
Source: NVD
CVE-2026-26001 HIGH - 7.1

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, non sanitized user input can lend to an SQL injection from reports, with adequate rights. This vulnerability is fixed in 1.6.6.

Vendor: glpi-project
Product: glpi-inventory-plugin
Published: Mar 18, 2026
Source: NVD
CVE-2026-22727 HIGH - 7.5

Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing them to access secure application information.

Vendor: Cloudfoundry
Product: Cloud Foundry
Published: Mar 17, 2026
Source: NVD
CVE-2026-1264 HIGH - 7.1

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 allows a remote unauthenticated attacker to view and delete the partners of a community and to delete the communities.

Vendor: ibm
Product: sterling_b2b_integrator
Published: Mar 17, 2026
Source: NVD
CVE-2025-14031 HIGH - 7.5

IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could allow an unauthenticated attacker to send a specially crafted request that causes the application to crash.

Vendor: IBM
Product: Sterling B2B Integrator
Published: Mar 17, 2026
Source: NVD
CVE-2026-32841 HIGH - 8.1

Edimax GS-5008PL firmware version 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthenticated attackers to access the management interface. Attackers can exploit the global authentication flag mechanism to gain administrative access without credentials after any user...

Vendor: EDIMAX Technology Co., Ltd.
Product: Edimax GS-5008PL
Published: Mar 17, 2026
Source: NVD
CVE-2026-32838 HIGH - 7.5

Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implementing TLS or SSL encryption. Attackers on the same network can intercept management traffic to capture administrator credentials and sensitive configuration data.

Vendor: EDIMAX Technology Co., Ltd.
Product: Edimax GS-5008PL
Published: Mar 17, 2026
Source: NVD
CVE-2026-1376 HIGH - 7.5

IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.

Vendor: ibm
Product: i
Published: Mar 17, 2026
Source: NVD
CVE-2026-33039 HIGH - 8.6

WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs against internal/private networks using isSSRFSafeURL(), but only checks the initial URL. When the initial URL responds with an HTTP redirect (Location heade...

Vendor: composer
Product: wwbn/avideo
Published: Mar 17, 2026
Source: GitHub
CVE-2026-4295 HIGH - 7.8

Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote unauthenticated threat actor to execute arbitrary code via maliciously crafted project directory files that bypass workspace trust protections when a local user opens the directory. ...

Published: Mar 17, 2026
Source: NVD
CVE-2026-4064 HIGH - 8.3

Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and dis...

Vendor: ironmansoftware
Product: powershell_universal
Published: Mar 17, 2026
Source: NVD