Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,812
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,761 - 8,780 of 13,058 CVEs
CVE-2026-4289 HIGH - 7.3

A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an unknown function of the file /rest/preSetTemplate/getRecByTemplateId. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit ...

Published: Mar 17, 2026
Source: NVD
CVE-2026-4288 HIGH - 7.3

A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown function of the file /rest/devStatus/getDevDetailedInfo of the component Endpoint. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launche...

Published: Mar 17, 2026
Source: NVD
CVE-2026-4287 HIGH - 7.3

A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an unknown function of the file /rest/devStatus/queryResources of the component Endpoint. Performing a manipulation of the argument areaId results in sql injection. The attack can be in...

Published: Mar 17, 2026
Source: NVD
CVE-2026-32813 HIGH - 8.0

Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configuration feature lets authenticated users define custom list column layouts, storing user-supplied column names, sort direc...

Vendor: composer
Product: admidio/admidio
Published: Mar 16, 2026
Source: GitHub
CVE-2026-32756 HIGH - 8.8

Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSRF token validation and file extension verification interact within UploadHandlerFile.php, an auth...

Vendor: composer
Product: admidio/admidio
Published: Mar 16, 2026
Source: GitHub
CVE-2025-50881 HIGH - 8.8

The `flow/admin/moniteur.php` script in Use It Flow administration website before 10.0.0 is vulnerable to Remote Code Execution. When handling GET requests, the script takes user-supplied input from the `action` URL parameter, performs insufficient validation, and incorporates this input into a stri...

Published: Mar 16, 2026
Source: NVD

Fullchain is an umbrella project for deploying a ready-to-use CTF platform. In versions prior to 0.1.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a subverted application to any Pod out of the origin namespace. The flawed inter-ns NetworkPolicy breaks the security-by-defau...

Vendor: go
Product: github.com/ctfer-io/fullchain
Published: Mar 16, 2026
Source: GitHub
CVE-2026-32805 HIGH - 7.5

Romeo gives the capability to reach high code coverage of Go โ‰ฅ1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to version 0.2.2, the `sanitizeArchivePath` function in `webserver/api/v1/decoder.go` (lines 80-88) is vulnerable to a path tr...

Vendor: go
Product: github.com/ctfer-io/romeo/webserver
Published: Mar 16, 2026
Source: GitHub

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). In versions prior to 0.2.2, the sanitizeArchivePath function in pkg/extract/extract.go (lines 248โ€“254) is vulnerable to Path Traversal due to a missin...

Vendor: go
Product: github.com/ctfer-io/monitoring
Published: Mar 16, 2026
Source: GitHub
CVE-2026-32737 HIGH - 10.0

Romeo gives the capability to reach high code coverage of Go โ‰ฅ1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to version 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from the "hardened" namespace to a...

Vendor: go
Product: github.com/ctfer-io/romeo/environment/deploy
Published: Mar 16, 2026
Source: GitHub

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, due to a miswritten NetworkPolicy, a malicious actor can pivot from an instance to any Pod out of the origin namespace. This breaks the security-by-default property expected as par...

Vendor: go
Product: github.com/ctfer-io/chall-manager/deploy
Published: Mar 16, 2026
Source: GitHub
CVE-2026-30881 HIGH - 8.8

Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The parameters date_start and date_end from $_REQUEST are embedded directly into a raw SQL string without proper sanitization. Although Database::escape_stri...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 16, 2026
Source: NVD
CVE-2026-30875 HIGH - 8.8

Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated users with Teacher role to achieve Remote Code Execution (RCE). The H5P package validation only checks if h5p.json exists but doesn't bloc...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 16, 2026
Source: NVD
CVE-2025-68971 HIGH - 7.5

In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be associated with an issue or a release).

Published: Mar 16, 2026
Source: NVD

Webhooks for Craft CMS plugin adds the ability to manage โ€œwebhooksโ€ in Craft CMS, which will send GET or POST requests when certain events occur. From version 3.0.0 to before version 3.2.0, the Webhooks plugin renders user-supplied template content through Twigโ€™s renderString() function without sand...

Vendor: craftcms
Product: webhooks
Published: Mar 16, 2026
Source: NVD
CVE-2026-32749 HIGH - 7.6

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploaded archives to a path derived from the multipart filename field without sanitization, allowing an admin to write files to arbitrary locations outside ...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 16, 2026
Source: GitHub
CVE-2026-32728 HIGH - 7.6

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.15 and 8.6.41, an attacker who is allowed to upload files can bypass the file extension filter by appending a MIME parameter (e.g. `;charset=utf-8`) to the `Content-Type` head...

Vendor: npm
Product: parse-server
Published: Mar 16, 2026
Source: GitHub

The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, unauthenticated users can view a list of buckets the plugin has access to. The `DefaultController->actionLoadContainerData()` endpoint allows unauthe...

Vendor: composer
Product: craftcms/azure-blob
Published: Mar 16, 2026
Source: GitHub
CVE-2026-4269 HIGH - 7.5

A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before vers...

Vendor: pip
Product: bedrock-agentcore-starter-toolkit
Published: Mar 16, 2026
Source: NVD
CVE-2026-28498 HIGH - 7.5

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash...

Vendor: authlib
Product: authlib
Published: Mar 16, 2026
Source: NVD