Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,810
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,821 - 8,840 of 13,058 CVEs
CVE-2026-4193 HIGH - 7.3

A security vulnerability has been detected in D-Link DIR-823G 1.0.2B05. The affected element is the function GetDDNSSettings/GetDeviceDomainName/GetDeviceSettings/GetDMZSettings/GetFirewallSettings/GetGuestNetworkSettings/GetLanWanConflictInfo/GetLocalMacAddress/GetNetworkSettings/GetQoSSettings/Get...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4191 HIGH - 7.3

A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Picture Handler. This manipulation causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been published and may ...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4190 HIGH - 7.3

A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulation of the argument sort results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was conta...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4188 HIGH - 8.8

A security flaw has been discovered in D-Link DIR-619L 2.06B01. The affected element is the function formSchedule of the file /goform/formSchedule of the component boa. Performing a manipulation of the argument curTime results in stack-based buffer overflow. The attack may be initiated remotely. The...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4180 HIGH - 7.3

A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goahead. The manipulation of the argument token_id leads to improper access controls. The attack may be initiated remotely. The exploit is publicly availa...

Vendor: dlink
Product: dir-816_firmware
Published: Mar 16, 2026
Source: NVD
CVE-2026-4172 HIGH - 7.2

A vulnerability was detected in TRENDnet TEW-632BRP 1.010B32. This affects an unknown part of the file /ping_response.cgi of the component HTTP POST Request Handler. The manipulation of the argument ping_ipaddr results in stack-based buffer overflow. The attack may be performed from remote. The expl...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4167 HIGH - 8.8

A vulnerability was determined in Belkin F9K1122 1.00.33. This affects the function formReboot of the file /goform/formReboot. This manipulation of the argument webpage causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utiliz...

Published: Mar 16, 2026
Source: NVD
CVE-2026-3839 HIGH - 7.3

Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Unraid. Authentication is not required to exploit this vulnerability. The specific flaw exists within the auth-request.p...

Vendor: unraid
Product: unraid
Published: Mar 16, 2026
Source: NVD
CVE-2026-3838 HIGH - 8.8

Unraid Update Request Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authentication is required to exploit this vulnerability. The specific flaw exists within the update.php file. The issu...

Vendor: unraid
Product: unraid
Published: Mar 16, 2026
Source: NVD
CVE-2026-3561 HIGH - 8.0

Philips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Although authentication is required to exploit this vulnerability,...

Published: Mar 16, 2026
Source: NVD
CVE-2026-3560 HIGH - 8.8

Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerabil...

Published: Mar 16, 2026
Source: NVD
CVE-2026-3559 HIGH - 8.1

Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The specific f...

Published: Mar 16, 2026
Source: NVD
CVE-2026-3558 HIGH - 8.1

Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The ...

Published: Mar 16, 2026
Source: NVD
CVE-2026-3557 HIGH - 8.0

Philips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Although authentication is required to exploit th...

Published: Mar 16, 2026
Source: NVD
CVE-2026-3556 HIGH - 8.8

Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The spe...

Published: Mar 16, 2026
Source: NVD
CVE-2026-3555 HIGH - 8.0

Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. User interaction is required to exploit this vulnerab...

Published: Mar 16, 2026
Source: NVD
CVE-2026-3476 HIGH - 7.8

A Code Injection vulnerability affecting in SOLIDWORKS Desktop from Release 2025 through Release 2026 could allow an attacker to execute arbitrary code on the user's machine while opening a specially crafted file.

Published: Mar 16, 2026
Source: NVD
CVE-2026-3086 HIGH - 7.8

GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depen...

Vendor: gstreamer
Product: gstreamer
Published: Mar 16, 2026
Source: NVD
CVE-2026-3085 HIGH - 8.8

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depe...

Vendor: gstreamer
Product: gstreamer
Published: Mar 16, 2026
Source: NVD
CVE-2026-3084 HIGH - 7.8

GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may vary dependi...

Vendor: gstreamer
Product: gstreamer
Published: Mar 16, 2026
Source: NVD