Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 8,861 - 8,880 of 13,058 CVEs
CVE-2026-28520 HIGH - 8.4

arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. When the victim's smart hardware connects to an attacker-controlled AP hotspot, the attacker can exploit the overflow to execute arbitrary code on the affected embedded device.

Vendor: Tuya
Product: arduino-TuyaOpen
Published: Mar 16, 2026
Source: NVD
CVE-2026-28519 HIGH - 8.8

arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An attacker on the same local area network who controls the LAN DNS server can send malicious DNS responses to overflow the heap buffer, potentially allowing execution of arbitrary c...

Vendor: Tuya
Product: arduino-TuyaOpen
Published: Mar 16, 2026
Source: NVD
CVE-2026-26133 HIGH - 7.1

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Published: Mar 16, 2026
Source: NVD
CVE-2026-25083 HIGH - 8.3

GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or tamper the other user's threads/messages.

Vendor: GROWI, Inc.
Product: GROWI
Published: Mar 16, 2026
Source: NVD
CVE-2026-24458 HIGH - 7.5

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Mattermost Advisory ID: MMSA-2026-00587

Vendor: Mattermost
Product: Mattermost
Published: Mar 16, 2026
Source: NVD
CVE-2026-20990 HIGH - 8.1

Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Mar 16, 2026
Source: NVD
CVE-2026-1947 HIGH - 7.5

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the submit_nex_form() function due to missing validation on a user controlled key. This makes it possible for unauthenticated att...

Published: Mar 16, 2026
Source: NVD
CVE-2025-69240 HIGH - 8.8

Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker (who knows the victim's email address) can force the server to send an email with password reset link pointing to the domain from spoofed header. When victim clicks the link, ...

Vendor: Raytha
Product: Raytha
Published: Mar 16, 2026
Source: NVD
CVE-2025-54920 HIGH - 8.8

This issue affects Apache Spark: before 3.5.7 and 4.0.1. Users are recommended to upgrade to version 3.5.7 or 4.0.1 and above, which fixes the issue. Summary Apache Spark 3.5.4 and earlier versions contain a code execution vulnerability in the Spark History Web UI due to overly permissive Jack...

Vendor: Apache Software Foundation
Product: Apache Spark
Published: Mar 16, 2026
Source: NVD
CVE-2025-15540 HIGH - 8.8

"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to application. Due to a lack of sandboxing or access restrictions, JavaScript code executed through Raytha’s “functions” feature can instantiate .NET components and perform arbitrary operati...

Vendor: Raytha
Product: Raytha
Published: Mar 16, 2026
Source: NVD
CVE-2025-14287 HIGH - 7.5

A command injection vulnerability exists in mlflow/mlflow versions before v3.7.0, specifically in the `mlflow/sagemaker/__init__.py` file at lines 161-167. The vulnerability arises from the direct interpolation of user-supplied container image names into shell commands without proper sanitization, w...

Vendor: mlflow
Product: mlflow/mlflow
Published: Mar 16, 2026
Source: NVD
CVE-2017-20222 HIGH - 7.5

Telesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger device reboot without authentication. Attackers can send POST requests to the lte.cgi endpoint with the Command=Reboot parameter to cause denial of serv...

Vendor: Telesquare
Product: SDT-CS3B1
Published: Mar 16, 2026
Source: NVD
CVE-2017-20220 HIGH - 7.5

Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the mediabrowser login password. Attackers can send specially crafted requests to the REST API endpoints to modify credentials without authentication.

Vendor: Serviio
Product: Serviio PRO
Published: Mar 16, 2026
Source: NVD
CVE-2017-20218 HIGH - 7.8

Serviio PRO 1.8 contains an unquoted search path vulnerability in the Windows service that allows local users to execute arbitrary code with elevated privileges by placing malicious executables in the system root path. Additionally, improper directory permissions with full access for the Users group...

Vendor: Serviio
Product: Serviio PRO
Published: Mar 16, 2026
Source: NVD
CVE-2017-20217 HIGH - 7.5

Serviio PRO 1.8 contains an information disclosure vulnerability due to improper access control enforcement in the Configuration REST API that allows unauthenticated attackers to access sensitive information. Remote attackers can send specially crafted requests to the REST API endpoints to retrieve ...

Vendor: Serviio
Product: Serviio PRO
Published: Mar 16, 2026
Source: NVD
CVE-2016-20034 HIGH - 8.8

Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUse...

Vendor: Wowza Media Systems, LLC.
Product: Wowza Streaming Engine
Published: Mar 16, 2026
Source: NVD
CVE-2016-20033 HIGH - 7.8

Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the mana...

Vendor: Wowza Media Systems, LLC.
Product: Wowza Streaming Engine
Published: Mar 16, 2026
Source: NVD
CVE-2016-20032 HIGH - 7.2

ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious payloads through the 'holiday_name' and 'memo' POST parameters. Attackers can submit crafted requests ...

Vendor: ZKTeco Inc.
Product: ZKTeco ZKAccess Security System
Published: Mar 16, 2026
Source: NVD
CVE-2016-20025 HIGH - 8.8

ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users to escalate privileges by modifying executable files. Attackers can leverage the Modify permission granted to the Authenticated Users group to replace executable binaries with malic...

Vendor: ZKTeco Inc.
Product: ZKTeco ZKAccess Professional
Published: Mar 16, 2026
Source: NVD
CVE-2015-20121 HIGH - 8.2

Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting arbitrary SQL code through the GET parameter 'u_id' in /admin/users.php and the POST parameter 'agent[]' in /admin/mailer...

Vendor: Next Click Ventures
Product: RealtyScripts
Published: Mar 16, 2026
Source: NVD