Total CVEs

140,315

Critical Severity

3,712

High Severity

13,361

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,881 - 8,900 of 13,058 CVEs
CVE-2015-20120 HIGH - 8.2

Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extract database information by injecting SQL code into application parameters. Attackers can craft requests with time-delay payloads to infer database cont...

Vendor: Next Click Ventures
Product: RealtyScript
Published: Mar 16, 2026
Source: NVD
CVE-2015-20118 HIGH - 7.2

Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name parameter of the admin locations interface. Attackers can submit POST requests to the locations.php endpoint with JavaScript payloads in the location_name field to execute arbitrary code ...

Vendor: Next Click Ventures
Product: RealtyScript
Published: Mar 16, 2026
Source: NVD
CVE-2015-20115 HIGH - 7.2

Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by oth...

Vendor: Next Click Ventures
Product: RealtyScript
Published: Mar 16, 2026
Source: NVD
CVE-2013-20006 HIGH - 7.5

Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly sanitized before being stored and returned to users. Attackers can inject malicious JavaScript code through parameters like 'title', 'nam...

Vendor: Qool
Product: Qool CMS
Published: Mar 16, 2026
Source: NVD

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). Prior to 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from a component to any other namespace. This breaks the security-by-d...

Vendor: go
Product: github.com/ctfer-io/monitoring
Published: Mar 13, 2026
Source: GitHub
CVE-2026-32640 HIGH - 9.8

SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modules through to direct access inside the sandbox. If the objects you've passed in as names to SimpleEval have modules or other disallowed / dangerou...

Vendor: pip
Product: simpleeval
Published: Mar 13, 2026
Source: GitHub

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20, a Cross-Site Scripting (XSS) vulnerability has been identified in the Angular runtime and compiler. It occurs when...

Vendor: npm
Product: @angular/core
Published: Mar 13, 2026
Source: GitHub
CVE-2026-32600 HIGH - 8.2

xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recov...

Vendor: composer
Product: simplesamlphp/xml-security
Published: Mar 13, 2026
Source: GitHub
CVE-2026-32314 HIGH - 7.5

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when processing a crafted inbound Data frame that sets SYN and uses a body length greater than DEFAULT_CREDIT (e.g. 262145). On the first packet of a new inbo...

Vendor: rust
Product: yamux
Published: Mar 13, 2026
Source: GitHub
CVE-2026-32313 HIGH - 8.2

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the...

Vendor: composer
Product: robrichards/xmlseclibs
Published: Mar 13, 2026
Source: GitHub
CVE-2026-4111 HIGH - 7.5

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This c...

Published: Mar 13, 2026
Source: NVD

Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequences.

Vendor: npm
Product: @google/clasp
Published: Mar 13, 2026
Source: NVD
CVE-2026-3910 HIGH - 8.8

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Mar 13, 2026
Source: NVD
CVE-2026-3909 HIGH - 8.8

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Mar 13, 2026
Source: NVD
CVE-2026-3873 HIGH - 7.2

Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Avantra: before 25.3.0.

Published: Mar 13, 2026
Source: NVD
CVE-2026-3045 HIGH - 7.5

The Appointment Booking Calendar โ€” Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a non-user-bound `public_nonce` is exposed to unauthenticated users...

Published: Mar 13, 2026
Source: NVD
CVE-2026-32597 HIGH - 7.5

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 ยง4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting ...

Vendor: jpadilla
Product: pyjwt
Published: Mar 13, 2026
Source: NVD
CVE-2026-32459 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Blind SQL Injection.This issue affects UpsellWP: from n/a through <= 2.2.4.

Vendor: flycart
Product: UpsellWP
Published: Mar 13, 2026
Source: NVD
CVE-2026-32458 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 WOLF bulk-editor allows Blind SQL Injection.This issue affects WOLF: from n/a through <= 1.0.8.7.

Vendor: RealMag777
Product: WOLF
Published: Mar 13, 2026
Source: NVD
CVE-2026-32433 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-with-paypal allows Blind SQL Injection.This issue affects CP Contact Form with Paypal: from n/a through <= 1.3.61.

Vendor: codepeople
Product: CP Contact Form with Paypal
Published: Mar 13, 2026
Source: NVD