Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 8,921 - 8,940 of 13,059 CVEs
CVE-2026-31922 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fox-lms allows Blind SQL Injection.This issue affects Fox LMS: from n/a through <= 1.0.6.3.

Vendor: Ays Pro
Product: Fox LMS
Published: Mar 13, 2026
Source: NVD
CVE-2026-31917 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a through <= 1.16.10.

Vendor: weDevs
Product: WP ERP
Published: Mar 13, 2026
Source: NVD
CVE-2026-31899 HIGH - 7.5

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive <use> element amplification in cairosvg/defs.py. This causes CPU exhaustion from a small input.

Vendor: Kozea
Product: CairoSVG
Published: Mar 13, 2026
Source: NVD
CVE-2026-31814 HIGH - 7.5

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a specially crafted WindowUpdate can cause arithmetic overflow in send-window accounting, which triggers a panic in the connection state machine. This is remotely reachable over a normal ne...

Vendor: libp2p
Product: rust-yamux
Published: Mar 13, 2026
Source: NVD
CVE-2026-2890 HIGH - 7.5

The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Stripe PaymentIntent stat...

Published: Mar 13, 2026
Source: NVD
CVE-2026-2673 HIGH - 7.5

Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred grou...

Published: Mar 13, 2026
Source: NVD
CVE-2026-29079 HIGH - 7.5

Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are written into the element’s fields via an unsafe cast, corrupting the q...

Vendor: lexbor
Product: lexbor
Published: Mar 13, 2026
Source: NVD
CVE-2026-29078 HIGH - 7.5

Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary size variable between iterations. The statement ctx->buffer_used -= size with a stale size = 3 causes an integer underflow that wraps to SIZE_MAX. Afterwards, memcpy is called wi...

Vendor: lexbor
Product: lexbor
Published: Mar 13, 2026
Source: NVD
CVE-2026-25819 HIGH - 7.5

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unauthenticated attackers to cause a Denial of Service by using a specially crafted HTTP request that leads to a reboot of the device, provided they have a...

Published: Mar 13, 2026
Source: NVD
CVE-2026-25817 HIGH - 8.8

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have improper neutralization of special elements used in an OS command allowing remote code execution by attackers with low privilege access on the gateway, provi...

Published: Mar 13, 2026
Source: NVD
CVE-2026-25076 HIGH - 7.3

Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenticated attacker that is able to access the GraphQL API could execute arbitrary SQL instructions resulting in modifications to the data contained in the Anchore Enterprise database.

Vendor: Anchore
Product: Anchore Enterprise
Published: Mar 13, 2026
Source: NVD
CVE-2026-22202 HIGH - 8.1

wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to tr...

Vendor: gVectors
Product: wpDiscuz
Published: Mar 13, 2026
Source: NVD
CVE-2026-22193 HIGH - 8.1

wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers can inject malicious SQL code through email, activation_key, subscription_date, and imported_from parameters to manipulate...

Vendor: gVectors
Product: wpDiscuz
Published: Mar 13, 2026
Source: NVD
CVE-2026-22182 HIGH - 7.5

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdiscuz-ajax.php endpoint with arbitrary postId and comment_id par...

Vendor: gVectors
Product: wpDiscuz
Published: Mar 13, 2026
Source: NVD
CVE-2026-0957 HIGH - 7.8

There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted file in Digilent DASYLab.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted fil...

Vendor: ni
Product: dasylab
Published: Mar 13, 2026
Source: NVD
CVE-2026-0956 HIGH - 7.8

There is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent DASYLab.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted file...

Vendor: ni
Product: dasylab
Published: Mar 13, 2026
Source: NVD
CVE-2026-0955 HIGH - 7.8

There is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent DASYLab.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted file...

Vendor: ni
Product: dasylab
Published: Mar 13, 2026
Source: NVD
CVE-2026-0954 HIGH - 7.8

There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted DSB file in Digilent DASYLab.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted...

Vendor: ni
Product: dasylab
Published: Mar 13, 2026
Source: NVD
CVE-2025-71263 HIGH - 7.4

In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable having a fixed size of 100 bytes. A local user can exploit this to gain root privileges. It is unlikely that UNIX v4 is running anywhere outside of a very small number of ...

Vendor: AT&T Bell Labs
Product: UNIX
Published: Mar 13, 2026
Source: NVD
CVE-2025-13779 HIGH - 8.3

Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

Vendor: ABB
Product: AWIN GW100 rev.2, AWIN GW120
Published: Mar 13, 2026
Source: NVD