Total CVEs

140,339

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,769
Quick preset (or use dates below)
Clear Filters
Showing 881 - 900 of 1,473 CVEs
CVE-2026-4899 LOW - 2.4

A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /dbfood/food.php. The manipulation of the argument cuisines results in cross site scripting. It is possible to launch the attack remotely. The exploi...

Published: Mar 26, 2026
Source: NVD
CVE-2026-2271 LOW - 3.3

A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnerability in the read_creator_block() function by providing a specially crafted PSP image file. This vulnerability occurs when a 32-bit length value from the file is used for mem...

Published: Mar 26, 2026
Source: NVD
CVE-2026-2239 LOW - 2.8

A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pascal string is not properly null-terminated, leading to an out-of-bounds read wh...

Published: Mar 26, 2026
Source: NVD
CVE-2026-0968 LOW - 3.1

A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the hea...

Published: Mar 26, 2026
Source: NVD
CVE-2026-0967 LOW - 2.2

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expression backtracking. This can cause timeouts and resource exhaustion...

Vendor: libssh
Product: libssh
Published: Mar 26, 2026
Source: NVD
CVE-2026-0965 LOW - 3.3

A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to...

Vendor: libssh
Product: libssh
Published: Mar 26, 2026
Source: NVD
CVE-2026-3109 LOW - 2.2

Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584

Published: Mar 26, 2026
Source: NVD

HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available across the internet and craft attacks against the application.

Vendor: HCL
Product: Aftermarket DPC
Published: Mar 26, 2026
Source: NVD

HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout.

Vendor: HCL
Product: Aftermarket DPC
Published: Mar 26, 2026
Source: NVD

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an admin user.

Vendor: HCL
Product: Aftermarket DPC
Published: Mar 26, 2026
Source: NVD

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could...

Vendor: HCL
Product: Aftermarket DPC
Published: Mar 26, 2026
Source: NVD

HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details which would allow them to craft software specific attacks.

Vendor: HCL
Product: Aftermarket DPC
Published: Mar 26, 2026
Source: NVD

HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, an attacker may be able to execute arbitrary commands or inject harmful content into the response..

Vendor: HCL
Product: Aftermarket DPC
Published: Mar 26, 2026
Source: NVD

HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS, SQL Injection, Command Injection etc.

Vendor: HCL
Product: Aftermarket DPC
Published: Mar 26, 2026
Source: NVD
CVE-2026-4874 LOW - 3.1

A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session...

Vendor: redhat
Product: build_of_keycloak
Published: Mar 26, 2026
Source: NVD
CVE-2026-4835 LOW - 3.5

A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface. Such manipulation of the argument costumer_name leads to cross site scripting. The attack may be per...

Published: Mar 26, 2026
Source: NVD
CVE-2026-4833 LOW - 3.3

A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled recursion. The attack is restricted to local execution. The exploit has been made available to the pub...

Published: Mar 26, 2026
Source: NVD
CVE-2026-4831 LOW - 3.7

A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler. Performing a manipulation results in improper authentication. The attack is possible...

Published: Mar 26, 2026
Source: NVD
CVE-2026-4823 LOW - 2.5

A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTLM2 Handler. Executing a manipulation can lead to information disclosure. The attack is restricted to local execution. Attacks of this nature are highly c...

Published: Mar 25, 2026
Source: NVD

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

Vendor: IBM
Product: InfoSphere Information Server
Published: Mar 25, 2026
Source: NVD