Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,800
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,041 - 9,060 of 13,211 CVEs
CVE-2026-32600 HIGH - 8.2

xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recov...

Vendor: composer
Product: simplesamlphp/xml-security
Published: Mar 13, 2026
Source: GitHub
CVE-2026-32314 HIGH - 7.5

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when processing a crafted inbound Data frame that sets SYN and uses a body length greater than DEFAULT_CREDIT (e.g. 262145). On the first packet of a new inbo...

Vendor: rust
Product: yamux
Published: Mar 13, 2026
Source: GitHub
CVE-2026-32313 HIGH - 8.2

xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the...

Vendor: composer
Product: robrichards/xmlseclibs
Published: Mar 13, 2026
Source: GitHub
CVE-2026-4111 HIGH - 7.5

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This c...

Published: Mar 13, 2026
Source: NVD

Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script project containing specially crafted filenames with directory traversal sequences.

Vendor: npm
Product: @google/clasp
Published: Mar 13, 2026
Source: NVD
CVE-2026-3910 HIGH - 8.8

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Mar 13, 2026
Source: NVD
CVE-2026-3909 HIGH - 8.8

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Mar 13, 2026
Source: NVD
CVE-2026-3873 HIGH - 7.2

Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Avantra: before 25.3.0.

Published: Mar 13, 2026
Source: NVD
CVE-2026-3045 HIGH - 7.5

The Appointment Booking Calendar โ€” Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a non-user-bound `public_nonce` is exposed to unauthenticated users...

Published: Mar 13, 2026
Source: NVD
CVE-2026-32597 HIGH - 7.5

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 ยง4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting ...

Vendor: jpadilla
Product: pyjwt
Published: Mar 13, 2026
Source: NVD
CVE-2026-32459 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in flycart UpsellWP checkout-upsell-and-order-bumps allows Blind SQL Injection.This issue affects UpsellWP: from n/a through <= 2.2.4.

Vendor: flycart
Product: UpsellWP
Published: Mar 13, 2026
Source: NVD
CVE-2026-32458 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 WOLF bulk-editor allows Blind SQL Injection.This issue affects WOLF: from n/a through <= 1.0.8.7.

Vendor: RealMag777
Product: WOLF
Published: Mar 13, 2026
Source: NVD
CVE-2026-32433 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-with-paypal allows Blind SQL Injection.This issue affects CP Contact Form with Paypal: from n/a through <= 1.3.61.

Vendor: codepeople
Product: CP Contact Form with Paypal
Published: Mar 13, 2026
Source: NVD
CVE-2026-32426 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Medilazar Core medilazar-core allows PHP Local File Inclusion.This issue affects Medilazar Core: from n/a through < 1.4.7.

Vendor: themelexus
Product: Medilazar Core
Published: Mar 13, 2026
Source: NVD
CVE-2026-32422 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Blind SQL Injection.This issue affects WP EasyCart: from n/a through <= 5.8.13.

Vendor: levelfourdevelopment
Product: WP EasyCart
Published: Mar 13, 2026
Source: NVD
CVE-2026-32418 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordy Meow Meow Gallery meow-gallery allows Blind SQL Injection.This issue affects Meow Gallery: from n/a through <= 5.4.4.

Vendor: Jordy Meow
Product: Meow Gallery
Published: Mar 13, 2026
Source: NVD
CVE-2026-32414 HIGH - 7.2

Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo-labels allows Remote Code Inclusion.This issue affects Advanced Woo Labels: from n/a through <= 2.36.

Vendor: ILLID
Product: Advanced Woo Labels
Published: Mar 13, 2026
Source: NVD
CVE-2026-32401 HIGH - 7.2

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <...

Vendor: BoldGrid
Product: Client Invoicing by Sprout Invoices
Published: Mar 13, 2026
Source: NVD
CVE-2026-32400 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemetechMount Boldman boldman allows PHP Local File Inclusion.This issue affects Boldman: from n/a through <= 7.7.

Vendor: ThemetechMount
Product: Boldman
Published: Mar 13, 2026
Source: NVD
CVE-2026-32399 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Blind SQL Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.32.

Vendor: David Lingren
Product: Media LIbrary Assistant
Published: Mar 13, 2026
Source: NVD