Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,800
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 9,101 - 9,120 of 13,211 CVEs
CVE-2026-32247 HIGH - 8.1

Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher injection vulnerability in shared search-filter construction for non-Kuzu backends. Attacker-controlled label values supplied through SearchFilters.node_labels ...

Vendor: getzep
Product: graphiti
Published: Mar 12, 2026
Source: NVD
CVE-2026-32246 HIGH - 8.5

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user's password but not their TOTP secret can obtai...

Vendor: steveiliop56
Product: tinyauth
Published: Mar 12, 2026
Source: NVD

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.

Vendor: qhkm
Product: zeptoclaw
Published: Mar 12, 2026
Source: NVD
CVE-2026-32231 HIGH - 8.2

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request body and applies authorization checks to those untrusted values. Because authentication is optional and defaults to disabled (auth_token: None),...

Vendor: qhkm
Product: zeptoclaw
Published: Mar 12, 2026
Source: NVD
CVE-2026-32138 HIGH - 8.2

NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vulnerability was identified where Firebase and Web3Forms API keys were exposed. An attacker could use these keys to interact with backend services wi...

Vendor: Stalin-143
Product: website
Published: Mar 12, 2026
Source: NVD
CVE-2025-70873 HIGH - 7.5

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

Published: Mar 12, 2026
Source: NVD
CVE-2026-32274 HIGH - 7.5

Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker who controls the value...

Vendor: pip
Product: black
Published: Mar 12, 2026
Source: GitHub
CVE-2026-32141 HIGH - 7.5

flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack ove...

Vendor: WebReflection
Product: flatted
Published: Mar 12, 2026
Source: NVD
CVE-2026-32140 HIGH - 8.8

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous JDBC properties, leading to remote code execution...

Vendor: dataease
Product: dataease
Published: Mar 12, 2026
Source: NVD
CVE-2026-32137 HIGH - 8.8

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user-controllable string, attackers can inject malicio...

Vendor: dataease
Product: dataease
Published: Mar 12, 2026
Source: NVD

soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (PoseidonSponge) accepts variable-length inputs without injective padding. When a caller provides fewer inputs than the sponge rate (inputs.len() < T - 1), unused rate positions ...

Vendor: stellar
Product: rs-soroban-poseidon
Published: Mar 12, 2026
Source: NVD
CVE-2026-32116 HIGH - 8.1

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wormhole receive) from a malicious party could result in overwriting critical local files, including ~/.ssh/authorized_keys and .bashrc. This co...

Vendor: magic-wormhole
Product: magic-wormhole
Published: Mar 12, 2026
Source: NVD
CVE-2026-26794 HIGH - 8.8

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via a crafted HTTP request.

Vendor: gl-inet
Product: ar300m16_firmware
Published: Mar 12, 2026
Source: NVD
CVE-2026-28793 HIGH - 8.4

Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path traversal, allowing attackers to read and write arbitrary files on the filesystem outside the intended media directory. When running tinacms dev, the C...

Vendor: @tinacms
Product: cli
Published: Mar 12, 2026
Source: NVD
CVE-2026-28791 HIGH - 7.4

Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload handler. The code at media.ts joins user-controlled path segments using path.join() without validating that the resulting path stays within the in...

Vendor: tinacms
Product: tinacms
Published: Mar 12, 2026
Source: NVD
CVE-2026-28356 HIGH - 7.5

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential backtracking (ReDoS) when parsing maliciously crafted HTTP or multi...

Vendor: defnull
Product: multipart
Published: Mar 12, 2026
Source: NVD
CVE-2026-27940 HIGH - 7.8

llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Using the subsequent fread() writes 528+ bytes of attacker-controlled data past the buffer boundary. Th...

Vendor: ggml-org
Product: llama.cpp
Published: Mar 12, 2026
Source: NVD
CVE-2026-25529 HIGH - 8.1

Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included in the admin interface. The primary way for unescaped data to be added is via the API's "send/raw" method. This could allow arbitrary HTM...

Vendor: postalserver
Product: postal
Published: Mar 12, 2026
Source: NVD
CVE-2026-21887 HIGH - 7.7

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, the OpenCTI platform’s data ingestion feature accepts user-supplied URLs without validation and uses the Axios HTTP client with its default configuration (allowAbsoluteUrls: true). T...

Vendor: OpenCTI-Platform
Product: opencti
Published: Mar 12, 2026
Source: NVD
CVE-2026-21672 HIGH - 8.8

A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

Vendor: Veeam
Product: Backup and Recovery
Published: Mar 12, 2026
Source: NVD