Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,649
Quick preset (or use dates below)
Clear Filters
Showing 901 - 920 of 1,478 CVEs
CVE-2026-4835 LOW - 3.5

A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface. Such manipulation of the argument costumer_name leads to cross site scripting. The attack may be per...

Published: Mar 26, 2026
Source: NVD
CVE-2026-4833 LOW - 3.3

A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdown.c of the component Markdown Handler. This manipulation causes uncontrolled recursion. The attack is restricted to local execution. The exploit has been made available to the pub...

Published: Mar 26, 2026
Source: NVD
CVE-2026-4831 LOW - 3.7

A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler. Performing a manipulation results in improper authentication. The attack is possible...

Published: Mar 26, 2026
Source: NVD
CVE-2026-4823 LOW - 2.5

A flaw has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this vulnerability is an unknown functionality of the component NTLM2 Handler. Executing a manipulation can lead to information disclosure. The attack is restricted to local execution. Attacks of this nature are highly c...

Published: Mar 25, 2026
Source: NVD

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

Vendor: IBM
Product: InfoSphere Information Server
Published: Mar 25, 2026
Source: NVD

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's proxy controller does not limit the number of byte ranges in an HTTP Range header. A request with thousands of small ranges causes disproportionate...

Vendor: rubygems
Product: activestorage
Published: Mar 25, 2026
Source: GitHub

Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traversal vulnerability in the configuration import endpoint allows an authenticated user to write arbitrary files outside the config directory, which can lead to RCE by creating a plugi...

Vendor: go
Product: github.com/tobychui/zoraxy
Published: Mar 25, 2026
Source: GitHub

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.

Vendor: composer
Product: prestashop/prestashop
Published: Mar 25, 2026
Source: GitHub
CVE-2026-4363 LOW - 3.7

GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user to gain unauthorized access to resources due to improper caching of authorization decisions.

Vendor: gitlab
Product: gitlab
Published: Mar 25, 2026
Source: NVD

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.4. A document may be written to a temporary file when using print preview.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD

This issue was addressed with improved permissions checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4, watchOS 26.4. A local attacker may gain access to user's Keychain items.

Vendor: Apple
Product: iOS and iPadOS, macOS, visionOS, watchOS
Published: Mar 25, 2026
Source: NVD

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypass Gatekeeper checks.

Vendor: Apple
Product: macOS
Published: Mar 25, 2026
Source: NVD

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54, an attacker who obtains a user's password and a single MFA recovery code can reuse that recovery code an unlimited number of times by sending conc...

Vendor: parse-community
Product: parse-server
Published: Mar 24, 2026
Source: NVD

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they cannot view and still receive editor response data...

Vendor: craftcms
Product: cms
Published: Mar 24, 2026
Source: NVD

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive a valid transform URL, and fetch transformed image bytes. Th...

Vendor: craftcms
Product: cms
Published: Mar 24, 2026
Source: NVD

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In version 4.39.15, an attacker may potentially be able to inject javascript into the Authelia login page if several conditions are met s...

Vendor: go
Product: github.com/authelia/authelia/v4
Published: Mar 24, 2026
Source: GitHub

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. ...

Vendor: F5
Product: NGINX Open Source, NGINX Plus
Published: Mar 24, 2026
Source: NVD
CVE-2026-4626 LOW - 3.5

A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the publ...

Published: Mar 24, 2026
Source: NVD
CVE-2026-4616 LOW - 2.4

A security flaw has been discovered in bolo-blog κΉŒμ§€ 2.6.4. The affected element is an unknown function of the file /console/article/ of the component Article Title Handler. Performing a manipulation of the argument articleTitle results in cross site scripting. It is possible to initiate the attack r...

Published: Mar 24, 2026
Source: NVD

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully c...

Vendor: rails
Product: actionview
Published: Mar 23, 2026
Source: NVD