Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,765
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,201 - 9,220 of 13,211 CVEs
CVE-2026-32131 HIGH - 7.7

ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Management API has been reported, which allowed authenticated users holding a valid low-privilege token (e.g., project.read, project.grant.read, or project.app.read) to retrieve manag...

Vendor: zitadel
Product: zitadel
Published: Mar 11, 2026
Source: NVD
CVE-2026-32130 HIGH - 7.5

ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a System for Cross-domain Identity Management (SCIM) API to provision users from external providers into Zitadel. Request to the API with URL-encoded path values were correctly routed but...

Vendor: zitadel
Product: zitadel
Published: Mar 11, 2026
Source: NVD
CVE-2026-32117 HIGH - 7.6

The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor privileges can set the ...

Vendor: ekacnet
Product: grafanacubism-panel
Published: Mar 11, 2026
Source: NVD
CVE-2026-32127 HIGH - 8.8

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vulnerability in the ajax graphs library that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input va...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32126 HIGH - 7.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be enforced only for controllers that already have their own internal authorizatio...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32123 HIGH - 7.7

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for group encounters are broken because the code only consults form_encounter for sensitivity, while group encounters store sensitivity in form_groups_encount...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32121 HIGH - 7.7

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, Stored XSS in prescription CSS/HTML print view via patient demographics. That finding involves server-side rendering of patient names via raw PHP echo. This finding involves cl...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32110 HIGH - 8.3

SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenticated users to make arbitrary HTTP requests from the server. The endpoint accepts a user-controlled URL and makes HTTP requests to it, returning the full response body and headers....

Vendor: siyuan-note
Product: siyuan
Published: Mar 11, 2026
Source: NVD
CVE-2026-32102 HIGH - 6.5

OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-action authorization. A low-privileged authenticated user can rece...

Vendor: OliveTin
Product: OliveTin
Published: Mar 11, 2026
Source: NVD
CVE-2026-32101 HIGH - 7.6

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.3.1, the S3 storage manager's isAuthorized() function is declared async (returns Promise<boolean>) but is called without await in both the POST and PUT handlers. Since a Promise object is alw...

Vendor: @studiocms
Product: s3-storage
Published: Mar 11, 2026
Source: NVD
CVE-2026-2368 HIGH - 7.1

An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code.

Published: Mar 11, 2026
Source: NVD
CVE-2026-1716 HIGH - 7.1

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to delete arbitrary registry keys with elevated privileges.

Published: Mar 11, 2026
Source: NVD
CVE-2026-1715 HIGH - 7.1

An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiying that could allow a local authenticated user to modify arbitrary registry keys with elevated privileges.

Published: Mar 11, 2026
Source: NVD
CVE-2026-32097 HIGH - 8.8

PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticated user may be able to retrieve or delete files outside the intended authorization scope. This issue could result in retrieval or deletion of private files, including user-uploaded...

Vendor: comppolicylab
Product: pingpong
Published: Mar 11, 2026
Source: NVD
CVE-2026-31979 HIGH - 8.8

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc_<uid> without symlink protections. Since commit 87a51ee, PrivateTmp is explicitly removed from...

Vendor: himmelblau-idm
Product: himmelblau
Published: Mar 11, 2026
Source: NVD
CVE-2026-31958 HIGH - 7.5

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility...

Vendor: tornadoweb
Product: tornado
Published: Mar 11, 2026
Source: NVD
CVE-2026-31895 HIGH - 8.8

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in html/matPat/restaurar_produto.php. The id_produto parameter from $_GET is directly interpolated into SQL queries without param...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Mar 11, 2026
Source: NVD
CVE-2026-31894 HIGH - 7.5

WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP's PharData class, then uses glob() and file_get_contents() to read SQL files from the extracted contents. Neither the extraction nor the file read...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Mar 11, 2026
Source: NVD
CVE-2026-27703 HIGH - 7.5

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. In 2026.01 and earlier, the default handler for the well_known_core resource coap_well_known_core_default_handler writes user-provided option da...

Vendor: RIOT-OS
Product: RIOT
Published: Mar 11, 2026
Source: NVD
CVE-2026-31889 HIGH - 8.9

Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow used HMAC‑based authe...

Vendor: composer
Product: shopware/platform
Published: Mar 11, 2026
Source: GitHub