Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,765
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,221 - 9,240 of 13,211 CVEs
CVE-2026-31887 HIGH - 7.5

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 ...

Vendor: shopware
Product: core, platform
Published: Mar 11, 2026
Source: NVD
CVE-2026-31881 HIGH - 7.7

Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-reset request is active, resulting in full account takeover. The endpoint POST /api/auth/reset-password is exposed without authentication/authorization c...

Vendor: runtipi
Product: runtipi
Published: Mar 11, 2026
Source: NVD
CVE-2019-25486 HIGH - 8.2

Varient 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user_id parameter. Attackers can submit POST requests with crafted SQL payloads in the user_id field to bypass authentication and extract sensi...

Vendor: Varient
Product: Varient SQL Inj.
Published: Mar 11, 2026
Source: NVD
CVE-2019-25483 HIGH - 8.4

Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k contains a restricted shell escape vulnerability that allows local users to bypass command restrictions by using the command substitution operator $( ). Attackers can inject arbitrary commands through the $( ) syntax when passed as arguments to allo...

Vendor: Comtrend
Product: AR-5310
Published: Mar 11, 2026
Source: NVD
CVE-2019-25480 HIGH - 7.5

ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulating the file parameter with path traversal sequences. Attackers can upload PHP files with traversal payloads ../public_html/ to write executable code to...

Vendor: ARMBot
Product: ARMBot
Published: Mar 11, 2026
Source: NVD
CVE-2019-25478 HIGH - 7.5

GetGo Download Manager 6.2.2.3300 contains a buffer overflow vulnerability that allows remote attackers to cause denial of service by sending HTTP responses with excessively long headers. Attackers can craft malicious HTTP responses with oversized header values to crash the application and make it u...

Vendor: Getgosoft
Product: GetGo Download Manager
Published: Mar 11, 2026
Source: NVD
CVE-2019-25472 HIGH - 7.5

IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read se...

Vendor: Intelbras
Product: Telefone IP TIP 200, Telefone IP TIP 200 LITE
Published: Mar 11, 2026
Source: NVD
CVE-2019-25470 HIGH - 7.5

eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with minimal privileges to retrieve sensitive user data by exploiting the wsdReadForm endpoint. Attackers can send POST requests to /wrcgi.bin/wsdReadForm with base64-encoded partial credentials ...

Vendor: eWON
Product: eWON
Published: Mar 11, 2026
Source: NVD
CVE-2019-25467 HIGH - 8.4

Verypdf docPrint Pro 8.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized alphanumeric encoded payload in the User Password or Master Password fields. Attackers can craft a malicious payload with en...

Vendor: Verypdf
Product: docPrint Pro
Published: Mar 11, 2026
Source: NVD
CVE-2019-25466 HIGH - 8.4

Easy File Sharing Web Server 7.2 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by creating a malicious username. Attackers can craft a username with a payload containing 4059 bytes of padding followed by a nseh valu...

Vendor: Sharing-File
Product: Easy File Sharing Web Server
Published: Mar 11, 2026
Source: NVD
CVE-2019-25465 HIGH - 7.5

Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by exploiting directory listing in the cgi-bin directory. Attackers can request the getadslattr.cgi endpoint to retrieve ADSL credentials and network ...

Vendor: Hisilicon
Product: HiIpcam
Published: Mar 11, 2026
Source: NVD
CVE-2026-31870 HIGH - 7.5

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib::stream::Post, etc.), the library calls std::stoull() directly on the Content-Length header value received from the serve...

Vendor: yhirose
Product: cpp-httplib
Published: Mar 11, 2026
Source: NVD
CVE-2026-20163 HIGH - 7.2

In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.124, a user who holds a role that contains the high-privilege capability `edit_cmd` could execute arbitrary shell commands using the `...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Mar 11, 2026
Source: NVD
CVE-2026-20074 HIGH - 7.4

A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. This vulnerability is due to insufficient input validation of ing...

Vendor: Cisco
Product: Cisco IOS XR Software
Published: Mar 11, 2026
Source: NVD
CVE-2026-20046 HIGH - 8.8

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerability is due to incorrect mapping of a command to task groups wi...

Vendor: Cisco
Product: Cisco IOS XR Software
Published: Mar 11, 2026
Source: NVD
CVE-2026-20040 HIGH - 8.8

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI c...

Vendor: Cisco
Product: Cisco IOS XR Software
Published: Mar 11, 2026
Source: NVD
CVE-2025-68623 HIGH - 8.8

In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file during the installation process, which may result in unintended elevation of privileges. During installation, the installer runs with HIGH integrity and downloads executables and DLLs...

Published: Mar 11, 2026
Source: NVD
CVE-2025-67037 HIGH - 8.8

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.

Published: Mar 11, 2026
Source: NVD
CVE-2025-67036 HIGH - 8.8

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.

Published: Mar 11, 2026
Source: NVD
CVE-2025-67034 HIGH - 8.8

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.

Published: Mar 11, 2026
Source: NVD