Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,765
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,241 - 9,260 of 13,211 CVEs
CVE-2026-31892 HIGH - 8.1

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workflows can completely bypass all security settings defined in a WorkflowTemplate by including a podSpecPatch field in their...

Vendor: argoproj
Product: argo-workflows
Published: Mar 11, 2026
Source: NVD
CVE-2026-22248 HIGH - 8.0

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger its execution through an unsafe PHP instantiation....

Vendor: glpi-project
Product: glpi
Published: Mar 11, 2026
Source: NVD
CVE-2026-21888 HIGH - 7.5

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts 5-byte varints without bounds checks; reliably triggers OOB read / crash when built with ASan. This affects 0.24.6 and earlier.

Vendor: nanomq
Product: nanomq
Published: Mar 11, 2026
Source: NVD
CVE-2026-1090 HIGH - 8.7

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper saniti...

Vendor: gitlab
Product: gitlab
Published: Mar 11, 2026
Source: NVD
CVE-2026-1069 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.

Vendor: gitlab
Product: gitlab
Published: Mar 11, 2026
Source: NVD
CVE-2025-14513 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON pa...

Vendor: GitLab
Product: GitLab
Published: Mar 11, 2026
Source: NVD
CVE-2025-13929 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain c...

Vendor: GitLab
Product: GitLab
Published: Mar 11, 2026
Source: NVD
CVE-2026-30902 HIGH - 7.8

Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

Vendor: Zoom Communications Inc.
Product: Zoom Workplace
Published: Mar 11, 2026
Source: NVD
CVE-2026-30901 HIGH - 7.0

Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege via local access.

Vendor: Zoom Communications Inc.
Product: Zoom Rooms
Published: Mar 11, 2026
Source: NVD
CVE-2026-30900 HIGH - 7.8

Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

Vendor: Zoom Communications Inc.
Product: Zoom Workplace
Published: Mar 11, 2026
Source: NVD
CVE-2025-70027 HIGH - 7.5

An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This allows attackers to obtain sensitive information

Published: Mar 11, 2026
Source: NVD
CVE-2025-67298 HIGH - 8.1

An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile

Published: Mar 11, 2026
Source: NVD
CVE-2026-31857 HIGH - 8.8

Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled string input through renderObjectTemplate() -- an unsandboxed Tw...

Vendor: composer
Product: craftcms/cms
Published: Mar 11, 2026
Source: GitHub
CVE-2026-31839 HIGH - 8.2

Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's digital confirmation workflow prior to v3.0.0. Hash-only validation trusted manifest hash fields that could be modified together with package content, allowing tampered ...

Vendor: npm
Product: @striae-org/striae
Published: Mar 11, 2026
Source: GitHub
CVE-2026-28229 HIGH - 7.5

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing tok...

Vendor: go
Product: github.com/argoproj/argo-workflows/v3
Published: Mar 11, 2026
Source: GitHub
CVE-2026-3496 HIGH - 7.5

The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it ...

Published: Mar 11, 2026
Source: NVD
CVE-2026-32063 HIGH - 7.1

OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generation where attacker-controlled environment values are not validated for CR/LF characters, allowing newline injection to break out of Environment= lines and inject arbitrary systemd d...

Vendor: openclaw
Product: openclaw
Published: Mar 11, 2026
Source: NVD
CVE-2026-32062 HIGH - 7.5

OpenClaw versions2026.2.21-2 prior to 2026.2.22 and @openclaw/voice-call versions 2026.2.21 prior to 2026.2.22 accept media-stream WebSocket upgrades before stream validation, allowing unauthenticated clients to establish connections. Remote attackers can hold idle pre-authenticated sockets open to ...

Vendor: openclaw
Product: openclaw, voice-call
Published: Mar 11, 2026
Source: NVD
CVE-2026-32060 HIGH - 8.8

OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the configured workspace directory. When apply_patch is enabled without filesystem sandbox containment, attackers can exploit crafted paths including dire...

Vendor: openclaw
Product: openclaw
Published: Mar 11, 2026
Source: NVD
CVE-2026-32059 HIGH - 8.8

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-flag checks via abbreviated options. Remote attackers can execute sort commands with abbreviated long options ...

Vendor: openclaw
Product: openclaw
Published: Mar 11, 2026
Source: NVD