Total CVEs

140,323

Critical Severity

3,747

High Severity

13,514

Last 7 Days

1,764
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,281 - 9,300 of 13,211 CVEs
CVE-2026-3453 HIGH - 8.1

The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing ownership validation on the change_plan_sub_id parameter in the process_checkout() function. The ppress_process_checkout AJAX handler accepts ...

Published: Mar 11, 2026
Source: NVD
CVE-2026-21361 HIGH - 8.1

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vvulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript ma...

Vendor: Adobe
Product: Adobe Commerce
Published: Mar 11, 2026
Source: NVD
CVE-2026-21311 HIGH - 8.0

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may...

Vendor: Adobe
Product: Adobe Commerce
Published: Mar 11, 2026
Source: NVD
CVE-2026-21309 HIGH - 7.5

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthoriz...

Vendor: Adobe
Product: Adobe Commerce
Published: Mar 11, 2026
Source: NVD
CVE-2026-21290 HIGH - 8.7

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may ...

Vendor: Adobe
Product: Adobe Commerce
Published: Mar 11, 2026
Source: NVD
CVE-2026-21289 HIGH - 7.5

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthoriz...

Vendor: Adobe
Product: Adobe Commerce
Published: Mar 11, 2026
Source: NVD
CVE-2026-21284 HIGH - 8.1

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may...

Vendor: Adobe
Product: Adobe Commerce
Published: Mar 11, 2026
Source: NVD
CVE-2026-31875 HIGH - 5.9

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled for a user account, Parse Server generates two single-use recovery codes. These codes are intended as ...

Vendor: npm
Product: parse-server
Published: Mar 11, 2026
Source: GitHub
CVE-2026-31872 HIGH - 7.5

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE clauses and sort parameters. An attacker can use dot-notation ...

Vendor: npm
Product: parse-server
Published: Mar 11, 2026
Source: GitHub
CVE-2026-31866 HIGH - 7.5

flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and gRPC (evaluation.v1, evaluation.v2) endpoints for feature flag evaluation. These endpoints are designed to be publicly accessible by client applications. The evaluation context in...

Vendor: go
Product: github.com/open-feature/flagd/flagd
Published: Mar 11, 2026
Source: GitHub
CVE-2026-31858 HIGH - 8.8

Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementIndexesController in CVE-2026-25495. The exact same SQL injection vulnerability (including criteria[orderBy], the original advisory vector) work...

Vendor: composer
Product: craftcms/cms
Published: Mar 11, 2026
Source: GitHub
CVE-2026-31861 HIGH - 8.8

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.24.0, The /api/user/git-config endpoint constructs shell commands by interpolating user-supplied gitName and gitEmail values into command strings passed to child_process.exec(). T...

Vendor: npm
Product: @siteboon/claude-code-ui
Published: Mar 10, 2026
Source: GitHub
CVE-2026-27272 HIGH - 7.8

Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Illustrator
Published: Mar 10, 2026
Source: NVD
CVE-2026-27271 HIGH - 7.8

Illustrator versions 29.8.4, 30.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Illustrator
Published: Mar 10, 2026
Source: NVD
CVE-2026-27267 HIGH - 7.8

Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Illustrator
Published: Mar 10, 2026
Source: NVD
CVE-2026-21362 HIGH - 7.8

Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Illustrator
Published: Mar 10, 2026
Source: NVD
CVE-2026-21333 HIGH - 8.6

Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendor: Adobe
Product: Illustrator
Published: Mar 10, 2026
Source: NVD
CVE-2026-31834 HIGH - 7.2

Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticated backoffice users with permission to manage users, may be able to elevate their privileges due to insufficient authoriza...

Vendor: umbraco
Product: Umbraco-CMS
Published: Mar 10, 2026
Source: NVD
CVE-2026-31830 HIGH - 7.5

sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.2.3, Sigstore::Verifier#verify does not propagate the VerificationFailure returned by verify_in_toto when the artifact digest does not match the digest in the in-toto attestation s...

Vendor: sigstore
Product: sigstore-ruby
Published: Mar 10, 2026
Source: NVD
CVE-2026-31829 HIGH - 7.1

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise exposes an HTTP Node in AgentFlow and Chatflow that performs server-side HTTP requests using user-controlled URLs. By default, there are no restrictions on target hosts, including pr...

Vendor: FlowiseAI
Product: Flowise
Published: Mar 10, 2026
Source: NVD