Total CVEs

140,339

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,774
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,361 - 9,380 of 13,215 CVEs
CVE-2026-3845 HIGH - 8.8

Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android. This vulnerability affects Firefox < 148.0.2.

Vendor: mozilla
Product: firefox
Published: Mar 10, 2026
Source: NVD
CVE-2026-3483 HIGH - 7.8

An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.

Vendor: ivanti
Product: desktop_\&_server_management
Published: Mar 10, 2026
Source: NVD
CVE-2026-31796 HIGH - 7.8

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow in icCurvesFromXml() causing heap memory corruption or crash. This vulnerability is fixed in 2.3.1.5.

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 10, 2026
Source: NVD
CVE-2026-31795 HIGH - 7.8

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack buffer overflow write in CIccXform3DLut::Apply() corrupting stack memory or crash. This vulnerability is fixed in 2.3.1.5.

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 10, 2026
Source: NVD
CVE-2026-31792 HIGH - 7.8

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a null pointer dereference in CIccTagXmlStruct::ParseTag() causing a segmentation fault or denial of service. This vulnerability is fixed in 2.3.1.5.

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 10, 2026
Source: NVD
CVE-2026-30987 HIGH - 7.8

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack buffer overflow in CIccTagNum<>::GetValues() causing stack memory corruption or crash. This vulnerability is fixed in 2.3.1.5.

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 10, 2026
Source: NVD
CVE-2026-30985 HIGH - 7.8

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow write in CIccMatrixMath::SetRange() causing memory corruption or crash. This vulnerability is fixed in 2.3.1.5.

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 10, 2026
Source: NVD
CVE-2026-30983 HIGH - 7.8

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack buffer overflow in icFixXml() (strcpy) causing stack memory corruption or crash. This vulnerability is fixed in 2.3.1.5.

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 10, 2026
Source: NVD
CVE-2026-30979 HIGH - 7.8

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-based buffer overflow in CIccCalculatorFunc::InitSelectOp() triggered with local user interaction causing memory corruption/crash. This vulnerability is fixed in 2.3.1.5.

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 10, 2026
Source: NVD
CVE-2026-30978 HIGH - 7.8

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a heap-use-after-free in CIccCmm::AddXform() causing invalid vptr dereference and crash. This vulnerability is fixed in 2.3.1.5.

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Mar 10, 2026
Source: NVD
CVE-2026-30958 HIGH - 7.2

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The componentName route parameter is concatenated directly into a file pat...

Vendor: OneUptime
Product: oneuptime
Published: Mar 10, 2026
Source: NVD
CVE-2026-30945 HIGH - 7.1

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user with editor privileges or above to revoke API tokens belonging to any other user, including admin and owner acc...

Vendor: withstudiocms
Product: studiocms
Published: Mar 10, 2026
Source: NVD
CVE-2026-30944 HIGH - 8.8

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user (at least Editor) to generate API tokens for any other user, including owner and admin accounts. The endpoint fails to...

Vendor: withstudiocms
Product: studiocms
Published: Mar 10, 2026
Source: NVD
CVE-2026-30941 HIGH - 7.5

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1, NoSQL injection vulnerability allows an unauthenticated attacker to inject MongoDB query operators via the token field in the password reset and email verificati...

Vendor: parse-community
Product: parse-server
Published: Mar 10, 2026
Source: NVD
CVE-2026-2724 HIGH - 7.2

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2.0.5. This is due to insufficient input sanitization and output escaping on form submission data displayed in the admin Form Entries...

Published: Mar 10, 2026
Source: NVD
CVE-2026-2339 HIGH - 7.5

Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion, Privilege Abuse, Command Injection.This issue affects Liderahenk: before v3.4.0.

Published: Mar 10, 2026
Source: NVD
CVE-2026-26738 HIGH - 7.8

Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary code via a crafted .sns snapshot file.

Published: Mar 10, 2026
Source: NVD
CVE-2026-26148 HIGH - 8.1

External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.

Vendor: microsoft
Product: azure_ad_ssh_login_extension_for_linux
Published: Mar 10, 2026
Source: NVD
CVE-2026-26144 HIGH - 7.5

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: 365_apps
Published: Mar 10, 2026
Source: NVD
CVE-2026-26141 HIGH - 7.8

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

Vendor: microsoft
Product: azure_automation_hybrid_worker_windows_extension
Published: Mar 10, 2026
Source: NVD