Total CVEs

140,343

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,769
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,481 - 9,500 of 13,215 CVEs
CVE-2025-70030 HIGH - 7.5

An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

Published: Mar 09, 2026
Source: NVD
CVE-2025-62166 HIGH - 7.5

FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. Thi...

Vendor: FreshRSS
Product: FreshRSS
Published: Mar 09, 2026
Source: NVD
CVE-2026-30930 HIGH - 9.8

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string concatenation with unsanitized system monitoring data. The normalize() method wraps string values in single quotes but does not escape embedded single qu...

Vendor: pip
Product: Glances
Published: Mar 09, 2026
Source: GitHub
CVE-2026-30928 HIGH - 7.5

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file contains credentials for al...

Vendor: pip
Product: glances
Published: Mar 09, 2026
Source: GitHub
CVE-2026-30934 HIGH - 8.9

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/<hash> without context-aware escaping. The server uses text/templa...

Vendor: go
Product: github.com/gtsteffaniak/filebrowser
Published: Mar 09, 2026
Source: GitHub
CVE-2026-30933 HIGH - 7.5

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-s...

Vendor: go
Product: github.com/gtsteffaniak/filebrowser/backend
Published: Mar 09, 2026
Source: GitHub
CVE-2026-30140 HIGH - 7.5

An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive information disclosure and po...

Vendor: tenda
Product: w15e_firmware
Published: Mar 09, 2026
Source: NVD
CVE-2026-30926 HIGH - 7.1

SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the publish service of SiYuan Note that allows low-privilege publish accounts (RoleReader) to modify notebook content via the /api/block/appendHeadingChildren API endpoint. The endpoint ...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 09, 2026
Source: GitHub
CVE-2026-29023 HIGH - 7.3

Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled and exposed, allows network attackers to authenticate using the publicly known static key. An attacker able to reach the router port can proxy requests through the Shannon instance u...

Vendor: KeygraphHQ
Product: Shannon
Published: Mar 09, 2026
Source: NVD
CVE-2025-70038 HIGH - 8.8

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Twake v2023.Q1.1223. This allows attackers to execute arbitrary code.

Vendor: linagora
Product: twake
Published: Mar 09, 2026
Source: NVD
CVE-2025-70034 HIGH - 7.5

An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0.

Published: Mar 09, 2026
Source: NVD
CVE-2026-30920 HIGH - 8.6

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is authorized for t...

Vendor: npm
Product: @oneuptime/common
Published: Mar 09, 2026
Source: GitHub
CVE-2026-28513 HIGH - 8.5

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, the OIDC token endpoint rejects an authorization code only when both the client ID is wrong and the code is expired. This allows cross-client code exchange and expired code reuse. Th...

Vendor: go
Product: github.com/pocket-id/pocket-id/backend
Published: Mar 09, 2026
Source: GitHub
CVE-2026-28512 HIGH - 7.1

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to before 2.4.0, a flaw in callback URL validation allowed crafted redirect_uri values containing URL userinfo (@) to bypass legitimate callback pattern checks. If an attacker can trick a...

Vendor: go
Product: github.com/pocket-id/pocket-id/backend
Published: Mar 09, 2026
Source: GitHub
CVE-2026-3588 HIGH - 7.5

A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private keys by sending a crafted request.

Published: Mar 09, 2026
Source: NVD
CVE-2026-25866 HIGH - 7.8

MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable path when opening remote files. An attacker can exploit the search path behavior by placing a malicious executable earli...

Vendor: Mobatek
Product: MobaXterm
Published: Mar 09, 2026
Source: NVD
CVE-2025-70048 HIGH - 7.5

An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.

Vendor: nexus
Product: nexusinterface
Published: Mar 09, 2026
Source: NVD
CVE-2025-70047 HIGH - 7.5

An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta.2.

Vendor: nexus
Product: nexusinterface
Published: Mar 09, 2026
Source: NVD
CVE-2025-70250 HIGH - 7.5

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 09, 2026
Source: NVD
CVE-2025-70243 HIGH - 7.5

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard534.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 09, 2026
Source: NVD