Total CVEs

140,343

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,765
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,501 - 9,520 of 13,215 CVEs
CVE-2025-70238 HIGH - 7.5

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.

Vendor: dlink
Product: dir-513_firmware
Published: Mar 09, 2026
Source: NVD
CVE-2025-70059 HIGH - 7.5

An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attackers to cause a denial of service.

Vendor: ymfe
Product: yapi
Published: Mar 09, 2026
Source: NVD
CVE-2026-3038 HIGH - 7.5

The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr structures into a sockaddr_storage structure on the stack. It assumes that the source sockaddr length field had already been validated, but this is not necessarily the case, and it&...

Published: Mar 09, 2026
Source: NVD
CVE-2026-2261 HIGH - 7.5

Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a certain number of leaked sockets is reached, blocklistd becomes unable to run the helper script: a child process is forked, but this child dereferences a null pointer and crashes befor...

Published: Mar 09, 2026
Source: NVD
CVE-2026-3818 HIGH - 7.3

A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebService/GetDBData.jsp. This manipulation of the argument strTBName causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. The vend...

Vendor: tiandy
Product: easy7_cms
Published: Mar 09, 2026
Source: NVD
CVE-2025-15576 HIGH - 7.5

If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may nonetheless be able to access a shared directory via a nullfs mount, if the administrator has configured one. In this cas...

Vendor: FreeBSD
Product: FreeBSD
Published: Mar 09, 2026
Source: NVD
CVE-2025-15547 HIGH - 8.8

By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesystems, subject to privilege checks. If a privileged user within a jail is able to nullfs-mount directories, a limitation of the kernel's path lookup...

Vendor: FreeBSD
Product: FreeBSD
Published: Mar 09, 2026
Source: NVD
CVE-2025-14769 HIGH - 7.5

In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule can then allow the traffic after the packet data is gone, resulting in a NULL pointer dereference. Maliciously crafted packets sent from a remote host m...

Vendor: FreeBSD
Product: FreeBSD
Published: Mar 09, 2026
Source: NVD
CVE-2025-14558 HIGH - 7.2

The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passed to resolvconf(8) unmodified. resolvconf(8) is a shell script which does not validate its input. A lack of quoting meant that shell commands pass a...

Vendor: FreeBSD
Product: FreeBSD
Published: Mar 09, 2026
Source: NVD
CVE-2026-3815 HIGH - 8.8

A weakness has been identified in UTT HiPER 810G up to 1.7.7-1711. This affects the function strcpy of the file /goform/formApMail. Executing a manipulation can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used ...

Vendor: utt
Product: 810g_firmware
Published: Mar 09, 2026
Source: NVD
CVE-2025-69219 HIGH - 8.8

A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likelihood of it making any damage is low. Y...

Vendor: Apache Software Foundation
Product: Apache Airflow Providers Http
Published: Mar 09, 2026
Source: NVD
CVE-2026-3814 HIGH - 8.8

A security flaw has been discovered in UTT HiPER 810G up to 1.7.7-1711. Affected by this issue is the function strcpy of the file /goform/getOneApConfTempEntry. Performing a manipulation results in buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the ...

Vendor: utt
Product: 810g_firmware
Published: Mar 09, 2026
Source: NVD
CVE-2026-3811 HIGH - 8.8

A vulnerability was found in Tenda FH1202 1.2.0.14(408). This impacts the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be use...

Vendor: tenda
Product: fh1202_firmware
Published: Mar 09, 2026
Source: NVD
CVE-2025-69279 HIGH - 7.5

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Vendor: Unisoc (Shanghai) Technologies Co., Ltd.
Product: T8100/T9100/T8200/T8300
Published: Mar 09, 2026
Source: NVD
CVE-2025-69278 HIGH - 7.5

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Vendor: Unisoc (Shanghai) Technologies Co., Ltd.
Product: T7300/T8100/T9100/T8200/T8300
Published: Mar 09, 2026
Source: NVD
CVE-2025-61616 HIGH - 7.5

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Vendor: Unisoc (Shanghai) Technologies Co., Ltd.
Product: T8100/T9100/T8200/T8300
Published: Mar 09, 2026
Source: NVD
CVE-2025-61615 HIGH - 7.5

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Vendor: Unisoc (Shanghai) Technologies Co., Ltd.
Product: T8100/T9100/T8200/T8300
Published: Mar 09, 2026
Source: NVD
CVE-2025-61614 HIGH - 7.5

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Vendor: Unisoc (Shanghai) Technologies Co., Ltd.
Product: T7300/T8100/T9100/T8200/T8300
Published: Mar 09, 2026
Source: NVD
CVE-2025-61613 HIGH - 7.5

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Vendor: Unisoc (Shanghai) Technologies Co., Ltd.
Product: T8100/T9100/T8200/T8300
Published: Mar 09, 2026
Source: NVD
CVE-2025-61612 HIGH - 7.5

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

Vendor: Unisoc (Shanghai) Technologies Co., Ltd.
Product: T7300/T8100/T9100/T8200/T8300
Published: Mar 09, 2026
Source: NVD