Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,581 - 9,600 of 13,221 CVEs
CVE-2026-3696 HIGH - 7.3

A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation results in os command injection. The attack can be initiated remotely. The exploit has bee...

Vendor: totolink
Product: n300rh_firmware
Published: Mar 08, 2026
Source: NVD
CVE-2026-3693 HIGH - 7.3

A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function get_user_info/update_user_info of the file /src/backend/agentchat/api/v1/user.py of the component User Endpoint. This manipulation of the argument user_id causes improper control of resource identifiers. It...

Published: Mar 08, 2026
Source: NVD
CVE-2026-3679 HIGH - 8.8

A vulnerability was identified in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex. Such manipulation of the argument mit_linktype/PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. The ex...

Vendor: tenda
Product: f451_firmware
Published: Mar 07, 2026
Source: NVD
CVE-2026-3678 HIGH - 8.8

A vulnerability was determined in Tenda FH451 1.0.0.9. Affected is the function sub_3C434 of the file /goform/AdvSetWan. This manipulation of the argument wanmode/PPPOEPassword causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed...

Vendor: tenda
Product: fh451_firmware
Published: Mar 07, 2026
Source: NVD
CVE-2026-3677 HIGH - 8.8

A vulnerability was found in Tenda FH451 1.0.0.9. This impacts the function fromSetCfm of the file /goform/setcfm. The manipulation of the argument funcname/funcpara1 results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

Vendor: tenda
Product: fh451_firmware
Published: Mar 07, 2026
Source: NVD
CVE-2026-29196 HIGH - 4.3

Netmaker makes networks with WireGuard. Prior to version 1.5.0, a user assigned the platform-user role can retrieve WireGuard private keys of all wireguard configs in a network by calling GET /api/extclients/{network} or GET /api/nodes/{network}. While the Netmaker UI restricts visibility, the API e...

Vendor: gravitl
Product: netmaker
Published: Mar 07, 2026
Source: NVD
CVE-2026-29779 HIGH - 7.5

UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377a596, configuration file uptime.config.ts exports both pageConfig (safe for client use) and workerConfig (server-only, contains sensitive data) from the same module. Due to pag...

Vendor: lyc8503
Product: UptimeFlare
Published: Mar 07, 2026
Source: NVD
CVE-2026-29194 HIGH - 8.1

Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validates host JWT tokens. When a route permits host authentication (hostAllowed=true), a valid host token bypasses all subsequent authorization checks without verifying that the host is ...

Vendor: gravitl
Product: netmaker
Published: Mar 07, 2026
Source: NVD
CVE-2026-28678 HIGH - 8.1

DSA Study Hub is an interactive educational web application. Prior to commit d527fba, the user authentication system in server/routes/auth.js was found to be vulnerable to Insufficiently Protected Credentials. Authentication tokens (JWTs) were stored in HTTP cookies without cryptographic protection ...

Vendor: toxicbishop
Product: DSA-with-tsx
Published: Mar 07, 2026
Source: NVD
CVE-2026-29067 HIGH - 8.1

ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password reset mechanism in login V2. ZITADEL utilizes the Forwarded or X-Forwarded-Host header from incoming requests to construct the URL for the password re...

Vendor: zitadel
Product: zitadel
Published: Mar 07, 2026
Source: NVD
CVE-2026-2219 HIGH - 7.5

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, which may result in denial of service (infinite loop spinning the CPU).

Published: Mar 07, 2026
Source: NVD
CVE-2026-24308 HIGH - 7.5

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential produc...

Vendor: Apache Software Foundation
Product: Apache ZooKeeper
Published: Mar 07, 2026
Source: NVD
CVE-2026-24281 HIGH - 7.4

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It's important to note that attacker ...

Vendor: Apache Software Foundation
Product: Apache ZooKeeper
Published: Mar 07, 2026
Source: NVD
CVE-2026-1074 HIGH - 7.2

The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in all versions up to, and including, 1.5. This is due to insufficient input sanitization and output escaping combined with a missing authorization check in the `App_Bar_Se...

Published: Mar 07, 2026
Source: NVD
CVE-2025-14675 HIGH - 7.2

The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. This makes it possible for authenticated attackers, with Contributor-level access and above, ...

Vendor: metabox
Product: Meta Box
Published: Mar 07, 2026
Source: NVD
CVE-2026-30840 HIGH - 8.8

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification testers. This issue has been patched in version 4.6.2.

Vendor: ellite
Product: Wallos
Published: Mar 07, 2026
Source: NVD
CVE-2026-30828 HIGH - 7.5

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been patched in version 4.6.2.

Vendor: ellite
Product: Wallos
Published: Mar 07, 2026
Source: NVD
CVE-2025-8899 HIGH - 8.8

The Paid Videochat Turnkey Site โ€“ HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.20. This is due to videowhisper_register_form() function not restricting user roles that can be set during registration. This makes it possibl...

Published: Mar 07, 2026
Source: NVD
CVE-2026-31900 HIGH - 9.8

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A malicious pull request could edit pyproject.toml to use a direct U...

Vendor: actions
Product: psf/black
Published: Mar 07, 2026
Source: GitHub
CVE-2026-3352 HIGH - 7.2

The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0.4 via the `update_wp_memory_constants()` method. This is due to insufficient input validation on the `wp_memory_limit` and `wp_max_memory_limit` settings before writing them to `w...

Published: Mar 07, 2026
Source: NVD