Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,601 - 9,620 of 13,221 CVEs
CVE-2026-2020 HIGH - 7.5

The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This is due to the deserialization of untrusted input supplied via the 'included' parameter of the plugin's shor...

Published: Mar 07, 2026
Source: NVD
CVE-2025-14353 HIGH - 7.5

The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.2 via the 'zipcode' parameter. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL quer...

Vendor: presstigers
Product: ZIP Code Based Content Protection
Published: Mar 07, 2026
Source: NVD
CVE-2026-25071 HIGH - 7.5

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticated remote attackers to download device configuration files. Attackers can access this endpoint without credentials to ret...

Vendor: Anhui Seeker Electronic Technology Co., LTD.
Product: XikeStor SKS8310-8X
Published: Mar 07, 2026
Source: NVD
CVE-2026-30859 HIGH - 7.5

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control vulnerability in the database query tool allows any authenticated tenant to read sensitive data belonging to other tenants, including API keys, model ...

Vendor: go
Product: github.com/Tencent/WeKnora
Published: Mar 06, 2026
Source: GitHub
CVE-2026-30858 HIGH - 7.5

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a DNS rebinding vulnerability in the web_fetch tool allows an unauthenticated attacker to bypass URL validation and access internal resources on the server, including private ...

Vendor: go
Product: github.com/Tencent/WeKnora
Published: Mar 06, 2026
Source: GitHub
CVE-2026-30851 HIGH - 8.1

Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_auth copy_headers does not strip client-supplied headers, allowing identity injection and privilege escalation. This issue has been patched in version 2.11.2.

Vendor: go
Product: github.com/caddyserver/caddy/v2/modules/caddyhttp/reverseproxy
Published: Mar 06, 2026
Source: GitHub
CVE-2026-30824 HIGH - 9.8

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container management and token gene...

Vendor: npm
Product: flowise
Published: Mar 06, 2026
Source: GitHub
CVE-2026-30823 HIGH - 8.8

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.

Vendor: npm
Product: flowise
Published: Mar 06, 2026
Source: GitHub
CVE-2026-30822 HIGH - 7.7

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13.

Vendor: npm
Product: flowise
Published: Mar 06, 2026
Source: GitHub
CVE-2026-27142 HIGH - 7.5

Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with the value "refresh". A new GODEBUG setting has been added, htmlmetacontenturlescape, which can be used to disable escaping URLs i...

Vendor: Go standard library
Product: html/template
Published: Mar 06, 2026
Source: NVD
CVE-2026-27137 HIGH - 7.5

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

Vendor: Go standard library
Product: crypto/x509
Published: Mar 06, 2026
Source: NVD
CVE-2026-25679 HIGH - 7.5

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

Vendor: Go standard library
Product: net/url
Published: Mar 06, 2026
Source: NVD
CVE-2026-29788 HIGH - 7.5

TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, conversion of empty strings to null allows disguising DPA reports as genuine self-deletion reports. This issue has been pa...

Vendor: miraheze
Product: TSPortal
Published: Mar 06, 2026
Source: NVD
CVE-2026-30846 HIGH - 7.5

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication exposes all global webhook integrations—including sensitive url and token fields—without performing any authentication check on the server side. Although the subscription is normall...

Vendor: Wekan
Product: Wekan
Published: Mar 06, 2026
Source: NVD
CVE-2026-30845 HIGH - 8.2

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication in Wekan publishes all integration data for a board without any field filtering, exposing sensitive fields including webhook URLs and authentication tokens to any subscriber. Since...

Vendor: Wekan
Product: Wekan
Published: Mar 06, 2026
Source: NVD
CVE-2026-30844 HIGH - 8.1

Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forgery (SSRF) via attachment URL loading. During board import in Wekan, attachment URLs from user-supplied JSON data are fetched directly by the server without any URL validation or f...

Vendor: Wekan
Product: Wekan
Published: Mar 06, 2026
Source: NVD
CVE-2025-69654 HIGH - 7.5

A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` interpreter using the `-m` option and a low memory limit can cause an out-of-memory condition followed by an assertion failure in JS_FreeRuntime (list_...

Published: Mar 06, 2026
Source: NVD
CVE-2025-69650 HIGH - 7.5

GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may p...

Vendor: gnu
Product: binutils
Published: Mar 06, 2026
Source: NVD
CVE-2026-30821 HIGH - 9.8

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API. While the server validates uploads based on ...

Vendor: npm
Product: flowise
Published: Mar 06, 2026
Source: GitHub
CVE-2026-30820 HIGH - 8.8

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that sets the header x-request-from: internal, allowing an authenticated tenant session to bypass all /api/v1/** authorization checks. With only a brow...

Vendor: npm
Product: flowise
Published: Mar 06, 2026
Source: GitHub