Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,621 - 9,640 of 13,221 CVEs
CVE-2026-30229 HIGH - 7.2

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.6 and 9.5.0-alpha.4, the readOnlyMasterKey can call POST /loginAs to obtain a valid session token for any user. This allows a read-only credential to impersonate arbitrary us...

Vendor: npm
Product: parse-server
Published: Mar 06, 2026
Source: GitHub
CVE-2026-30834 HIGH - 7.5

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, a Server-Side Request Forgery (SSRF) vulnerability in the /download endpoint allows any user with API access to induce the PinchTab server to make requests to arbitrary URLs, inclu...

Vendor: go
Product: github.com/pinchtab/pinchtab/cmd/pinchtab
Published: Mar 06, 2026
Source: GitHub
CVE-2026-30827 HIGH - 7.5

express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to versions 8.0.2, 8.1.1, 8.2.2, and 8.3.0, the default keyGenerator in express-rate-limit applies IPv6 subnet masking (/56 by default) to all addresses that net.isIPv6() returns true for. T...

Vendor: npm
Product: express-rate-limit
Published: Mar 06, 2026
Source: GitHub
CVE-2026-29089 HIGH - 8.8

TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From version 2.23.0 to 2.25.1, PostgreSQL uses the search_path setting to locate unqualified database objects (tables, functions, operators). If the search_path includes user-writable sch...

Vendor: timescale
Product: timescaledb
Published: Mar 06, 2026
Source: NVD

The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter expansion patterns. An attacker who can influence the commands executed by the agent (e.g., via prompt injection through repository files, MCP server res...

Vendor: github
Product: copilot-cli
Published: Mar 06, 2026
Source: NVD
CVE-2026-29082 HIGH - 7.3

Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestraโ€™s execution-file preview renders user-supplied Markdown (.md) with markdown-it instantiated as html:true and injects the resulting HTML with Vueโ€™s v-html without sanitisation. At time of publication, there ar...

Vendor: kestra-io
Product: kestra
Published: Mar 06, 2026
Source: NVD
CVE-2026-29075 HIGH - 8.3

Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been patched via commit c...

Vendor: mesa
Product: mesa
Published: Mar 06, 2026
Source: NVD
CVE-2026-29064 HIGH - 8.2

Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write...

Vendor: zarf-dev
Product: zarf
Published: Mar 06, 2026
Source: NVD
CVE-2025-70363 HIGH - 7.5

Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated attackers to access sensitive data via enumerating object IDs.

Published: Mar 06, 2026
Source: NVD
CVE-2025-15602 HIGH - 8.8

Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, including the Super...

Vendor: Grokability, Inc.
Product: Snipe-IT
Published: Mar 06, 2026
Source: NVD
CVE-2026-27764 HIGH - 7.3

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connecti...

Vendor: Mobiliti
Product: e-mobi.hu
Published: Mar 06, 2026
Source: NVD
CVE-2026-26018 HIGH - 7.5

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseud...

Vendor: coredns
Product: coredns
Published: Mar 06, 2026
Source: NVD
CVE-2026-26017 HIGH - 7.7

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of...

Vendor: coredns
Product: coredns
Published: Mar 06, 2026
Source: NVD
CVE-2026-24696 HIGH - 7.5

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain una...

Vendor: Everon
Product: api.everon.io
Published: Mar 06, 2026
Source: NVD
CVE-2026-20882 HIGH - 7.5

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain una...

Vendor: Mobiliti
Product: e-mobi.hu
Published: Mar 06, 2026
Source: NVD
CVE-2026-20748 HIGH - 7.3

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connecti...

Vendor: Everon
Product: api.everon.io
Published: Mar 06, 2026
Source: NVD
CVE-2026-2754 HIGH - 7.5

Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote attacker with network access to the device can execute HTTP GET requests to TCP port 8080 to retrieve internal network parameters including ECDIS & OT...

Published: Mar 06, 2026
Source: NVD
CVE-2026-2753 HIGH - 7.5

An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to properly sanitize user-supplied path input. Unauthenticated remote attackers can exploit this issue by submitting requests containing absolute filesystem paths. Successful exploita...

Published: Mar 06, 2026
Source: NVD
CVE-2018-25199 HIGH - 8.2

OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parame...

Vendor: Zsoft
Product: OOP CMS BLOG
Published: Mar 06, 2026
Source: NVD
CVE-2018-25197 HIGH - 8.2

PlayJoom 0.10.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with option=com_playjoom&view=genre&catid=[SQL] to extract sens...

Vendor: Playjoom
Product: PlayJoom
Published: Mar 06, 2026
Source: NVD