Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,788
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,681 - 9,700 of 13,224 CVEs
CVE-2026-29041 HIGH - 8.8

Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability caused by improper validation of uploaded files. The application relies solely on MIME-type verification when handling file uploads and does not adequate...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 06, 2026
Source: NVD
CVE-2025-59541 HIGH - 8.1

Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete projects inside a course without the victim’s consent. The issue arises because sensitive actions such as project deletion do not implement anti-CSRF prot...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 06, 2026
Source: NVD
CVE-2025-55289 HIGH - 8.8

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an attacker to inject arbitrary JavaScript into the platform’s social network and internal messaging features. When viewed by an authenticated user (includin...

Vendor: chamilo
Product: chamilo-lms
Published: Mar 06, 2026
Source: NVD
CVE-2026-3613 HIGH - 7.2

A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly availa...

Vendor: wavlink
Product: wl-nu516u1_firmware
Published: Mar 06, 2026
Source: NVD
CVE-2026-3612 HIGH - 7.2

A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA Online Upgrade. This manipulation of the argument firmware_url causes command injection. It is possible to initiate the attack remotely. The exploit ha...

Vendor: wavlink
Product: wl-nu516u1_firmware
Published: Mar 06, 2026
Source: NVD
CVE-2026-28727 HIGH - 7.8

Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124.

Vendor: Acronis
Product: Acronis Cyber Protect 17, Acronis Cyber Protect Cloud Agent
Published: Mar 06, 2026
Source: NVD
CVE-2026-28722 HIGH - 7.3

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

Vendor: Acronis
Product: Acronis Cyber Protect 17
Published: Mar 06, 2026
Source: NVD
CVE-2026-28721 HIGH - 7.3

Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

Vendor: Acronis
Product: Acronis Cyber Protect 17
Published: Mar 06, 2026
Source: NVD
CVE-2026-28713 HIGH - 7.1

Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build 41186.

Vendor: Acronis
Product: Acronis Cyber Protect Cloud Agent, Acronis Cyber Protect 17
Published: Mar 06, 2026
Source: NVD
CVE-2026-28710 HIGH - 8.1

Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

Vendor: Acronis
Product: Acronis Cyber Protect 17
Published: Mar 06, 2026
Source: NVD
CVE-2026-27778 HIGH - 7.5

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or mis-routing legitimate charger telemetry, or conduct brute-force attacks to gain una...

Vendor: ePower
Product: epower.ie
Published: Mar 06, 2026
Source: NVD
CVE-2026-24912 HIGH - 7.3

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enables session hijacking or shadowing, where the most recent connecti...

Vendor: ePower
Product: epower.ie
Published: Mar 06, 2026
Source: NVD
CVE-2025-11792 HIGH - 7.3

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 41124.

Vendor: Acronis
Product: Acronis Cyber Protect Cloud Agent
Published: Mar 06, 2026
Source: NVD
CVE-2026-26125 HIGH - 8.6

Payment Orchestrator Service Elevation of Privilege Vulnerability

Published: Mar 05, 2026
Source: NVD
CVE-2026-29613 HIGH - 7.5

OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing bypass of configured webhook passwords. When the gateway operate...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-29610 HIGH - 7.8

OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH environment variables through node-host execution or project-local bootstrapping. Attackers with authenticated access to node-host execution surfac...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-29609 HIGH - 7.5

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that allocates entire response payloads in memory before enforcing maxBytes limits. Remote attackers can trigger memory exhaustion by serving oversized responses without content-length heade...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28485 HIGH - 8.4

OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local callers to invoke privileged operations. Remote attackers on the local network or local processes can execute arbitrary browser-context act...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28479 HIGH - 7.5

OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations, which is deprecated and vulnerable to collision attacks. An attacker can exploit SHA-1 collisions to cause cache poisoning, allowing one sandbox configuration to be mis...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28478 HIGH - 7.5

OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or time limits. Remote unauthenticated attackers can send oversized JSON payloads or slow uploads to webhook endpoints causing memory pressure and availab...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD