Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 9,741 - 9,760 of 13,224 CVEs
CVE-2026-30798 HIGH - 7.5

Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation. This vulnerability is a...

Vendor: rustdesk-client
Product: RustDesk Client
Published: Mar 05, 2026
Source: NVD

xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32, the multi-level nested syntax caused a segmentation fault (core dumped). This issue has been patched in version 0.1.32.

Vendor: mlc-ai
Product: xgrammar
Published: Mar 05, 2026
Source: NVD
CVE-2026-27750 HIGH - 7.8

Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without revalidating the target ...

Vendor: Gen Digital Inc.
Product: Avira Internet Security
Published: Mar 05, 2026
Source: NVD
CVE-2026-27749 HIGH - 7.8

Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET BinaryFormatter without im...

Vendor: Gen Digital Inc.
Product: Avira Internet Security
Published: Mar 05, 2026
Source: NVD
CVE-2026-27748 HIGH - 7.8

Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM deletes a file under C:\\ProgramData without validating whether the path resolves through a symbolic link or reparse point. ...

Vendor: Gen Digital Inc.
Product: Avira Internet Security
Published: Mar 05, 2026
Source: NVD
CVE-2026-1720 HIGH - 8.8

The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the 'install_and_active_plugin' function in all versions up to, and including, 1....

Published: Mar 05, 2026
Source: NVD
CVE-2026-1605 HIGH - 7.5

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated for decompressing th...

Vendor: maven
Product: org.eclipse.jetty:jetty-server
Published: Mar 05, 2026
Source: NVD
CVE-2026-28548 HIGH - 7.1

Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Vendor: Huawei
Product: HarmonyOS, EMUI
Published: Mar 05, 2026
Source: NVD
CVE-2026-28542 HIGH - 7.3

Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.

Vendor: Huawei
Product: HarmonyOS, EMUI
Published: Mar 05, 2026
Source: NVD
CVE-2026-1321 HIGH - 8.1

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter without validating that t...

Published: Mar 05, 2026
Source: NVD
CVE-2026-25702 HIGH - 7.3

A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via nftables to not be effective.This issue affects SUSE Linux Enterprise Server: from 9e6d9d4601768c75fdb0bad3fbbe636e748939c2 before 9c294edb7085fb91650...

Vendor: SUSE
Product: SUSE Linux Enterprise Server
Published: Mar 05, 2026
Source: NVD
CVE-2026-28137 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Reflected XSS.This issue affects MediCenter - Health Medical Clinic: from n/a through <= 14.9.

Vendor: QuanticaLabs
Product: MediCenter - Health Medical Clinic
Published: Mar 05, 2026
Source: NVD
CVE-2026-28135 HIGH - 8.2

Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Royal Elementor Addons: from n/a through <= 1.7.1049.

Vendor: WP Royal
Product: Royal Elementor Addons
Published: Mar 05, 2026
Source: NVD
CVE-2026-28134 HIGH - 8.5

Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue affects JetEngine: from n/a through <= 3.7.2.

Vendor: Crocoblock
Product: JetEngine
Published: Mar 05, 2026
Source: NVD
CVE-2026-28133 HIGH - 8.1

Unrestricted Upload of File with Dangerous Type vulnerability in WP Chill Filr filr-protection allows Upload a Web Shell to a Web Server.This issue affects Filr: from n/a through <= 1.2.12.

Vendor: WP Chill
Product: Filr
Published: Mar 05, 2026
Source: NVD
CVE-2026-28130 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign u-design allows Reflected XSS.This issue affects UDesign: from n/a through <= 4.14.0.

Vendor: AndonDesign
Product: UDesign
Published: Mar 05, 2026
Source: NVD
CVE-2026-28129 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Little Birdies little-birdies allows PHP Local File Inclusion.This issue affects Little Birdies: from n/a through <= 1.3.16.

Vendor: axiomthemes
Product: Little Birdies
Published: Mar 05, 2026
Source: NVD
CVE-2026-28128 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Verse verse allows PHP Local File Inclusion.This issue affects Verse: from n/a through <= 1.7.0.

Vendor: ThemeREX
Product: Verse
Published: Mar 05, 2026
Source: NVD
CVE-2026-28127 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Lawyer Directory lawyer-directory allows Reflected XSS.This issue affects Lawyer Directory: from n/a through <= 1.3.2.

Vendor: e-plugins
Product: Lawyer Directory
Published: Mar 05, 2026
Source: NVD
CVE-2026-28126 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sizam RH Frontend Publishing Pro rh-frontend allows Reflected XSS.This issue affects RH Frontend Publishing Pro: from n/a through <= 4.3.2.

Vendor: sizam
Product: RH Frontend Publishing Pro
Published: Mar 05, 2026
Source: NVD