Total CVEs

141,537

Critical Severity

3,871

High Severity

13,923

Last 7 Days

1,618
Quick preset (or use dates below)
Clear Filters
Showing 9,861 - 9,880 of 14,444 CVEs
CVE-2026-30235 MEDIUM - 6.5

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to improper validation of OpenProject’s Markdown rendering, specifically in the hyperlink handling. This allows an attacker to inject malicious hyperlink payloads that perform DOM clo...

Vendor: opf
Product: openproject
Published: Mar 11, 2026
Source: NVD
CVE-2026-20166 MEDIUM - 5.4

In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, and 10.0.2503.12, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve the Observability Cloud API access token throug...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Mar 11, 2026
Source: NVD
CVE-2026-20165 MEDIUM - 6.3

In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.7, 10.1.2507.17, 10.0.2503.12, and 9.3.2411.124, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve sensitive informa...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Mar 11, 2026
Source: NVD
CVE-2026-20164 MEDIUM - 6.5

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, 10.0.2503.11, and 9.3.2411.123, a low-privileged user that does not hold the "admin" or "power" Splunk roles could access the `/splunkd/__raw...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Mar 11, 2026
Source: NVD
CVE-2026-20162 MEDIUM - 6.3

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform versions below 10.2.2510.4, 10.1.2507.15, 10.0.2503.11, and 9.3.2411.123, a low-privileged user who does not hold the "admin" or "power" Splunk roles could craft a malicious payload wh...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Mar 11, 2026
Source: NVD
CVE-2026-20118 MEDIUM - 6.8

A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series with NC57 line cards and Cisco NCS 5700 Routers and Cisco IOS XR Software for Third Party Software could allow an unauthentic...

Vendor: Cisco
Product: Cisco IOS XR Software
Published: Mar 11, 2026
Source: NVD
CVE-2026-20117 MEDIUM - 6.1

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management int...

Vendor: Cisco
Product: Cisco Unified Contact Center Express
Published: Mar 11, 2026
Source: NVD
CVE-2026-20116 MEDIUM - 6.1

A vulnerability in the web-based management interface of  Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an u...

Vendor: Cisco
Product: Cisco Unified Contact Center Express
Published: Mar 11, 2026
Source: NVD
CVE-2025-12555 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that, under certain conditions, could have allowed an authenticated user to access previous pipeline job information on projects with repository and CI/CD disable...

Vendor: GitLab
Product: GitLab
Published: Mar 11, 2026
Source: NVD
CVE-2026-3848 MEDIUM - 5.0

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to make unintended internal requests through proxy environments under certain conditions due to improper input valid...

Published: Mar 11, 2026
Source: NVD
CVE-2026-30234 MEDIUM - 6.5

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions can upload a crafted .bcf archive where the <Snapshot> value in markup.bcf is manipulated to contain an absolute or traversal local path (for examp...

Vendor: opf
Product: openproject
Published: Mar 11, 2026
Source: NVD
CVE-2026-28803 MEDIUM - 6.5

Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner receives an e-mail with instructions or a deep-link to start the cosign flow. The submission reference is communicated so that the user can retrieve the submission to be cosigned. At...

Vendor: open-formulieren
Product: open-forms
Published: Mar 11, 2026
Source: NVD
CVE-2026-1732 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose confidential issue titles due to improper filtering under certain circumstances.

Vendor: gitlab
Product: gitlab
Published: Mar 11, 2026
Source: NVD
CVE-2026-1663 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validation in the g...

Vendor: gitlab
Product: gitlab
Published: Mar 11, 2026
Source: NVD
CVE-2026-1230 MEDIUM - 4.1

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validati...

Vendor: gitlab
Product: gitlab
Published: Mar 11, 2026
Source: NVD
CVE-2026-0602 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, milestones, or commits due to improper filtering in...

Vendor: gitlab
Product: gitlab
Published: Mar 11, 2026
Source: NVD
CVE-2025-13690 MEDIUM - 6.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header names under certai...

Vendor: GitLab
Product: GitLab
Published: Mar 11, 2026
Source: NVD
CVE-2025-12576 MEDIUM - 6.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under certain conditions could have allowed an authenticated user to cause a denial of service due to improper handling of webhook response data.

Vendor: GitLab
Product: GitLab
Published: Mar 11, 2026
Source: NVD
CVE-2026-32229 MEDIUM - 6.8

In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled

Vendor: JetBrains
Product: Hub
Published: Mar 11, 2026
Source: NVD

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource can inject backtick-delimited rule tokens into Traefik's router rule language via unsanitized header or query parameter match values. In shared gateway deployments, this can ...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Mar 11, 2026
Source: GitHub