Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 81 - 100 of 157 CVEs
CVE-2026-25744 MEDIUM - 6.5

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API accepts an `id` in the request body and treats it as an UPDATE. There is no verification that the vital belongs to the current patient or encounter. An ...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-25745 MEDIUM - 6.5

OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) updates by message/note ID only and does not verify that the message belongs to the current patient (or ...

Vendor: openemr
Product: openemr
Published: Mar 18, 2026
Source: NVD
CVE-2026-33067 MEDIUM - 9.0

SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template literals without HTML escaping. A malicious package author can inject arbitrary HTML/JavaScript into these fields, which executes automatically when any...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33066 MEDIUM - 9.0

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetSanitize(true), allowing raw HTML embedded in Markdown to pass through unmodified. The frontend then assigns the rendered HTML to innerHTML without any ...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 18, 2026
Source: GitHub
CVE-2026-32751 MEDIUM - 9.0

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via innerHTML without HTML escaping when processing renamenotebook WebSocket events. The desktop version (Files.ts) properly uses escapeHtml() for the same oper...

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 16, 2026
Source: GitHub
CVE-2026-32626 CRITICAL - 9.6

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the chat rendering pipeline that escalates to Remote Code Execution on the host OS du...

Vendor: Mintplex-Labs
Product: anything-llm
Published: Mar 16, 2026
Source: NVD
CVE-2026-32127 HIGH - 8.8

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vulnerability in the ajax graphs library that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input va...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32126 HIGH - 7.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be enforced only for controllers that already have their own internal authorizatio...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32125 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the Track Anything feature are stored from user input (POST) and later rendered in Dygraph charts (titles/labels) using innerHTML or equivalent without esc...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32124 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJAX endpoint returns code descriptions (code_text) that are rendered in the front end (e.g. DataTables) without HTML escaping. If an administrator (or u...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32123 HIGH - 7.7

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for group encounters are broken because the code only consults form_encounter for sensitivity, while group encounters store sensitivity in form_groups_encount...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32122 MEDIUM - 4.3

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the Claim File Tracker feature exposes an AJAX endpoint that returns billing claim metadata (claim IDs, payer info, transmission logs). The endpoint does not enforce the same AC...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32121 HIGH - 7.7

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, Stored XSS in prescription CSS/HTML print view via patient demographics. That finding involves server-side rendering of patient names via raw PHP echo. This finding involves cl...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32118 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scripting (XSS) in the Graphical Pain Map ("clickmap") form allows any authenticated clinician to inject arbitrary JavaScript that executes in the br...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-3631 HIGH - 7.5

Delta Electronics COMMGR2 has Buffer Over-read DoS vulnerability.

Vendor: deltaww
Product: commgr2
Published: Mar 09, 2026
Source: NVD
CVE-2026-3630 CRITICAL - 9.8

Delta Electronics COMMGR2 has Stack-based Buffer Overflow vulnerability.

Vendor: deltaww
Product: commgr2
Published: Mar 09, 2026
Source: NVD
CVE-2026-3719 MEDIUM - 5.3

A vulnerability was identified in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This issue affects some unknown processing of the file /System/Cms/downLoad. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit is publicly ...

Published: Mar 08, 2026
Source: NVD
CVE-2026-25073 MEDIUM - 5.4

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute in a victim's bro...

Vendor: Anhui Seeker Electronic Technology Co., LTD.
Product: XikeStor SKS8310-8X
Published: Mar 07, 2026
Source: NVD
CVE-2026-25072 CRITICAL - 9.8

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote attackers to hijack authenticated sessions. Attackers can predict session identifiers using insufficiently random cookie ...

Vendor: Anhui Seeker Electronic Technology Co., LTD.
Product: XikeStor SKS8310-8X
Published: Mar 07, 2026
Source: NVD
CVE-2026-25071 HIGH - 7.5

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticated remote attackers to download device configuration files. Attackers can access this endpoint without credentials to ret...

Vendor: Anhui Seeker Electronic Technology Co., LTD.
Product: XikeStor SKS8310-8X
Published: Mar 07, 2026
Source: NVD