Total CVEs

140,343

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,765
Quick preset (or use dates below)
Clear Filters
Showing 981 - 1,000 of 1,473 CVEs

Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report...

Vendor: pip
Product: memray
Published: Mar 16, 2026
Source: GitHub

StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `getUsers` endpoint in StudioCMS uses the attacker-controlled `rank` query parameter to decide whether owner accounts should be filtered from the result set. As a result, an admin toke...

Vendor: npm
Product: studiocms
Published: Mar 16, 2026
Source: GitHub
CVE-2026-4250 LOW - 2.5

A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an unknown function of the file resources/assets/service-account.json of the component Google Cloud Service Account Key Handler. Performing a manipulation results in unprotected storage...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4243 LOW - 2.5

A weakness has been identified in La Nacion App 10.2.25 on Android. This impacts an unknown function of the file source/app/lanacion/clublanacion/BuildConfig.java of the component app.lanacion.activity. Executing a manipulation of the argument API_KEY_WEBSOCKET_CV can lead to unprotected storage of ...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4242 LOW - 2.5

A security flaw has been discovered in BabyChakra Pregnancy & Parenting App up to 5.4.3.0 on Android. This affects an unknown function of the file file app/babychakra/babychakra/Configuration.java of the component app.babychakra.babychakra. Performing a manipulation of the argument SEGMENT_WRITE...

Published: Mar 16, 2026
Source: NVD

Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type switch which allows an authenticated attacker to change account password without confirmation via falsely claiming a different auth provider.. Mattermost Advisory ID: MMSA-...

Vendor: Mattermost
Product: Mattermost
Published: Mar 16, 2026
Source: NVD

HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infer or guess system-generated values, potentially leading to limited information disclosure or unintended access under specific conditions.

Vendor: HCL
Product: AION
Published: Mar 16, 2026
Source: NVD

HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmful SQL queries. Improper validation or restrictions on query execution could expose the system to unintended database interactions or limited information exposure under specific con...

Vendor: HCL
Product: AION
Published: Mar 16, 2026
Source: NVD

HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or unintended behaviour.

Vendor: HCL
Product: AION
Published: Mar 16, 2026
Source: NVD

HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal environment structure details which could potentially aid in further targeted attacks or information disclosure.

Vendor: HCL
Product: AION
Published: Mar 16, 2026
Source: NVD

HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow excessive resource consumption, which could potentially lead to service degradation or denial-of-service conditions under certain scenarios.

Vendor: HCL
Product: AION
Published: Mar 16, 2026
Source: NVD

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a user provided callback to `set_tlsext_servername_callback` raised an unhandled exception, this would result in a connection being accepted. If a user was relying on this callback fo...

Vendor: pip
Product: pyopenssl
Published: Mar 16, 2026
Source: GitHub
CVE-2026-4239 LOW - 3.5

A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatables. The manipulation results in improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit has been made public an...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4225 LOW - 2.4

A security flaw has been discovered in CMS Made Simple up to 2.2.21. Impacted is an unknown function of the file admin/listusers.php of the component User Management Module. Performing a manipulation of the argument Message results in cross site scripting. The attack is possible to be carried out re...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4222 LOW - 3.8

A vulnerability was determined in SSCMS up to 7.4.0. This vulnerability affects the function PathUtils.RemoveParentPath of the file /api/admin/plugins/install/actions/download. This manipulation of the argument path causes path traversal. Remote exploitation of the attack is possible. The exploit ha...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4219 LOW - 3.3

A flaw has been found in INDEX Conferences & Exhibitions Organization YWF BPOF APGCS App up to 1.0.2 on Android. Affected by this vulnerability is an unknown functionality of the file com/index/event/BuildConfig.java of the component ae.index.apgcs. Executing a manipulation of the argument ACCES...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4218 LOW - 2.5

A vulnerability was detected in myAEDES App up to 1.18.4 on Android. Affected is an unknown function of the file aedes/me/beta/utils/EngageBayUtils.java of the component aedes.me.beta. Performing a manipulation of the argument AUTH_KEY results in information disclosure. The attack is only possible w...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4217 LOW - 2.5

A security vulnerability has been detected in XREAL Nebula App up to 3.2.1 on Android. This impacts an unknown function of the file in ai/nreal/nebula/flutterPlugin/CloudStoragePlugin.java of the component ai.nreal.nebula.universal. Such manipulation of the argument accessKey/secretAccessKey/securit...

Published: Mar 16, 2026
Source: NVD
CVE-2026-4186 LOW - 3.5

A vulnerability was determined in UEditor up to 1.4.3.2. This issue affects some unknown processing of the file php/controller.php?action=uploadimage of the component JSONP Callback Handler. This manipulation of the argument callback causes cross site scripting. The attack can be initiated remotely....

Published: Mar 16, 2026
Source: NVD
CVE-2026-4175 LOW - 3.5

A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. The affected element is an unknown function of the file plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php of the component Chatter Message Handler. Executing a manipulation of the...

Published: Mar 16, 2026
Source: NVD