Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,730
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,081 - 10,100 of 13,238 CVEs
CVE-2026-24502 HIGH - 8.8

Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: Dell
Product: Dell Command | Intel vPro Out of Band
Published: Mar 03, 2026
Source: NVD
CVE-2026-1567 HIGH - 7.1

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.

Vendor: ibm
Product: infosphere_information_server
Published: Mar 03, 2026
Source: NVD
CVE-2026-28696 HIGH - 7.5

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused by both authenticated users and unauthenticated guests (if a Public Schema is enabled) to access sens...

Vendor: composer
Product: craftcms/cms
Published: Mar 03, 2026
Source: GitHub
CVE-2026-2915 HIGH - 7.1

HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was remediated with HP System Event Utility version 3.2.16.

Vendor: hp
Product: system_event_utility
Published: Mar 03, 2026
Source: NVD
CVE-2026-29022 HIGH - 7.3

dr_libs version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 ...

Vendor: mackron
Product: dr_libs
Published: Mar 03, 2026
Source: NVD
CVE-2026-26892 HIGH - 7.2

Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.

Vendor: oretnom23
Product: simple_logistic_hub_parcel\'s_management_system
Published: Mar 03, 2026
Source: NVD
CVE-2026-0869 HIGH - 8.8

Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Brocade Support Link(BSL) and streaming configuration. and could even disable the ASCG application or disable use of BSL data collection on Brocade switches within the fabric.

Vendor: broadcom
Product: brocade_active_support_connectivity_gateway
Published: Mar 03, 2026
Source: NVD
CVE-2024-55027 HIGH - 7.5

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to stroe credentials in plaintext in the component uac_temp.db.

Vendor: weintek
Product: easyweb
Published: Mar 03, 2026
Source: NVD
CVE-2024-55026 HIGH - 8.8

An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.

Vendor: weintek
Product: easyweb
Published: Mar 03, 2026
Source: NVD
CVE-2024-55024 HIGH - 8.8

An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts.

Vendor: weintek
Product: easyweb
Published: Mar 03, 2026
Source: NVD
CVE-2024-55022 HIGH - 8.8

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain an authenticated command injection vulnerability via the HMI Name parameter.

Vendor: weintek
Product: easyweb
Published: Mar 03, 2026
Source: NVD
CVE-2024-55021 HIGH - 7.5

Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.

Vendor: weintek
Product: easyweb
Published: Mar 03, 2026
Source: NVD
CVE-2026-29053 HIGH - 7.7

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.

Vendor: npm
Product: ghost
Published: Mar 03, 2026
Source: GitHub
CVE-2026-3437 HIGH - 7.8

An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulne...

Vendor: portwell
Product: engineering_toolkits
Published: Mar 03, 2026
Source: NVD
CVE-2025-69765 HIGH - 7.5

Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution.

Vendor: tenda
Product: ax3_firmware
Published: Mar 03, 2026
Source: NVD
CVE-2025-67840 HIGH - 7.2

Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Build 14614 through TZM_1757588060_SEP2025_FULL.depot web application API endpoints (including Scheduler and Actions pages). The appliance directly concatenates user-controlled paramet...

Vendor: cohesity
Product: tranzman
Published: Mar 03, 2026
Source: NVD
CVE-2025-63912 HIGH - 7.5

Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for data encryption, allowing attackers to trivially reverse the encyption and expose credentials.

Vendor: cohesity
Product: tranzman
Published: Mar 03, 2026
Source: NVD
CVE-2025-63911 HIGH - 7.2

Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability.

Vendor: cohesity
Product: tranzman
Published: Mar 03, 2026
Source: NVD
CVE-2025-63910 HIGH - 7.2

An authenticated arbitrary file upload vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted patch file.

Vendor: cohesity
Product: tranzman
Published: Mar 03, 2026
Source: NVD
CVE-2025-63909 HIGH - 7.2

Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attackers to escalate privileges to root and read and write arbitrary files.

Vendor: cohesity
Product: tranzman
Published: Mar 03, 2026
Source: NVD