Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,719
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,121 - 10,140 of 13,240 CVEs
CVE-2026-2269 HIGH - 7.2

The Uncanny Automator โ€“ Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.0.3 via the download_url() function. This makes it possible for authenticated attackers, with Admin...

Published: Mar 03, 2026
Source: NVD
CVE-2026-1566 HIGH - 8.8

The LatePoint โ€“ Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 5.2.7. This is due to the plugin allowing users with a LatePoint Agent role, who are creating new customers to set t...

Published: Mar 03, 2026
Source: NVD
CVE-2026-3338 HIGH - 7.5

Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1...

Published: Mar 02, 2026
Source: NVD
CVE-2026-3336 HIGH - 7.5

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should up...

Vendor: aws
Product: aws_libcrypto
Published: Mar 02, 2026
Source: NVD

Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained import file write and template path traversal. This issue has been patched in version 1.6.4.

Vendor: composer
Product: idno/known
Published: Mar 02, 2026
Source: GitHub
CVE-2026-28438 HIGH - 9.8

CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify the configured table name before creating some SQL statements (ALTER TABLE). So, in the application code, if the table name is provided by an untrusted upstream, it expose vuln...

Vendor: pip
Product: cocoindex
Published: Mar 02, 2026
Source: GitHub
CVE-2026-27596 HIGH - 7.5

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2 with an extra comma...

Vendor: Exiv2
Product: exiv2
Published: Mar 02, 2026
Source: NVD
CVE-2026-25884 HIGH - 8.1

Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an out-of-bounds read was found. The vulnerability is in the CRW image parser. This issue has been patched in version 0.28.8.

Vendor: Exiv2
Product: exiv2
Published: Mar 02, 2026
Source: NVD
CVE-2026-28492 HIGH - 6.5

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.0, when a user creates a public share link for a directory, the withHashFile middleware in http/public.go uses filepath.Dir(link.Pa...

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Mar 02, 2026
Source: GitHub
CVE-2026-21853 HIGH - 8.8

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This vulnerability can be exploited by embedding a specially crafted affine: URL on a website. An attacker can trigger the vulnerability in two c...

Vendor: toeverything
Product: AFFiNE
Published: Mar 02, 2026
Source: NVD
CVE-2026-0047 HIGH - 8.4

In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2026-0038 HIGH - 8.4

In multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2026-0037 HIGH - 8.4

In multiple functions of ffa.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2026-0035 HIGH - 8.4

In createRequest of MediaProvider.java, there is a possible way for an app to gain read/write access to non-existing files due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2026-0034 HIGH - 8.4

In setPackageOrComponentEnabled of ManagedServices.java, there is a possible notification policy desync due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2026-0032 HIGH - 7.8

In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2026-0031 HIGH - 8.4

In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2026-0030 HIGH - 8.4

In __host_check_page_state_range of mem_protect.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2026-0028 HIGH - 8.4

In __pkvm_host_share_guest of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD
CVE-2026-0026 HIGH - 7.8

In removePermission of PermissionManagerServiceImpl.java, there is a possible way to override any system permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Vendor: google
Product: android
Published: Mar 02, 2026
Source: NVD