Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,669
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,181 - 10,200 of 13,240 CVEs
CVE-2026-21882 HIGH - 8.4

theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.2.0, improper privilege dropping allows local privilege escalation via command re-execution. This issue has been patched in version 0.2.0.

Vendor: rust
Product: theshit
Published: Mar 02, 2026
Source: GitHub
CVE-2026-28399 HIGH - 8.8

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Creator role can inject arbitrary SQL via the DATEADD formula's unit parameter. This issue has been patched in version 0.301.3.

Vendor: nocodb
Product: nocodb
Published: Mar 02, 2026
Source: NVD
CVE-2026-28286 HIGH - 8.5

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the frontend/UI to prevent users from creating files or folders in internal OS paths. However, when interacting directly with the API, the r...

Vendor: IceWhaleTech
Product: ZimaOS
Published: Mar 02, 2026
Source: NVD
CVE-2026-21385 HIGH - 7.8

Memory corruption while using alignments for memory allocation.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-70252 HIGH - 7.5

An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable. If the conditions are met to sprintf, they will be spliced into tmp. It is worth noting that there is no size check,which leads to a stack overflow vulnerability.

Vendor: tenda
Product: ac6_firmware
Published: Mar 02, 2026
Source: NVD
CVE-2025-64427 HIGH - 7.1

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target URLs, an authenticated local user can craft requests that target internal IP addresses (e.g., 127.0.0.1, localhost, or pr...

Vendor: IceWhaleTech
Product: ZimaOS
Published: Mar 02, 2026
Source: NVD
CVE-2025-59603 HIGH - 7.8

Memory Corruption when processing invalid user address with nonstandard buffer address.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-59600 HIGH - 7.8

Memory Corruption when adding user-supplied data without checking available buffer space.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-47386 HIGH - 7.8

Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-47385 HIGH - 7.8

Memory Corruption when accessing trusted execution environment without proper privilege check.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-47383 HIGH - 7.2

Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-47381 HIGH - 7.8

Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-47379 HIGH - 7.8

Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-47378 HIGH - 7.1

Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-47377 HIGH - 7.8

Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-47376 HIGH - 7.8

Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-47375 HIGH - 7.8

Memory corruption while handling different IOCTL calls from the user-space simultaneously.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2025-47373 HIGH - 7.8

Memory Corruption when accessing buffers with invalid length during TA invocation.

Vendor: Qualcomm, Inc.
Product: Snapdragon
Published: Mar 02, 2026
Source: NVD
CVE-2026-28403 HIGH - 7.6

Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.1:<httpPort+1>`) accepts connections from any origin without validating the HTTP `Origin` header during the WebSocket handshake. A malicious web page visited in the same brow...

Vendor: f
Product: textream
Published: Mar 02, 2026
Source: NVD
CVE-2026-26699 HIGH - 8.8

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php.

Vendor: jon-remus-sevellejo
Product: personnel_property_equipment_system
Published: Mar 02, 2026
Source: NVD