Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
Showing 1,021 - 1,040 of 1,476 CVEs

IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow.

Vendor: IBM
Product: Aspera Console
Published: Mar 16, 2026
Source: NVD

Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.35.5.

Vendor: Elementor
Product: Elementor Website Builder
Published: Mar 13, 2026
Source: NVD

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library This vulnerability is fixed in 3.24.0.

Vendor: FreeRDP
Product: FreeRDP
Published: Mar 13, 2026
Source: NVD

wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a malicious cookie value that, when processed through urldecode() and passed to wp_mail() ...

Vendor: gVectors
Product: wpDiscuz
Published: Mar 13, 2026
Source: NVD

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.

Vendor: IBM
Product: Sterling Partner Engagement Manager
Published: Mar 13, 2026
Source: NVD

IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.

Vendor: IBM
Product: Sterling Partner Engagement Manager
Published: Mar 13, 2026
Source: NVD
CVE-2026-4045 LOW - 3.7

A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php. Executing a manipulation of the argument ldap_email can lead to observable response discrepancy. The attack can be executed remotely. A high complexity level is associated with t...

Published: Mar 12, 2026
Source: NVD
CVE-2026-4044 LOW - 3.8

A vulnerability was detected in projectsend up to r1945. This affects the function realpath of the file /import-orphans.php of the component Delete Handler. Performing a manipulation of the argument files[] results in path traversal. Remote exploitation of the attack is possible. The exploit is now ...

Published: Mar 12, 2026
Source: NVD

Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vulnerability exists in @backstage/plugin-auth-backend when auth.experimentalClientIdMetadataDocuments.enabled is set to true. The CIMD metadata fetch validates the initial client_id ...

Vendor: npm
Product: @backstage/plugin-auth-backend
Published: Mar 12, 2026
Source: GitHub

Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses String.includes(), which is case-sensitive. Browsers treat URI schemes case-insensitively. DATA:text/css,... is the same as data:text/css,... to the browser, but 'DATA:...'.in...

Vendor: npm
Product: unhead
Published: Mar 12, 2026
Source: GitHub
CVE-2026-4040 LOW - 3.3

A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handler. The manipulation leads to information exposure through discrepancy. The attack needs to be performed locally. Upgrading to version 2026.2.19-beta.1...

Vendor: openclaw
Product: openclaw
Published: Mar 12, 2026
Source: NVD
CVE-2026-2366 LOW - 3.1

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This information disclosure occurs if the attacker knows the victim...

Vendor: npm
Product: @keycloak/keycloak-admin-client
Published: Mar 12, 2026
Source: NVD
CVE-2026-4012 LOW - 3.3

A vulnerability was determined in rxi fe up to ed4cda96bd582cbb08520964ba627efb40f3dd91. The impacted element is the function read_ of the file src/fe.c. This manipulation with the input 1 causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be...

Published: Mar 12, 2026
Source: NVD
CVE-2026-4010 LOW - 3.3

A vulnerability was found in ThakeeNathees pocketlang up to cc73ca61b113d48ee130d837a7a8b145e41de5ce. The affected element is the function pkByteBufferAddString. The manipulation of the argument length with the input 4294967290 results in memory corruption. The attack requires a local approach. The ...

Published: Mar 12, 2026
Source: NVD
CVE-2026-4009 LOW - 3.3

A vulnerability has been found in jarikomppa soloud up to 20200207. Impacted is the function drwav_read_pcm_frames_s16__msadpcm in the library src/audiosource/wav/dr_wav.h of the component WAV File Parser. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The ex...

Published: Mar 12, 2026
Source: NVD
CVE-2026-3984 LOW - 3.5

A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerability affects unknown code of the file save_up_athlete.php. This manipulation of the argument a_name causes cross site scripting. It is possible to initiate the attack remotely. Th...

Published: Mar 12, 2026
Source: NVD
CVE-2026-3983 LOW - 3.5

A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This affects an unknown part of the file save-games.php. The manipulation of the argument game_name results in cross site scripting. The attack may be performed from remote. The exploit ha...

Published: Mar 12, 2026
Source: NVD
CVE-2026-3963 LOW - 3.7

A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. This affects the function rememberMeManager of the file src/main/java/com/perfree/config/ShiroConfig.java of the component Apache Shiro RememberMe. Performing a manipulation results in use of hard-coded cryptographic key . T...

Published: Mar 11, 2026
Source: NVD
CVE-2026-3929 LOW - 3.1

Side-channel information leakage in ResourceTiming in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Vendor: google
Product: chrome
Published: Mar 11, 2026
Source: NVD

HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors.

Vendor: HCLSoftware
Product: Nomad server on Domino
Published: Mar 11, 2026
Source: NVD