Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
Showing 1,061 - 1,080 of 1,476 CVEs

Craft is a content management system (CMS). Prior to 4.17.4 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not require POST and does not enforce a CSRF token, an att...

Vendor: composer
Product: craftcms/cms
Published: Mar 10, 2026
Source: GitHub

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP reque...

Vendor: Fortinet
Product: FortiWeb
Published: Mar 10, 2026
Source: NVD

An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4...

Vendor: Fortinet
Product: FortiAnalyzer, FortiAnalyzer Cloud, FortiManager, FortiManager Cloud
Published: Mar 10, 2026
Source: NVD

HCL Sametime for Android is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URL

Vendor: HCL
Product: Sametime
Published: Mar 10, 2026
Source: NVD

A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the char...

Vendor: Siemens
Product: Heliox Flex 180 kW EV Charging Station, Heliox Mobile DC 40 kW EV Charging Station
Published: Mar 10, 2026
Source: NVD

Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the application's confidential...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server for ABAP
Published: Mar 10, 2026
Source: NVD

A security vulnerability has been detected in open-webui up to 0.6.16. Affected is an unknown function of the file backend/start_windows.bat of the component JWT Key Handler. Such manipulation of the argument WEBUI_SECRET_KEY leads to insufficiently random values. It is possible to launch the attack...

Product: open-webui
Published: Mar 09, 2026
Source: NVD
CVE-2026-3766 LOW - 3.5

A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of the argument fullname results in cross site scripting. The attack may be initiated remotely. The exploit...

Vendor: senior-walter
Product: web-based_pharmacy_product_management_system
Published: Mar 08, 2026
Source: NVD
CVE-2026-3743 LOW - 3.5

A flaw has been found in YiFang CMS 2.0.5. This affects the function update of the file app/db/admin/D_singlePageGroup.php. Executing a manipulation of the argument Name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used. Th...

Vendor: yifangcms
Product: yifang
Published: Mar 08, 2026
Source: NVD
CVE-2026-3742 LOW - 3.5

A vulnerability was detected in YiFang CMS 2.0.5. The impacted element is the function update of the file app/db/admin/D_singlePage.php. Performing a manipulation of the argument Title results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may ...

Vendor: yifangcms
Product: yifang
Published: Mar 08, 2026
Source: NVD
CVE-2026-3741 LOW - 3.5

A security vulnerability has been detected in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argument linkName leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed pub...

Vendor: yifangcms
Product: yifang
Published: Mar 08, 2026
Source: NVD
CVE-2026-3721 LOW - 3.5

A weakness has been identified in 1024-lab/lab1024 SmartAdmin up to 3.29. The affected element is an unknown function of the file sa-base/src/main/java/net/lab1024/sa/base/module/support/helpdoc/domain/form/HelpDocAddForm.java of the component Help Documentation Module. This manipulation causes cros...

Vendor: lab1024
Product: smartadmin
Published: Mar 08, 2026
Source: NVD
CVE-2026-3720 LOW - 3.5

A security flaw has been discovered in 1024-lab/lab1024 SmartAdmin up to 3.29. Impacted is an unknown function of the file smart-admin-web-javascript/src/views/business/oa/notice/components/notice-form-drawer.vue of the component Notice Module. The manipulation results in cross site scripting. The a...

Vendor: lab1024
Product: smartadmin
Published: Mar 08, 2026
Source: NVD
CVE-2026-3716 LOW - 2.4

A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This vulnerability affects the function sub_401AD4 of the file /cgi-bin/adm.cgi. Executing a manipulation of the argument Hostname can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publi...

Vendor: wavlink
Product: wl-wn579x3-c_firmware
Published: Mar 08, 2026
Source: NVD
CVE-2026-3706 LOW - 3.7

A vulnerability was determined in mkj Dropbear up to 2025.89. Impacted is the function unpackneg of the file src/curve25519.c of the component S Range Check. This manipulation causes improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to h...

Published: Mar 08, 2026
Source: NVD
CVE-2026-3671 LOW - 3.3

A flaw has been found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function TokenBalanceContentProvider of the component org.ethereumphone.walletmanager.testing123. Executing a manipulation can lead to improper authorization. The attack requires local access. The ex...

Published: Mar 07, 2026
Source: NVD
CVE-2026-2671 LOW - 3.1

A vulnerability was detected in Mendi Neurofeedback Headset V4. Affected by this vulnerability is an unknown functionality of the component Bluetooth Low Energy Handler. Performing a manipulation results in cleartext transmission of sensitive information. The attack can only be performed from the lo...

Published: Mar 07, 2026
Source: NVD
CVE-2026-3668 LOW - 3.1

A weakness has been identified in Freedom Factory dGEN1 up to 20260221. This affects the function AndroidEthereum of the component org.ethosmobile.webpwaemul. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The attack is considered to have high compl...

Published: Mar 07, 2026
Source: NVD
CVE-2026-3665 LOW - 3.3

A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xlsx_consumer::read_office_document of the file source/detail/serialization/xlsx_consumer.cpp of the component XLSX File Parser. The manipulation leads to null pointer dereference. T...

Vendor: xlnt-community
Product: xlnt
Published: Mar 07, 2026
Source: NVD
CVE-2026-3664 LOW - 3.3

A vulnerability was determined in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_document::read_directory of the file source/detail/cryptography/compound_document.cpp of the component Encrypted XLSX File Parser. Executing a manipulation can lead to out-of-bounds rea...

Vendor: xlnt-community
Product: xlnt
Published: Mar 07, 2026
Source: NVD