Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
Showing 1,081 - 1,100 of 1,476 CVEs
CVE-2026-3663 LOW - 3.3

A vulnerability was found in xlnt-community xlnt up to 1.6.1. This issue affects the function xlnt::detail::compound_document_istreambuf::xsgetn of the file source/detail/cryptography/compound_document.cpp of the component XLSX File Parser. Performing a manipulation results in out-of-bounds read. Th...

Vendor: xlnt-community
Product: xlnt
Published: Mar 07, 2026
Source: NVD

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.9, an attacker may be able to bypass escaping for the shell being used. This can result, for example, in exposure of sensitive information. This impacts users of Shescape that configure their shell to point to a file on disk that...

Vendor: npm
Product: shescape
Published: Mar 07, 2026
Source: GitHub

On Unix platforms, when listing the contents of a directory using File.ReadDir or File.Readdir the returned FileInfo could reference a file outside of the Root in which the File was opened. The impact of this escape is limited to reading metadata provided by lstat from arbitrary locations on the fil...

Vendor: Go standard library
Product: os
Published: Mar 06, 2026
Source: NVD

Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDepth limit on GraphQL subscription queries received over WebSocket connections. The depth check is correctly applied to HTTP queries and mutations, but subscription queries are parsed...

Vendor: npm
Product: mercurius
Published: Mar 06, 2026
Source: GitHub

Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolates image src and alt attributes directly into an HTML string without escaping. An attacker can use a " in the alt attribute to break out of the attribute context and inject ev...

Vendor: npm
Product: defuddle
Published: Mar 06, 2026
Source: GitHub

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator might leak cleartext paths into the log file. This can reveal meta information about the files stored inside a vault at a time, where the actual vault is closed. Not every cleartext...

Vendor: cryptomator
Product: cryptomator
Published: Mar 06, 2026
Source: NVD
CVE-2026-3606 LOW - 3.3

A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this atta...

Published: Mar 05, 2026
Source: NVD

OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without homeserver validation. Remote Matrix users can impersonate allo...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD

The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example a component that enforces a black list may interpret the URIs differently from ...

Vendor: Eclipse Foundation
Product: Eclipse Jetty
Published: Mar 05, 2026
Source: NVD

HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.

Vendor: HCLSoftware
Product: Sametime for iOS
Published: Mar 05, 2026
Source: NVD

Permission control vulnerability in the resource scheduling module. Impact: Successful exploitation of this vulnerability may affect service integrity.

Vendor: Huawei
Product: HarmonyOS
Published: Mar 05, 2026
Source: NVD

dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.37.3, a path traversal vulnerability exists in dbt-common's safe_extract() function used when extracting tarball archives. The function uses os.path.commonprefix() to validate ...

Vendor: pip
Product: dbt-common
Published: Mar 05, 2026
Source: GitHub

Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server's Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting...

Vendor: go
Product: github.com/bishopfox/sliver
Published: Mar 05, 2026
Source: GitHub

Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. This issue has been patched in version 3.1.4.

Vendor: npm
Product: @backstage/plugin-scaffolder-backend
Published: Mar 05, 2026
Source: GitHub

Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encoded form to be included in file paths. When these URLs were processed by integration functions that co...

Vendor: npm
Product: @backstage/integration
Published: Mar 05, 2026
Source: GitHub

Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet files. In order to analyze cross-origin style sheets (stored on websites different from the original ...

Vendor: npm
Product: darkreader
Published: Mar 04, 2026
Source: GitHub

Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Conditions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service.

Vendor: Dell
Product: Device Management Agent (DDMA)
Published: Mar 04, 2026
Source: NVD

Dell PowerScale OneFS, versions 9.10.0.0 through 9.10.1.5 and versions 9.11.0.0 through 9.12.0.1, contains an external control of system or configuration setting vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to protection mechanism ...

Vendor: Dell
Product: PowerScale OneFS
Published: Mar 04, 2026
Source: NVD

Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php.

Vendor: oretnom23
Product: simple_logistic_hub_parcel\'s_management_system
Published: Mar 03, 2026
Source: NVD

Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.

Vendor: oretnom23
Product: pharmacy_point_of_sale_system
Published: Mar 03, 2026
Source: NVD