Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
Showing 1,121 - 1,140 of 1,476 CVEs
CVE-2026-3402 LOW - 2.4

A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The explo...

Vendor: phpgurukul
Product: student_record_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-3401 LOW - 3.1

A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of an attack is rather high. It is indicated that the exploitabi...

Vendor: senior-walter
Product: web-based_pharmacy_product_management_system
Published: Mar 02, 2026
Source: NVD
CVE-2026-3394 LOW - 3.3

A vulnerability was detected in jarikomppa soloud up to 20200207. This affects the function SoLoud::Wav::loadwav of the file src/audiosource/wav/soloud_wav.cpp of the component WAV File Parser. Performing a manipulation results in memory corruption. The attack must be initiated from a local position...

Vendor: solhsa
Product: soloud
Published: Mar 01, 2026
Source: NVD
CVE-2026-3393 LOW - 3.3

A security vulnerability has been detected in jarikomppa soloud up to 20200207. The impacted element is the function SoLoud::Wav::loadflac of the file src/audiosource/wav/soloud_wav.cpp of the component Audio File Handler. Such manipulation leads to heap-based buffer overflow. The attack must be car...

Published: Mar 01, 2026
Source: NVD
CVE-2026-3392 LOW - 3.3

A weakness has been identified in FascinatedBox lily up to 2.3. The affected element is the function eval_tree of the file src/lily_emitter.c. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been made available to the public and could b...

Vendor: lily-lang
Product: lily
Published: Mar 01, 2026
Source: NVD
CVE-2026-3391 LOW - 3.3

A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been released to the public and may be used for ...

Vendor: lily-lang
Product: lily
Published: Mar 01, 2026
Source: NVD
CVE-2026-3390 LOW - 3.3

A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error Reporting. The manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is ...

Vendor: lily-lang
Product: lily
Published: Mar 01, 2026
Source: NVD
CVE-2026-3389 LOW - 3.3

A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference. The attack can only be executed locally. The exploit has been publicly disclosed and ma...

Vendor: squirrel-lang
Product: squirrel
Published: Mar 01, 2026
Source: NVD
CVE-2026-3388 LOW - 3.3

A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolled recursion. The attack needs to be approached locally. The exploit has been made public and could be...

Vendor: squirrel-lang
Product: squirrel
Published: Mar 01, 2026
Source: NVD
CVE-2026-3387 LOW - 3.3

A vulnerability has been found in wren-lang wren up to 0.4.0. Affected by this issue is the function getByteCountForArguments of the file src/vm/wren_compiler.c. Such manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to t...

Vendor: wren
Product: wren
Published: Mar 01, 2026
Source: NVD
CVE-2026-3386 LOW - 3.3

A flaw has been found in wren-lang wren up to 0.4.0. Affected by this vulnerability is the function emitOp of the file src/vm/wren_compiler.c. This manipulation causes out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been published and may be used. The proje...

Vendor: wren
Product: wren
Published: Mar 01, 2026
Source: NVD
CVE-2026-3385 LOW - 3.3

A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recursion. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the pro...

Published: Mar 01, 2026
Source: NVD
CVE-2026-3384 LOW - 3.3

A security vulnerability has been detected in ChaiScript up to 6.1.0. This impacts the function chaiscript::eval::AST_Node_Impl::eval/chaiscript::eval::Function_Push_Pop of the file include/chaiscript/language/chaiscript_eval.hpp. The manipulation leads to uncontrolled recursion. An attack has to be...

Vendor: chaiscript
Product: chaiscript
Published: Mar 01, 2026
Source: NVD
CVE-2026-3383 LOW - 3.3

A weakness has been identified in ChaiScript up to 6.1.0. This affects the function chaiscript::Boxed_Number::go of the file include/chaiscript/dispatchkit/boxed_number.hpp. Executing a manipulation can lead to divide by zero. The attack requires local access. The exploit has been made available to ...

Vendor: chaiscript
Product: chaiscript
Published: Mar 01, 2026
Source: NVD
CVE-2026-3382 LOW - 3.3

A security flaw has been discovered in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::Boxed_Number::get_as of the file include/chaiscript/dispatchkit/boxed_number.hpp. Performing a manipulation results in memory corruption. The attack requires a local approach. The exploit ...

Vendor: chaiscript
Product: chaiscript
Published: Mar 01, 2026
Source: NVD

Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a very wide terminal. Version 9.2.0078 patches the issue.

Vendor: vim
Product: vim
Published: Feb 27, 2026
Source: NVD

Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.

Vendor: VMware
Product: Workstation
Published: Feb 27, 2026
Source: NVD

Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.

Vendor: VMware
Product: Workstation
Published: Feb 27, 2026
Source: NVD

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.e...

Vendor: hexpm, erlang
Product: hex_core, hex, rebar3
Published: Feb 27, 2026
Source: NVD

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to r...

Vendor: Keycloak, Red Hat
Product: keycloak, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.11, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.4
Published: Feb 27, 2026
Source: NVD