Total CVEs

125,574

Critical Severity

2,253

High Severity

7,771

Last 7 Days

1,121
Quick preset (or use dates below)
Clear Filters
Showing 101 - 120 of 1,441 CVEs
CVE-2026-33672 MEDIUM - 5.3

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits from `Object.prototype`, specially crafted POSIX bracket expressions (e.g., `[[:construc...

Vendor: npm
Product: picomatch
Published: Mar 25, 2026
Source: GitHub
CVE-2026-33671 HIGH - 7.5

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlap...

Vendor: npm
Product: picomatch
Published: Mar 25, 2026
Source: GitHub
CVE-2026-25401 HIGH - 7.5

Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through <= 8.0.2.

Vendor: Arni Cinco
Product: WPCargo Track & Trace
Published: Mar 25, 2026
Source: NVD
CVE-2026-33628 MEDIUM - 5.4

Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item descriptions in Invoice Ninja v5.13.0 bypass the XSS denylist filter, allowing stored XSS payloads to execute when invoices are rendered in the PDF preview or client portal. The li...

Vendor: composer
Product: invoiceninja/invoiceninja
Published: Mar 24, 2026
Source: GitHub
CVE-2026-33345 MEDIUM - 6.5

solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organizations/{org}/projects/{project} allows any authenticated Employee to access any project in the organization by UUID, including private projects they are not a member of. The index()...

Vendor: solidtime-io
Product: solidtime
Published: Mar 24, 2026
Source: NVD
CVE-2026-33417 MEDIUM - 6.5

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The password_resets table includes a created_at timestamp column, but the token validation logic never checks it. A password reset token remains valid indefini...

Vendor: ellite
Product: Wallos
Published: Mar 24, 2026
Source: NVD
CVE-2026-33407 CRITICAL - 9.1

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF via proxy hijacking. The server performs DNS resolution on user-supplied search ...

Vendor: ellite
Product: Wallos
Published: Mar 24, 2026
Source: NVD
CVE-2026-33401 MEDIUM - 6.5

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-30840) added SSRF protection to notification test endpoints but left three additional attack surfaces unprotected: the AI Ollama host parameter, the AI re...

Vendor: ellite
Product: Wallos
Published: Mar 24, 2026
Source: NVD
CVE-2026-33400 MEDIUM - 5.4

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint allows any authenticated user to inject arbitrary JavaScript that executes when any user visits the Settings, Subscri...

Vendor: ellite
Product: Wallos
Published: Mar 24, 2026
Source: NVD
CVE-2026-33399 HIGH - 7.7

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-30839 and CVE-2026-30840 is incomplete. The validate_webhook_url_for_ssrf() protection was added to the test* notification endpoints but not to the corres...

Vendor: ellite
Product: Wallos
Published: Mar 24, 2026
Source: NVD
CVE-2026-4728 MEDIUM - 6.5

Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Vendor: mozilla
Product: firefox
Published: Mar 24, 2026
Source: NVD
CVE-2026-33548 MEDIUM - 6.1

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, improper escaping of tag names retrieved from History in Timeline (my_view_page.php) allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript, when displaying a tag that ...

Vendor: mantisbt
Product: mantisbt
Published: Mar 23, 2026
Source: NVD
CVE-2026-33517 MEDIUM - 6.1

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In version 2.28.0, when deleting a Tag (tag_delete.php), improper escaping of its name when displaying the confirmation message allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript. Ver...

Vendor: mantisbt
Product: mantisbt
Published: Mar 23, 2026
Source: NVD
CVE-2026-30849 CRITICAL - 9.8

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter. Other database backends are not affect...

Vendor: mantisbt
Product: mantisbt
Published: Mar 23, 2026
Source: NVD
CVE-2026-4004 MEDIUM - 6.5

The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks in the callback_search() function and insufficient input validation that allows shortcode ...

Published: Mar 21, 2026
Source: NVD
CVE-2026-3572 MEDIUM - 6.1

The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in all versions up to and including 2.2.0. This is due to missing nonce verification on the settings form submission and insufficient input sanitization combined with missing outpu...

Published: Mar 21, 2026
Source: NVD
CVE-2026-33478 CRITICAL - 10.0

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json.php` endpoint exposes clone secret keys with...

Vendor: composer
Product: avideo/avideo
Published: Mar 20, 2026
Source: GitHub
CVE-2026-31836 HIGH - 8.1

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. In versions from 3.5.1 and prior, a mass assignment vulnerability in Checkmate's user profile update endpoint allows any...

Vendor: bluewave-labs
Product: Checkmate
Published: Mar 20, 2026
Source: NVD
CVE-2026-3550 MEDIUM - 5.3

The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. This is due to missing capability checks on multiple AJAX actions (rockpress_import, rockpress_import_status, rockpress_last_import, rockpress_reset_import, and rockpress_check_ser...

Published: Mar 20, 2026
Source: NVD
CVE-2026-2432 MEDIUM - 4.4

The CM Custom Reports โ€“ Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ...

Published: Mar 20, 2026
Source: NVD