Total CVEs

125,574

Critical Severity

2,253

High Severity

7,771

Last 7 Days

1,134
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 121 - 140 of 250 CVEs

In the Linux kernel, the following vulnerability has been resolved: macvlan: observe an RCU grace period in macvlan_common_newlink() error path valis reported that a race condition still happens after my prior patch. macvlan_common_newlink() might have made @dev visible before detecting an error,...

Vendor: Linux
Product: Linux
Published: Mar 20, 2026
Source: NVD
CVE-2026-29108 MEDIUM - 6.5

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, an authenticated API endpoint allows any user to retrieve detailed information about any other user, including their password hash, username, and MFA configuration. As a...

Vendor: SuiteCRM
Product: SuiteCRM-Core
Published: Mar 20, 2026
Source: NVD
CVE-2026-32754 CRITICAL - 9.3

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. Incoming email bodies are stored in the database without sanitization and rend...

Vendor: freescout-help-desk
Product: freescout
Published: Mar 19, 2026
Source: NVD
CVE-2026-3475 MEDIUM - 5.3

The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all versions up to and including 1.1.7. This is due to the handle_email_verification_page() function constructing a shortcode string from user-supplied GET parameters (token, email) and p...

Published: Mar 19, 2026
Source: NVD
CVE-2026-3090 HIGH - 7.2

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜event_type’ parameter in all versions up to, and including, 3.8.0 due to insufficient input sanitization an...

Published: Mar 18, 2026
Source: NVD
CVE-2026-22178 MEDIUM - 6.5

OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the stripBotMention function, allowing regex injection and denial of service. Attackers can craft nested-quantifier patterns or metacharacters in mention metadata to trigger catastrophic ...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 18, 2026
Source: NVD
CVE-2026-26004 MEDIUM - 6.5

Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability in Sentry's GroupEventJsonView endpoint. Version 26.1.0 patches the issue.

Vendor: getsentry
Product: sentry
Published: Mar 18, 2026
Source: NVD
CVE-2026-33041 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the application's password hashing algorithm to any unauthenticated user. An attacker can submit arbitrary passwords and receive their hashed equivalents, enabling offline password cr...

Vendor: composer
Product: wwbn/avideo
Published: Mar 17, 2026
Source: GitHub

Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report...

Vendor: pip
Product: memray
Published: Mar 16, 2026
Source: GitHub
CVE-2026-28356 HIGH - 7.5

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential backtracking (ReDoS) when parsing maliciously crafted HTTP or multi...

Vendor: defnull
Product: multipart
Published: Mar 12, 2026
Source: NVD
CVE-2026-3099 MEDIUM - 5.8

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This vulnerability allows a remote attacker to capture a single valid authenticat...

Published: Mar 12, 2026
Source: NVD
CVE-2026-32136 CRITICAL - 9.8

AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cleartext (h2c). Once the upgrade is accepted, the resulting HTT...

Vendor: AdguardTeam
Product: AdGuardHome
Published: Mar 11, 2026
Source: NVD
CVE-2026-32125 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the Track Anything feature are stored from user input (POST) and later rendered in Dygraph charts (titles/labels) using innerHTML or equivalent without esc...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-32122 MEDIUM - 4.3

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the Claim File Tracker feature exposes an AJAX endpoint that returns billing claim metadata (claim IDs, payer info, transmission logs). The endpoint does not enforce the same AC...

Vendor: openemr
Product: openemr
Published: Mar 11, 2026
Source: NVD
CVE-2026-3950 LOW - 3.3

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and mi...

Published: Mar 11, 2026
Source: NVD
CVE-2026-32094 MEDIUM - 6.5

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-bracket glob syntax for Bash, BusyBox sh, and Dash. Applications that interpolate the return value directly into a shell command string can cause an attacker-controlled value like secr...

Vendor: npm
Product: shescape
Published: Mar 11, 2026
Source: GitHub
CVE-2026-22248 HIGH - 8.0

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. From 11.0.0 to before 11.0.5, an authenticated technician user can upload a malicious file and trigger its execution through an unsafe PHP instantiation....

Vendor: glpi-project
Product: glpi
Published: Mar 11, 2026
Source: NVD

Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTML tags (angle brackets) -- it does not inspect or filter URL ...

Vendor: composer
Product: craftcms/cms
Published: Mar 11, 2026
Source: GitHub
CVE-2026-31817 HIGH - 8.5

OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists execution log entries to disk. The filename used for these log files is constructed in part from the user-supplied UniqueTrackingId field in the StartA...

Vendor: OliveTin
Product: OliveTin
Published: Mar 10, 2026
Source: NVD
CVE-2026-30925 HIGH - 7.5

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a crafted $regex pattern that causes catastrophic backtracking, blocking the Node.js event loop. This makes...

Vendor: npm
Product: parse-server
Published: Mar 10, 2026
Source: GitHub