Total CVEs

125,574

Critical Severity

2,253

High Severity

7,771

Last 7 Days

1,120
Quick preset (or use dates below)
Clear Filters
Showing 141 - 160 of 1,441 CVEs
CVE-2026-29076 MEDIUM - 5.9

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib uses std::regex (libstdc++) to parse RFC 5987 encoded filename* values in multipart Content-Disposition headers. The regex engine in libstdc++ implements backtracking via deep recur...

Vendor: yhirose
Product: cpp-httplib
Published: Mar 07, 2026
Source: NVD
CVE-2026-30842 MEDIUM - 4.3

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenticated user to delete avatar files uploaded by other users. The avatar deletion endpoint does not verify that the requested avatar belongs to the current user. As a result, any auth...

Vendor: ellite
Product: Wallos
Published: Mar 07, 2026
Source: NVD
CVE-2026-30841 MEDIUM - 6.1

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs $_GET["token"] and $_GET["email"] directly into HTML input value attributes using <?= $token ?> and <?= $email ?> without calling htmlspecialchars(...

Vendor: ellite
Product: Wallos
Published: Mar 07, 2026
Source: NVD
CVE-2026-30840 HIGH - 8.8

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification testers. This issue has been patched in version 4.6.2.

Vendor: ellite
Product: Wallos
Published: Mar 07, 2026
Source: NVD
CVE-2026-30839 MEDIUM - 4.3

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications.php does not validate the target URL against private/reserved IP ranges, enabling full-read SSRF. The server response is returned to the caller. This issue has been patched in vers...

Vendor: ellite
Product: Wallos
Published: Mar 07, 2026
Source: NVD
CVE-2026-30829 MEDIUM - 5.3

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to version 3.4.0, an unauthenticated information disclosure vulnerability exists in the GET /api/v1/status-page/:url en...

Vendor: bluewave-labs
Product: Checkmate
Published: Mar 07, 2026
Source: NVD
CVE-2026-30828 HIGH - 7.5

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been patched in version 4.6.2.

Vendor: ellite
Product: Wallos
Published: Mar 07, 2026
Source: NVD
CVE-2026-30847 MEDIUM - 6.5

Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publication in Wekan publishes user documents with no field filtering, causing the ReactiveCache.getUsers() call to return all fields including highly sensitive data such as bcrypt password ...

Vendor: Wekan
Product: Wekan
Published: Mar 06, 2026
Source: NVD
CVE-2018-25192 HIGH - 8.2

GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit crafted POST requests to the login.php endpoint with SQL injection payloads in the username field...

Vendor: Sourceforge
Product: GPS Tracking System
Published: Mar 06, 2026
Source: NVD
CVE-2018-25180 HIGH - 7.1

Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the mailid parameter in outmail and inmail modules. Attackers can also download the SQLite database file directly from the application directo...

Vendor: Salzertechnologies
Product: Maitra
Published: Mar 06, 2026
Source: NVD
CVE-2018-25161 HIGH - 8.2

Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL queries by injecting malicious code through the txtCustomerCode, txtCustomerName, and txtPhone POST parameters in SearchCustomer.php. Attackers can submit crafted SQL statements us...

Vendor: Warrantytrack
Product: Warranty Tracking System
Published: Mar 06, 2026
Source: NVD
CVE-2026-29052 MEDIUM - 6.1

The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cross-Site Scripting (XSS) vulnerability in the Event Types of the HumHub Calendar module impacts users ...

Vendor: humhub
Product: calendar
Published: Mar 05, 2026
Source: NVD
CVE-2026-28685 MEDIUM - 6.5

Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks the role-based view_invoice permission but does not verify the requesting user has access to the invoice's customer. Any user with ROLE_TEAMLEAD (which grants view_...

Vendor: composer
Product: kimai/kimai
Published: Mar 04, 2026
Source: GitHub
CVE-2026-0847 HIGH - 8.6

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file paths, enabling attack...

Published: Mar 04, 2026
Source: NVD
CVE-2026-27981 HIGH - 7.4

HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1. X-Real-IP header, 2. First entry of X-Forwarded-For header, and 3. r.RemoteAddr (TCP connection add...

Vendor: sysadminsmedia
Product: homebox
Published: Mar 03, 2026
Source: NVD

Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Scripting vulnerability in the "PWA" Canarytoken, whereby the Canarytoken's creator can attack themselves or someone they share the link with. The creator of a PWA Canaryt...

Vendor: thinkst
Product: canarytokens
Published: Feb 27, 2026
Source: NVD
CVE-2026-27449 HIGH - 7.5

Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed directly over the net...

Vendor: umbraco
Product: Umbraco.Engage.Forms
Published: Feb 26, 2026
Source: NVD
CVE-2026-27904 HIGH - 7.5

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastro...

Vendor: isaacs
Product: minimatch
Published: Feb 26, 2026
Source: NVD
CVE-2026-27903 HIGH - 7.5

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBST...

Vendor: isaacs
Product: minimatch
Published: Feb 26, 2026
Source: NVD
CVE-2026-25476 HIGH - 7.5

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the session expiration check in `library/auth.inc.php` runs only when `skip_timeout_reset` is not present in the request. When `skip_timeout_reset=1` is sent, the entire b...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD