Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
Showing 1,861 - 1,880 of 3,569 CVEs
CVE-2026-30283 CRITICAL - 9.8

An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Vendor: peaksel
Product: animal_sounds_and_ringtones
Published: Mar 31, 2026
Source: NVD
CVE-2026-30282 CRITICAL - 9.0

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

Vendor: uxgroupllc
Product: cast_to_tv
Published: Mar 31, 2026
Source: NVD
CVE-2026-30278 CRITICAL - 9.8

An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Vendor: funair
Product: fly_is_fun
Published: Mar 31, 2026
Source: NVD
CVE-2026-34235 CRITICAL - 9.1

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted VP9 Scalability Structure (SS) data. Insufficient bounds checking on the payload ...

Vendor: pjsip
Product: pjproject
Published: Mar 31, 2026
Source: NVD
CVE-2026-30281 CRITICAL - 9.8

An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Vendor: maru
Product: neo.maru
Published: Mar 31, 2026
Source: NVD
CVE-2026-30276 CRITICAL - 9.8

An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Vendor: deftpdf
Product: document_translator
Published: Mar 31, 2026
Source: NVD
CVE-2026-34532 CRITICAL - 9.1

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. When a ...

Vendor: parse-community
Product: parse-server
Published: Mar 31, 2026
Source: NVD
CVE-2026-34162 CRITICAL - 10.0

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy โ€” it accepts a user-supplied baseUrl, toolPath, HTTP method, custom headers, a...

Vendor: labring
Product: FastGPT
Published: Mar 31, 2026
Source: NVD
CVE-2026-30314 CRITICAL - 9.8

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operatio...

Vendor: ridvay
Product: auto-approval_module
Published: Mar 31, 2026
Source: NVD
CVE-2026-30312 CRITICAL - 9.8

DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on string-based parsing to validate commands; while it intercepts dangerous operators such as ;, &&, |...

Published: Mar 31, 2026
Source: NVD
CVE-2026-30311 CRITICAL - 9.8

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operatio...

Vendor: ridvay
Product: auto-approval_module
Published: Mar 31, 2026
Source: NVD
CVE-2026-0596 CRITICAL - 9.6

A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c` without proper sanitization. If the `model_uri` contains shell metacharacters, such as `$()` or backticks, it a...

Published: Mar 31, 2026
Source: NVD
CVE-2026-30310 CRITICAL - 9.8

In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a command to be potenti...

Published: Mar 31, 2026
Source: NVD
CVE-2026-34505 CRITICAL - 9.8

OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypass rate limits and brute-force webhook secrets. Attackers can submit repeated authentication requests with invalid secrets without triggering rate limit responses, enabling systema...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 31, 2026
Source: NVD
CVE-2026-32920 CRITICAL - 9.8

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenCl...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 31, 2026
Source: NVD
CVE-2026-32917 CRITICAL - 9.8

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 31, 2026
Source: NVD
CVE-2025-15618 CRITICAL - 9.1

Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::OnlinePayment::StoredTransaction generates a secret key by using a MD5 hash of a single call to the built-in rand function, which is unsuitable for cryptographic use. This key is intend...

Vendor: MOCK
Product: Business::OnlinePayment::StoredTransaction
Published: Mar 31, 2026
Source: NVD
CVE-2026-32714 CRITICAL - 9.8

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python's str.format() to construct SQL queries with user-supplied data (such as issuer and key_id). This allowed an attack...

Vendor: scitokens
Product: scitokens
Published: Mar 31, 2026
Source: NVD
CVE-2026-3300 CRITICAL - 9.8

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without p...

Published: Mar 31, 2026
Source: NVD
CVE-2026-30880 CRITICAL - 9.8

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue has been patched in version 5.2.3.

Vendor: baserproject
Product: basercms
Published: Mar 31, 2026
Source: NVD