Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,881 - 1,900 of 3,443 CVEs
CVE-2026-30877 CRITICAL - 9.1

baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in the update functionality. Due to this issue, an authenticated user with administrator privileges in baserCMS can execute arbitrary OS commands on the server with the privileges of t...

Vendor: baserproject
Product: basercms
Published: Mar 31, 2026
Source: NVD
CVE-2026-21861 CRITICAL - 9.1

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server due to improper handling of user-controlled input that is dire...

Vendor: baserproject
Product: basercms
Published: Mar 31, 2026
Source: NVD
CVE-2026-4257 CRITICAL - 9.8

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined wi...

Published: Mar 30, 2026
Source: NVD
CVE-2026-4789 CRITICAL - 9.8

Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access

Vendor: kyverno
Product: kyverno
Published: Mar 30, 2026
Source: NVD
CVE-2026-34558 CRITICAL - 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input within the Methods Management functionality when creating or manag...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Mar 30, 2026
Source: NVD
CVE-2026-34557 CRITICAL - 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input within group and role management functionality. Multiple input fie...

Vendor: ci4-cms-erp
Product: ci4ms
Published: Mar 30, 2026
Source: NVD
CVE-2026-31946 CRITICAL - 9.8

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version 20.2.5, OpenOLAT's OpenID Connect implicit flow implementation does not verify JWT signatures. The JSONWebToken.parse() method silently discards t...

Vendor: OpenOLAT
Product: OpenOLAT
Published: Mar 30, 2026
Source: NVD
CVE-2026-30313 CRITICAL - 9.8

DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on string-based parsing to validate commands; while it intercepts dangerous operators such as ;, &&, |...

Published: Mar 30, 2026
Source: NVD
CVE-2026-30308 CRITICAL - 9.8

In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe commands and Execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a co...

Published: Mar 30, 2026
Source: NVD
CVE-2026-30306 CRITICAL - 9.8

In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a command to be poten...

Published: Mar 30, 2026
Source: NVD
CVE-2026-32275 CRITICAL - 9.1

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP callback parameter allows cross-origin script injection and API key theft. This issue has been patched in version 2.17.0.

Vendor: Tautulli
Product: Tautulli
Published: Mar 30, 2026
Source: NVD
CVE-2026-30307 CRITICAL - 9.8

Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations,...

Vendor: roocode
Product: roo_code
Published: Mar 30, 2026
Source: NVD
CVE-2026-30305 CRITICAL - 9.8

Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it...

Published: Mar 30, 2026
Source: NVD
CVE-2026-28505 CRITICAL - 10.0

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handler.py implements a sandboxed eval() for notification text templates. The sandbox attempts to restrict callable names by inspecting code.co_names of the...

Vendor: Tautulli
Product: Tautulli
Published: Mar 30, 2026
Source: NVD
CVE-2026-34714 CRITICAL - 9.2

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

Vendor: Vim
Product: Vim
Published: Mar 30, 2026
Source: NVD
CVE-2026-33032 CRITICAL - 9.8

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message e...

Vendor: 0xJacky
Product: nginx-ui
Published: Mar 30, 2026
Source: NVD
CVE-2026-34361 CRITICAL - 9.3

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined with a star...

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.validation
Published: Mar 30, 2026
Source: GitHub
CVE-2026-34156 CRITICAL - 10.0

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require allowlist (controlled by WORKFLOW_SCRIPT_...

Vendor: npm
Product: @nocobase/plugin-workflow-javascript
Published: Mar 30, 2026
Source: GitHub
CVE-2026-33026 CRITICAL - 9.1

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.

Vendor: go
Product: github.com/0xJacky/Nginx-UI
Published: Mar 30, 2026
Source: GitHub
CVE-2026-30562 CRITICAL - 9.3

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web scrip...

Vendor: ahsanriaz26gmailcom
Product: sales_and_inventory_system
Published: Mar 30, 2026
Source: NVD