Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,901 - 1,920 of 3,443 CVEs
CVE-2026-2287 CRITICAL - 9.8

CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.

Vendor: crewai
Product: crewai
Published: Mar 30, 2026
Source: NVD
CVE-2026-2286 CRITICAL - 9.8

CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.

Vendor: crewai
Product: crewai
Published: Mar 30, 2026
Source: NVD
CVE-2026-2275 CRITICAL - 9.6

The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling.

Published: Mar 30, 2026
Source: NVD
CVE-2026-5128 CRITICAL - 10.0

A sensitive information exposure vulnerability exists in ArthurFiorette steam-trader 2.1.1. An unauthenticated attacker can send a request to the /usersย API endpoint to retrieve highly sensitive Steam account data, including the account username, password, identity secret, and shared secret. In addi...

Published: Mar 30, 2026
Source: NVD
CVE-2026-5121 CRITICAL - 9.8

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbi...

Published: Mar 30, 2026
Source: NVD
CVE-2025-15379 CRITICAL - 10.0

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_e...

Vendor: mlflow
Product: mlflow/mlflow
Published: Mar 30, 2026
Source: NVD
CVE-2025-15036 CRITICAL - 9.6

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member paths during extractio...

Vendor: mlflow
Product: mlflow/mlflow
Published: Mar 30, 2026
Source: NVD
CVE-2026-4176 CRITICAL - 9.8

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of z...

Published: Mar 29, 2026
Source: NVD
CVE-2026-34220 CRITICAL - 9.8

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL query fragments. This issue has been patched in versions 6.6.10 ...

Vendor: npm
Product: @mikro-orm/core
Published: Mar 29, 2026
Source: GitHub
CVE-2026-34243 CRITICAL - 9.8

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code e...

Vendor: actions
Product: njzjz/wenxian
Published: Mar 29, 2026
Source: GitHub
CVE-2026-32987 CRITICAL - 9.8

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairing scopes, including privilege escalation to operator.admin.

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 29, 2026
Source: NVD
CVE-2026-32975 CRITICAL - 9.8

OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create groups with identical names to allowlisted groups to bypass channel authorization and route messages fro...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 29, 2026
Source: NVD
CVE-2026-32973 CRITICAL - 9.8

OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard matching across path segments to execute commands or pat...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 29, 2026
Source: NVD
CVE-2026-32924 CRITICAL - 9.8

OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p conversations instead of group chats. Attackers can exploit this misclassification to bypass groupAllowFrom and requireMention protections in group ch...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 29, 2026
Source: NVD
CVE-2026-32922 CRITICAL - 9.9

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scopes to the caller's current scope set. Attackers can obtain operator.admin to...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 29, 2026
Source: NVD
CVE-2026-4851 CRITICAL - 9.8

GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Calls (RPC) over SSH for Perl. The client connects to remote hosts to execute code on them. A compromised or malicious remote host can execute arbitrary ...

Vendor: casiano
Product: grid\
Published: Mar 29, 2026
Source: NVD
CVE-2026-3256 CRITICAL - 9.8

HTTP::Session versions through 0.53 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash seeded with the built-in rand function, the high resolution epoch time, and the PID. The PID will come ...

Vendor: ktat
Product: http\
Published: Mar 28, 2026
Source: NVD
CVE-2025-15604 CRITICAL - 9.8

Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.06 through 6.16, the random_string function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it generates bytes by concatenating a SHA-1 has...

Vendor: TOKUHIROM
Product: Amon2
Published: Mar 28, 2026
Source: NVD
CVE-2018-25223 CRITICAL - 9.8

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially...

Vendor: crashmail
Product: Crashmail
Published: Mar 28, 2026
Source: NVD
CVE-2018-25221 CRITICAL - 9.8

EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to...

Vendor: Echatserver
Product: EChat Server
Published: Mar 28, 2026
Source: NVD