Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,056
Quick preset (or use dates below)
Clear Filters
Showing 1,901 - 1,920 of 3,576 CVEs
CVE-2026-28505 CRITICAL - 10.0

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handler.py implements a sandboxed eval() for notification text templates. The sandbox attempts to restrict callable names by inspecting code.co_names of the...

Vendor: Tautulli
Product: Tautulli
Published: Mar 30, 2026
Source: NVD
CVE-2026-34714 CRITICAL - 9.2

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

Vendor: Vim
Product: Vim
Published: Mar 30, 2026
Source: NVD
CVE-2026-33032 CRITICAL - 9.8

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message e...

Vendor: 0xJacky
Product: nginx-ui
Published: Mar 30, 2026
Source: NVD
CVE-2026-34361 CRITICAL - 9.3

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined with a star...

Vendor: maven
Product: ca.uhn.hapi.fhir:org.hl7.fhir.validation
Published: Mar 30, 2026
Source: GitHub
CVE-2026-34156 CRITICAL - 10.0

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require allowlist (controlled by WORKFLOW_SCRIPT_...

Vendor: npm
Product: @nocobase/plugin-workflow-javascript
Published: Mar 30, 2026
Source: GitHub
CVE-2026-33026 CRITICAL - 9.1

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.

Vendor: go
Product: github.com/0xJacky/Nginx-UI
Published: Mar 30, 2026
Source: GitHub
CVE-2026-30562 CRITICAL - 9.3

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web scrip...

Vendor: ahsanriaz26gmailcom
Product: sales_and_inventory_system
Published: Mar 30, 2026
Source: NVD
CVE-2026-2287 CRITICAL - 9.8

CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.

Vendor: crewai
Product: crewai
Published: Mar 30, 2026
Source: NVD
CVE-2026-2286 CRITICAL - 9.8

CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.

Vendor: crewai
Product: crewai
Published: Mar 30, 2026
Source: NVD
CVE-2026-2275 CRITICAL - 9.6

The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling.

Published: Mar 30, 2026
Source: NVD
CVE-2026-5128 CRITICAL - 10.0

A sensitive information exposure vulnerability exists in ArthurFiorette steam-trader 2.1.1. An unauthenticated attacker can send a request to the /users API endpoint to retrieve highly sensitive Steam account data, including the account username, password, identity secret, and shared secret. In addi...

Published: Mar 30, 2026
Source: NVD
CVE-2026-5121 CRITICAL - 9.8

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbi...

Published: Mar 30, 2026
Source: NVD
CVE-2025-15379 CRITICAL - 10.0

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency specifications from the model artifact's `python_e...

Vendor: mlflow
Product: mlflow/mlflow
Published: Mar 30, 2026
Source: NVD
CVE-2025-15036 CRITICAL - 9.6

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due to the lack of validation of tar member paths during extractio...

Vendor: mlflow
Product: mlflow/mlflow
Published: Mar 30, 2026
Source: NVD
CVE-2026-4176 CRITICAL - 9.8

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib. Compress::Raw::Zlib is included in the Perl package as a dual-life core module, and is vulnerable to CVE-2026-3381 due to a vendored version of z...

Published: Mar 29, 2026
Source: NVD
CVE-2026-34220 CRITICAL - 9.8

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL query fragments. This issue has been patched in versions 6.6.10 ...

Vendor: npm
Product: @mikro-orm/core
Published: Mar 29, 2026
Source: GitHub
CVE-2026-34243 CRITICAL - 9.8

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code e...

Vendor: actions
Product: njzjz/wenxian
Published: Mar 29, 2026
Source: GitHub
CVE-2026-32987 CRITICAL - 9.8

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairing scopes, including privilege escalation to operator.admin.

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 29, 2026
Source: NVD
CVE-2026-32975 CRITICAL - 9.8

OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create groups with identical names to allowlisted groups to bypass channel authorization and route messages fro...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 29, 2026
Source: NVD
CVE-2026-32973 CRITICAL - 9.8

OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX paths. Attackers can exploit the ? wildcard matching across path segments to execute commands or pat...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 29, 2026
Source: NVD