Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,921 - 1,940 of 3,443 CVEs
CVE-2018-25220 CRITICAL - 9.8

Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input string to the application. Attackers can craft a malicious payload with 1200 bytes of padding followed by a return-oriented programming chain to overwrite ...

Vendor: bochs
Product: BOCHS
Published: Mar 28, 2026
Source: NVD
CVE-2017-20229 CRITICAL - 9.8

MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can craft malicious input that overflows the stack buffer and execute a return-oriented programming ...

Vendor: mawk
Product: MAWK
Published: Mar 28, 2026
Source: NVD
CVE-2017-20227 CRITICAL - 9.8

JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boundaries. Attackers can craft malicious input passed to the jad command to overflow the stack and exec...

Vendor: Varaneckas
Product: JAD Java Decompiler
Published: Mar 28, 2026
Source: NVD
CVE-2017-20225 CRITICAL - 9.8

TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can trigger the overflow through command-line arguments passed to the application, leveraging ROP gadge...

Vendor: ticalc
Product: TiEmu
Published: Mar 28, 2026
Source: NVD
CVE-2016-20049 CRITICAL - 9.8

JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 8150 bytes to overflow the stack, overwrite return addre...

Vendor: Varaneckas
Product: JAD Java Decompiler
Published: Mar 28, 2026
Source: NVD
CVE-2025-9497 CRITICAL - 9.8

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.

Published: Mar 28, 2026
Source: NVD
CVE-2026-34202 CRITICAL - 7.5

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a specially crafted...

Vendor: rust
Product: zebrad
Published: Mar 27, 2026
Source: GitHub
CVE-2026-33976 CRITICAL - 9.6

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source p...

Vendor: streetwriters
Product: Notesnook Web/Desktop, Notesnook iOS/Android
Published: Mar 27, 2026
Source: NVD
CVE-2026-33875 CRITICAL - 9.3

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication flow hijacking, potentially allowing attackers to authenticate with the identities of victim users who click on a malicious deep link. Update Gematik...

Vendor: gematik
Product: app-Authenticator
Published: Mar 27, 2026
Source: NVD
CVE-2026-34205 CRITICAL - 9.6

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration...

Vendor: home-assistant
Product: Home Assistant Operating System, Home Assistant Supervisor
Published: Mar 27, 2026
Source: NVD
CVE-2026-34374 CRITICAL - 9.1

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by interpolating a stream key directly into the query string without parameterization. This method is called as a fallback from `LiveTransmition::keyExis...

Vendor: WWBN
Product: AVideo
Published: Mar 27, 2026
Source: NVD
CVE-2026-33937 CRITICAL - 9.8

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLiteral` AST node is emitted directly into the generated JavaScript w...

Vendor: npm
Product: handlebars
Published: Mar 27, 2026
Source: GitHub
CVE-2026-33992 CRITICAL - 6.5

pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download engine accepts arbitrary URLs without validation, enabling Server-Side Request Forgery (SSRF) attacks. An authenticated attacker can exploit this to access internal network ser...

Vendor: pip
Product: pyload-ng
Published: Mar 27, 2026
Source: GitHub
CVE-2026-30533 CRITICAL - 9.8

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.

Vendor: oretnom23
Product: online_food_ordering_system
Published: Mar 27, 2026
Source: NVD
CVE-2026-30532 CRITICAL - 9.8

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.

Vendor: oretnom23
Product: online_food_ordering_system
Published: Mar 27, 2026
Source: NVD
CVE-2026-30530 CRITICAL - 9.8

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject malicious S...

Vendor: oretnom23
Product: online_food_ordering_system
Published: Mar 27, 2026
Source: NVD
CVE-2026-30302 CRITICAL - 10.0

The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-based shell-quote library) to analyze commands on the ...

Vendor: coderider-kilo
Product: coderider
Published: Mar 27, 2026
Source: NVD
CVE-2026-30304 CRITICAL - 9.6

In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a command to be poten...

Vendor: tianguaduizhang
Product: ai_code
Published: Mar 27, 2026
Source: NVD
CVE-2026-30303 CRITICAL - 9.8

The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-based shell-quote library) to analyze commands on the Windo...

Vendor: matterai
Product: axon_code
Published: Mar 27, 2026
Source: NVD
CVE-2026-27876 CRITICAL - 9.1

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlEx...

Vendor: Grafana
Product: Grafana Enterprise
Published: Mar 27, 2026
Source: NVD