Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,941 - 1,960 of 3,443 CVEs
CVE-2026-25101 CRITICAL - 9.8

Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in version 3.17.2.

Vendor: Bludit
Product: Bludit
Published: Mar 27, 2026
Source: NVD
CVE-2026-22738 CRITICAL - 9.8

In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVectorStore and pass user-supplied input as a filter expression key...

Vendor: Spring
Product: Spring AI
Published: Mar 27, 2026
Source: NVD
CVE-2026-33890 CRITICAL - 9.8

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitrary passkey and subsequently authenticate with it to obtain a full admin session. The application exposes passkey registration endpoints without requiri...

Vendor: franklioxygen
Product: MyTube
Published: Mar 27, 2026
Source: NVD
CVE-2026-33945 CRITICAL - 9.9

Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something like `systemd.credentia...

Vendor: lxc
Product: incus
Published: Mar 27, 2026
Source: NVD
CVE-2026-33897 CRITICAL - 9.9

Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances which can be used at various times in the instance lifecycle to templ...

Vendor: lxc
Product: incus
Published: Mar 26, 2026
Source: NVD
CVE-2026-33640 CRITICAL - 9.8

Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identity Provider. Starting in version 0.86.0 and prior to version 1.6.0, Outline does not invalidate OTP codes based on amount or frequency of invalid submis...

Vendor: outline
Product: outline
Published: Mar 26, 2026
Source: NVD
CVE-2026-33152 CRITICAL - 9.1

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with BasicAuthentication as one of the default authentication backends. The AllAuth rate limiting configuration (ACCOUNT_R...

Vendor: TandoorRecipes
Product: recipes
Published: Mar 26, 2026
Source: NVD
CVE-2026-30458 CRITICAL - 9.1

An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

Vendor: thedaylightstudio
Product: fuel_cms
Published: Mar 26, 2026
Source: NVD
CVE-2026-30457 CRITICAL - 9.8

An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.

Vendor: thedaylightstudio
Product: dwoo
Published: Mar 26, 2026
Source: NVD

Convict has Prototype Pollution via startsWith() function

Vendor: npm
Product: convict
Published: Mar 26, 2026
Source: GitHub

Convict has prototype pollution via load(), loadFile(), and schema initialization

Vendor: npm
Product: convict
Published: Mar 26, 2026
Source: GitHub
CVE-2026-33758 CRITICAL - 6.1

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on the page for a faile...

Vendor: go
Product: github.com/openbao/openbao
Published: Mar 26, 2026
Source: GitHub
CVE-2026-33757 CRITICAL - 9.6

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and perform "remote ...

Vendor: go
Product: github.com/openbao/openbao
Published: Mar 26, 2026
Source: GitHub
CVE-2026-33873 CRITICAL - 9.9

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow executes LLM-generated Python code during its validation phase. Although this phase appears intended to validate generated component code, the implementati...

Vendor: pip
Product: langflow
Published: Mar 26, 2026
Source: GitHub
CVE-2026-33867 CRITICAL - 7.5

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or encryption is applied. If an attacker gains read access to the d...

Vendor: composer
Product: wwbn/avideo
Published: Mar 26, 2026
Source: GitHub
CVE-2026-27816 CRITICAL - 9.1

EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_transfer_modes copies a variable-length list into a fixed-size array of length 6 without bounds checking. With schema validation disabled by default, oversized MQTT Cmd payloads can t...

Vendor: EVerest
Product: everest-core
Published: Mar 26, 2026
Source: NVD
CVE-2026-27815 CRITICAL - 9.1

EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup copies a variable-length payment_options list into a fixed-size array of length 2 without bounds checking. With schema validation disabled by default, oversized MQTT Cmd payloads can ...

Vendor: EVerest
Product: everest-core
Published: Mar 26, 2026
Source: NVD

dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to ...

Vendor: maven
Product: com.datadoghq:dd-java-agent
Published: Mar 26, 2026
Source: GitHub
CVE-2026-33396 CRITICAL - 9.9

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monitor Playwright script execution. Synthetic monitor code is execut...

Vendor: OneUptime
Product: oneuptime
Published: Mar 26, 2026
Source: NVD
CVE-2026-4809 CRITICAL - 9.8

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while dec...

Published: Mar 26, 2026
Source: NVD