Total CVEs

138,585

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,053
Quick preset (or use dates below)
Clear Filters
Showing 1,961 - 1,980 of 3,576 CVEs
CVE-2026-33873 CRITICAL - 9.9

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow executes LLM-generated Python code during its validation phase. Although this phase appears intended to validate generated component code, the implementati...

Vendor: pip
Product: langflow
Published: Mar 26, 2026
Source: GitHub
CVE-2026-33867 CRITICAL - 7.5

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext โ€” no hashing, salting, or encryption is applied. If an attacker gains read access to the d...

Vendor: composer
Product: wwbn/avideo
Published: Mar 26, 2026
Source: GitHub
CVE-2026-27816 CRITICAL - 9.1

EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_transfer_modes copies a variable-length list into a fixed-size array of length 6 without bounds checking. With schema validation disabled by default, oversized MQTT Cmd payloads can t...

Vendor: EVerest
Product: everest-core
Published: Mar 26, 2026
Source: NVD
CVE-2026-27815 CRITICAL - 9.1

EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup copies a variable-length payment_options list into a fixed-size array of length 2 without bounds checking. With schema validation disabled by default, oversized MQTT Cmd payloads can ...

Vendor: EVerest
Product: everest-core
Published: Mar 26, 2026
Source: NVD

dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earlier, an attacker with network access to ...

Vendor: maven
Product: com.datadoghq:dd-java-agent
Published: Mar 26, 2026
Source: GitHub
CVE-2026-33396 CRITICAL - 9.9

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monitor Playwright script execution. Synthetic monitor code is execut...

Vendor: OneUptime
Product: oneuptime
Published: Mar 26, 2026
Source: NVD
CVE-2026-4809 CRITICAL - 9.8

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while dec...

Published: Mar 26, 2026
Source: NVD
CVE-2014-125112 CRITICAL - 9.8

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vulnerability where it allows an attacker to execute arbitrary code on the server during deserialization of the cookie data, when t...

Vendor: MIYAGAWA
Product: Plack::Middleware::Session::Cookie
Published: Mar 26, 2026
Source: NVD
CVE-2026-4484 CRITICAL - 9.8

The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6. This is due to the plugin allowing a user to update the user role through the 'InstructorsController::prepare_object_for_database' function. This makes it possible for ...

Published: Mar 26, 2026
Source: NVD
CVE-2026-33942 CRITICAL - 9.8

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAuthenticator::unserialize() to restore OAuth token state from cache or storage, with allowed_classes => true. An attacker who can control the ser...

Vendor: saloonphp
Product: saloon
Published: Mar 26, 2026
Source: NVD
CVE-2026-33701 CRITICAL - 9.8

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, the RMI instrumentation registered a custom endpoint that deserialized incoming data without applying serialization filters. On JDK version 16 and earli...

Vendor: maven
Product: io.opentelemetry.javaagent:opentelemetry-javaagent
Published: Mar 25, 2026
Source: GitHub
CVE-2025-70888 CRITICAL - 9.8

An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component

Published: Mar 25, 2026
Source: NVD
CVE-2026-33670 CRITICAL - 9.8

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 25, 2026
Source: GitHub
CVE-2026-33669 CRITICAL - 9.8

SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 patches the issue.

Vendor: go
Product: github.com/siyuan-note/siyuan/kernel
Published: Mar 25, 2026
Source: GitHub
CVE-2026-33696 CRITICAL - 10.0

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes. By supplying a crafted parameters as part of...

Vendor: n8n-io
Product: n8n
Published: Mar 25, 2026
Source: NVD
CVE-2026-33660 CRITICAL - 10.0

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could use the Merge node's "Combine by SQL" mode to read local files on the n8n host and achieve remote code executio...

Vendor: n8n-io
Product: n8n
Published: Mar 25, 2026
Source: NVD
CVE-2026-32573 CRITICAL - 9.1

Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.This issue affects Nelio AB Testing: from n/a through <= 8.2.7.

Vendor: Nelio Software
Product: Nelio AB Testing
Published: Mar 25, 2026
Source: NVD
CVE-2026-32539 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Revisions revisionary allows Blind SQL Injection.This issue affects PublishPress Revisions: from n/a through <= 3.7.23.

Vendor: PublishPress
Product: PublishPress Revisions
Published: Mar 25, 2026
Source: NVD
CVE-2026-32536 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-downloads allows Using Malicious Files.This issue affects Green Downloads: from n/a through <= 2.08.

Vendor: halfdata
Product: Green Downloads
Published: Mar 25, 2026
Source: NVD
CVE-2026-32525 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1.

Vendor: jetmonsters
Product: JetFormBuilder
Published: Mar 25, 2026
Source: NVD