Critical Vulnerabilities

382 advisories

CVE-2026-40317

Apr 18, 2026

Critical (9.3)

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers witho...

Read Advisory

CVE-2026-40324

Apr 18, 2026

Critical (9.1)

Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth limit. A cr...

Read Advisory

CVE-2026-40484

Apr 18, 2026

Critical (9.1)

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directo...

Read Advisory

CVE-2026-40572

Apr 18, 2026

Critical (9.0)

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address r...

Read Advisory

CVE-2026-37749

Apr 17, 2026

Critical (9.8)

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php....

Read Advisory

CVE-2026-40351

Apr 17, 2026

Critical (9.8)

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attack...

Read Advisory

CVE-2026-40477

Apr 17, 2026

Critical (9.0)

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Al...

Read Advisory

CVE-2026-40478

Apr 17, 2026

Critical (9.0)

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms...

Read Advisory

CVE-2026-31843

Apr 16, 2026

Critical (9.8)

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment ...

Read Advisory

CVE-2026-37338

Apr 16, 2026

Critical (9.4)

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php....

Read Advisory

CVE-2026-37347

Apr 16, 2026

Critical (9.1)

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php....

Read Advisory

CVE-2026-37345

Apr 16, 2026

Critical (9.8)

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php....

Read Advisory

CVE-2026-40322

Apr 16, 2026

Critical (9.0)

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the ...

Read Advisory

CVE-2026-20147

Apr 15, 2026

Critical (9.9)

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vul...

Read Advisory

CVE-2026-20180

Apr 15, 2026

Critical (9.9)

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit...

Read Advisory

CVE-2026-20184

Apr 15, 2026

Critical (9.8)

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service. ...

Read Advisory

CVE-2026-20186

Apr 15, 2026

Critical (9.9)

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit...

Read Advisory

CVE-2026-6296

Apr 15, 2026

Critical (9.6)

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)...

Read Advisory

CVE-2025-63939

Apr 14, 2026

Critical (9.8)

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter....

Read Advisory

CVE-2025-65135

Apr 14, 2026

Critical (9.8)

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.php through the fromdate POST parameter....

Read Advisory

CVE-2026-27243

Apr 14, 2026

Critical (9.3)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerab...

Read Advisory

CVE-2026-27245

Apr 14, 2026

Critical (9.3)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerab...

Read Advisory

CVE-2026-27246

Apr 14, 2026

Critical (9.3)

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execu...

Read Advisory

CVE-2026-27681

Apr 14, 2026

Critical (9.9)

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute crafted SQL statements to read, modify, and delete dat...

Read Advisory

CVE-2026-33824

Apr 14, 2026

Critical (9.8)

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network....

Read Advisory

CVE-2026-34457

Apr 14, 2026

Critical (9.1)

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy ...

Read Advisory

CVE-2026-39399

Apr 14, 2026

Critical (9.6)

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. An attacker can supply a...

Read Advisory

CVE-2026-39808

Apr 14, 2026

Critical (9.8)

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code ...

Read Advisory

CVE-2026-39813

Apr 14, 2026

Critical (9.8)

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here...

Read Advisory

CVE-2026-40288

Apr 14, 2026

Critical (9.8)

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command and code execution through untrus...

Read Advisory

CVE-2026-40313

Apr 14, 2026

Critical (9.1)

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known credential leakage vector caused by using actions/chec...

Read Advisory

CVE-2026-40289

Apr 14, 2026

Critical (9.1)

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote ses...

Read Advisory

CVE-2026-22562

Apr 13, 2026

Critical (9.8)

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code exec...

Read Advisory

CVE-2026-40044

Apr 13, 2026

Critical (9.8)

Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PH...

Read Advisory

CVE-2026-6139

Apr 13, 2026

Critical (9.8)

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of...

Read Advisory

CVE-2026-6112

Apr 12, 2026

Critical (9.8)

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the ar...

Read Advisory

CVE-2026-6113

Apr 12, 2026

Critical (9.8)

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTtyServiceCfg of the file /cgi-bin/cstecgi.cgi of the component C...

Read Advisory

CVE-2026-6114

Apr 12, 2026

Critical (9.8)

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a ...

Read Advisory

CVE-2026-6115

Apr 12, 2026

Critical (9.8)

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setAppCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argum...

Read Advisory

CVE-2026-6116

Apr 12, 2026

Critical (9.8)

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The mani...

Read Advisory

CVE-2026-31845

Apr 11, 2026

Critical (9.3)

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects...

Read Advisory

CVE-2026-4149

Apr 11, 2026

Critical (10.0)

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Au...

Read Advisory

CVE-2026-5058

Apr 11, 2026

Critical (9.8)

aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authentication i...

Read Advisory

CVE-2026-5059

Apr 11, 2026

Critical (9.8)

aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aws-mcp-server. Authenti...

Read Advisory

CVE-2026-1115

Apr 10, 2026

Critical (9.6)

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` fu...

Read Advisory

CVE-2026-32892

Apr 10, 2026

Critical (9.1)

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.li...

Read Advisory

CVE-2026-40175

Apr 10, 2026

Critical (10.0)

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-part...

Read Advisory

CVE-2026-33784

Apr 9, 2026

Critical (9.8)

A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows an unauthenticated, network-based attacker to take full control o...

Read Advisory

CVE-2026-34424

Apr 9, 2026

Critical (9.8)

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute ...

Read Advisory

CVE-2026-39980

Apr 9, 2026

Critical (9.1)

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage...

Read Advisory

CVE-2026-40088

Apr 9, 2026

Critical (9.6)

PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled input via agent workflows, YAML definitions, and LLM...

Read Advisory

CVE-2026-40089

Apr 9, 2026

Critical (9.9)

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API c...

Read Advisory

CVE-2026-40154

Apr 9, 2026

Critical (9.3)

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confir...

Read Advisory

CVE-2026-5976

Apr 9, 2026

Critical (9.8)

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipu...

Read Advisory

CVE-2026-39860

Apr 8, 2026

Critical (9.0)

Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically...

Read Advisory

CVE-2026-39888

Apr 8, 2026

Critical (9.9)

PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a ...

Read Advisory

CVE-2026-39890

Apr 8, 2026

Critical (9.8)

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/functio...

Read Advisory

CVE-2026-40035

Apr 8, 2026

Critical (9.1)

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed dire...

Read Advisory

CVE-2021-4473

Apr 7, 2026

Critical (9.8)

Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated attackers to execute arbitrary commands by supplyi...

Read Advisory

CVE-2026-35490

Apr 7, 2026

Critical (9.8)

changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. I...

Read Advisory

CVE-2026-35573

Apr 7, 2026

Critical (9.1)

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary...

Read Advisory

CVE-2026-35580

Apr 7, 2026

Critical (9.1)

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated di...

Read Advisory

CVE-2026-39337

Apr 7, 2026

Critical (10.0)

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to in...

Read Advisory

CVE-2026-39339

Apr 7, 2026

Critical (9.1)

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allow...

Read Advisory

CVE-2026-39355

Apr 7, 2026

Critical (9.9)

Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the genealogy application allows any authenticated user to transfer ownership of arbitrary...

Read Advisory

CVE-2026-5731

Apr 7, 2026

Critical (9.8)

Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and w...

Read Advisory

CVE-2026-5734

Apr 7, 2026

Critical (9.8)

Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with en...

Read Advisory

CVE-2026-5735

Apr 7, 2026

Critical (9.8)

Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...

Read Advisory

CVE-2025-54328

Apr 6, 2026

Critical (10.0)

An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 9110, W920, W930, W1000, Mod...

Read Advisory

CVE-2026-34208

Apr 6, 2026

Critical (10.0)

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can be bypassed through an expo...

Read Advisory

CVE-2026-34841

Apr 6, 2026

Critical (9.8)

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidd...

Read Advisory

CVE-2026-34976

Apr 6, 2026

Critical (10.0)

Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenti...

Read Advisory

CVE-2026-35022

Apr 6, 2026

Critical (9.8)

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in authentication helper execution where helper configuration values are executed using shell=true without ...

Read Advisory

CVE-2019-25687

Apr 5, 2026

Critical (9.8)

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionalit...

Read Advisory

CVE-2016-20052

Apr 4, 2026

Critical (9.8)

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can u...

Read Advisory

CVE-2018-25254

Apr 4, 2026

Critical (9.8)

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to...

Read Advisory

CVE-2026-35616

Apr 4, 2026

Critical (9.8)

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests....

Read Advisory

CVE-2018-25236

Apr 3, 2026

Critical (9.8)

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthentica...

Read Advisory

CVE-2026-26135

Apr 3, 2026

Critical (9.6)

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-28373

Apr 3, 2026

Critical (9.6)

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can...

Read Advisory

CVE-2026-32211

Apr 3, 2026

Critical (9.1)

Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network....

Read Advisory

CVE-2026-32213

Apr 3, 2026

Critical (10.0)

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-33105

Apr 3, 2026

Critical (10.0)

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-33107

Apr 3, 2026

Critical (10.0)

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-34612

Apr 3, 2026

Critical (9.9)

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execu...

Read Advisory

CVE-2026-34934

Apr 3, 2026

Critical (9.8)

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with unescaped thread IDs fetched from the database. An a...

Read Advisory

CVE-2026-34938

Apr 3, 2026

Critical (10.0)

PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing ...

Read Advisory

CVE-2026-34935

Apr 3, 2026

Critical (9.8)

PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and forwarded through the call chain to anyio.open_pro...

Read Advisory

CVE-2026-34952

Apr 3, 2026

Critical (9.1)

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any netwo...

Read Advisory

CVE-2026-34953

Apr 3, 2026

Critical (9.1)

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal store, which is empty by default. Any HTTP request ...

Read Advisory

CVE-2026-34758

Apr 2, 2026

Critical (9.1)

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/Wha...

Read Advisory

CVE-2026-20093

Apr 1, 2026

Critical (9.8)

A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the sys...

Read Advisory

CVE-2026-20160

Apr 1, 2026

Critical (9.8)

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SS...

Read Advisory

CVE-2026-29014

Apr 1, 2026

Critical (9.8)

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP...

Read Advisory

CVE-2026-34456

Apr 1, 2026

Critical (9.1)

Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth...

Read Advisory

CVE-2026-34563

Apr 1, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34559

Apr 1, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34566

Apr 1, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34567

Apr 1, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34569

Apr 1, 2026

Critical (9.9)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34571

Apr 1, 2026

Critical (9.9)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (...

Read Advisory

CVE-2026-32714

Mar 31, 2026

Critical (9.8)

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python's str.format() to co...

Read Advisory

CVE-2026-34156

Mar 31, 2026

Critical (9.9)

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScr...

Read Advisory

CVE-2026-34243

Mar 31, 2026

Critical (9.8)

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_com...

Read Advisory

CVE-2026-34361

Mar 31, 2026

Critical (9.3)

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" en...

Read Advisory

CVE-2026-34448

Mar 31, 2026

Critical (9.0)

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gall...

Read Advisory

CVE-2026-34449

Mar 31, 2026

Critical (9.6)

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS po...

Read Advisory

CVE-2025-15036

Mar 30, 2026

Critical (9.6)

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present ...

Read Advisory

CVE-2025-15379

Mar 30, 2026

Critical (10.0)

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_...

Read Advisory

CVE-2026-30562

Mar 30, 2026

Critical (9.3)

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The applic...

Read Advisory

CVE-2026-33032

Mar 30, 2026

Critical (9.8)

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /...

Read Advisory

CVE-2026-34557

Mar 30, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-34558

Mar 30, 2026

Critical (9.1)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to proper...

Read Advisory

CVE-2026-32922

Mar 29, 2026

Critical (9.9)

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrai...

Read Advisory

CVE-2026-32924

Mar 29, 2026

Critical (9.8)

OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p conversations instead of group chats. Attackers ca...

Read Advisory

CVE-2026-32973

Mar 29, 2026

Critical (9.8)

OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lowercasing and glob matching that overmatches on POSIX ...

Read Advisory

CVE-2026-32975

Mar 29, 2026

Critical (9.8)

OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attackers can create grou...

Read Advisory

CVE-2026-32987

Mar 29, 2026

Critical (9.8)

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times be...

Read Advisory

CVE-2016-20049

Mar 28, 2026

Critical (9.8)

JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers ...

Read Advisory

CVE-2017-20225

Mar 28, 2026

Critical (9.8)

TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can...

Read Advisory

CVE-2017-20229

Mar 28, 2026

Critical (9.8)

MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers ...

Read Advisory

CVE-2017-20227

Mar 28, 2026

Critical (9.8)

JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that exceeds buffer boun...

Read Advisory

CVE-2026-22738

Mar 27, 2026

Critical (9.8)

In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. ...

Read Advisory

CVE-2026-27876

Mar 27, 2026

Critical (9.1)

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always ...

Read Advisory

CVE-2026-30302

Mar 27, 2026

Critical (10.0)

The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect us...

Read Advisory

CVE-2026-30303

Mar 27, 2026

Critical (9.8)

The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of ...

Read Advisory

CVE-2026-30530

Mar 27, 2026

Critical (9.8)

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user...

Read Advisory

CVE-2026-30532

Mar 27, 2026

Critical (9.8)

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter....

Read Advisory

CVE-2026-30533

Mar 27, 2026

Critical (9.8)

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter....

Read Advisory

CVE-2026-33937

Mar 27, 2026

Critical (9.8)

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string....

Read Advisory

CVE-2026-33976

Mar 27, 2026

Critical (9.6)

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the deskto...

Read Advisory

CVE-2026-34205

Mar 27, 2026

Critical (9.6)

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoi...

Read Advisory

CVE-2026-33152

Mar 26, 2026

Critical (9.1)

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with BasicAuthenticati...

Read Advisory

CVE-2026-4809

Mar 26, 2026

Critical (9.8)

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling....

Read Advisory

CVE-2026-25366

Mar 25, 2026

Critical (9.9)

Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1....

Read Advisory

CVE-2026-26830

Mar 25, 2026

Critical (9.8)

pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to i...

Read Advisory

CVE-2026-26832

Mar 25, 2026

Critical (9.8)

node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. T...

Read Advisory

CVE-2026-33286

Mar 24, 2026

Critical (9.1)

Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affects Graphiti'...

Read Advisory

CVE-2026-4001

Mar 24, 2026

Critical (9.8)

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_c...

Read Advisory

CVE-2026-4688

Mar 24, 2026

Critical (10.0)

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9....

Read Advisory

CVE-2026-4691

Mar 24, 2026

Critical (9.8)

Use-after-free in the CSS Parsing and Computation component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9....

Read Advisory

CVE-2026-4696

Mar 24, 2026

Critical (9.8)

Use-after-free in the Layout: Text and Fonts component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9....

Read Advisory

CVE-2026-4698

Mar 24, 2026

Critical (9.8)

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9....

Read Advisory

CVE-2026-4701

Mar 24, 2026

Critical (9.8)

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9....

Read Advisory

CVE-2026-4700

Mar 24, 2026

Critical (9.8)

Mitigation bypass in the Networking: HTTP component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9....

Read Advisory

CVE-2026-4705

Mar 24, 2026

Critical (9.8)

Undefined behavior in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9....

Read Advisory

CVE-2026-4702

Mar 24, 2026

Critical (9.8)

JIT miscompilation in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9....

Read Advisory

CVE-2026-4725

Mar 24, 2026

Critical (10.0)

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149 and Thunderbird < 149....

Read Advisory

CVE-2026-4755

Mar 24, 2026

Critical (9.8)

CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11....

Read Advisory

CVE-2026-32968

Mar 23, 2026

Critical (9.8)

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system...

Read Advisory

CVE-2026-33297

Mar 23, 2026

Critical (9.1)

WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due t...

Read Advisory

CVE-2026-33351

Mar 23, 2026

Critical (9.1)

WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live p...

Read Advisory

CVE-2026-33352

Mar 23, 2026

Critical (9.8)

WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. The `doNotShowC...

Read Advisory

CVE-2026-33478

Mar 23, 2026

Critical (10.0)

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker ...

Read Advisory

CVE-2026-33502

Mar 23, 2026

Critical (9.3)

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to mak...

Read Advisory

CVE-2026-33716

Mar 23, 2026

Critical (9.4)

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplie...

Read Advisory

CVE-2026-3587

Mar 23, 2026

Critical (10.0)

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface and gain root access to the underlying Linux based OS, leading to full compromise ...

Read Advisory

CVE-2026-4567

Mar 23, 2026

Critical (9.8)

A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulation of the argument File leads to stack-based buffe...

Read Advisory

CVE-2026-4599

Mar 23, 2026

Critical (9.1)

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functio...

Read Advisory

CVE-2019-25614

Mar 22, 2026

Critical (9.8)

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized paylo...

Read Advisory

CVE-2019-25568

Mar 21, 2026

Critical (9.8)

Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwri...

Read Advisory

CVE-2026-21992

Mar 20, 2026

Critical (9.8)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Servi...

Read Advisory

CVE-2026-32890

Mar 20, 2026

Critical (9.6)

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and below, a stored Cross-site Scripting (XSS) vulnera...

Read Advisory

CVE-2026-32938

Mar 20, 2026

Critical (9.9)

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// links in pasted HTML into the workspa...

Read Advisory

CVE-2026-32940

Mar 20, 2026

Critical (9.3)

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist — it blocks data:text/html and data:image/svg+xml in href attributes but misses d...

Read Advisory

CVE-2026-32985

Mar 20, 2026

Critical (9.8)

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality. The issue exists in /website_code/php/import/import...

Read Advisory

CVE-2026-33054

Mar 20, 2026

Critical (10.0)

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_toke...

Read Advisory

CVE-2026-33057

Mar 20, 2026

Critical (9.8)

Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai/ testing module infrastructure directly ingests un...

Read Advisory

CVE-2026-33135

Mar 20, 2026

Critical (9.3)

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_memorandoo.php endpoint. An attacker can inject arbit...

Read Advisory

CVE-2026-33134

Mar 20, 2026

Critical (9.3)

WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto.php endpoint. The vulnerability a...

Read Advisory

CVE-2026-33136

Mar 20, 2026

Critical (9.3)

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An attacker can inj...

Read Advisory

CVE-2026-33186

Mar 20, 2026

Critical (9.1)

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go serve...

Read Advisory

CVE-2026-27542

Mar 19, 2026

Critical (9.8)

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a th...

Read Advisory

CVE-2026-32038

Mar 19, 2026

Critical (9.8)

OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network namespace. Attackers can configure the docker.netw...

Read Advisory

CVE-2026-32169

Mar 19, 2026

Critical (10.0)

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network....

Read Advisory

CVE-2026-32191

Mar 19, 2026

Critical (9.8)

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network....

Read Advisory

CVE-2026-32194

Mar 19, 2026

Critical (9.8)

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network....

Read Advisory

CVE-2026-32754

Mar 19, 2026

Critical (9.3)

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification...

Read Advisory

CVE-2026-25873

Mar 18, 2026

Critical (9.8)

OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST req...

Read Advisory

CVE-2026-31938

Mar 18, 2026

Critical (9.6)

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the `output` function allows attackers to inject arbitrary HTML (such as scripts) i...

Read Advisory

CVE-2026-32698

Mar 18, 2026

Critical (9.1)

OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2.1 are vulnerable to an SQL injection attack via a custom field's name. When tha...

Read Advisory

CVE-2026-32731

Mar 18, 2026

Critical (9.9)

ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.crea...

Read Advisory

CVE-2026-21994

Mar 17, 2026

Critical (9.8)

Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affected is 0.3.0....

Read Advisory

CVE-2026-25534

Mar 17, 2026

Critical (9.1)

### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly handle undersc...

Read Advisory

CVE-2026-3564

Mar 17, 2026

Critical (9.0)

A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scen...

Read Advisory

CVE-2016-20026

Mar 16, 2026

Critical (9.8)

ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manager application. Attackers can authenticate with hard...

Read Advisory

CVE-2016-20030

Mar 16, 2026

Critical (9.8)

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the username parameter. Attack...

Read Advisory

CVE-2026-27962

Mar 16, 2026

Critical (9.1)

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attack...

Read Advisory

CVE-2026-32621

Mar 16, 2026

Critical (9.9)

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within th...

Read Advisory

CVE-2026-32626

Mar 16, 2026

Critical (9.6)

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vu...

Read Advisory

CVE-2026-4170

Mar 16, 2026

Critical (9.8)

A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/management/nmc_sync.php of the component HTTP Request Han...

Read Advisory

CVE-2026-25823

Mar 13, 2026

Critical (9.8)

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stack buffer overflow that leads to a Denial of Service...

Read Advisory

CVE-2026-26954

Mar 13, 2026

Critical (10.0)

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Function, and Object.fr...

Read Advisory

CVE-2026-31886

Mar 13, 2026

Critical (9.1)

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoints is passed directly into filepath.Join to constru...

Read Advisory

CVE-2026-32301

Mar 13, 2026

Critical (9.3)

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when configured with a dynamic JWKS endpoint URL using ...

Read Advisory

CVE-2026-32304

Mar 13, 2026

Critical (9.8)

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function ...

Read Advisory

CVE-2026-3891

Mar 13, 2026

Critical (9.8)

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' ...

Read Advisory

CVE-2026-21708

Mar 12, 2026

Critical (9.9)

A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user....

Read Advisory

CVE-2019-25471

Mar 11, 2026

Critical (9.8)

FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint. Attackers can upload ZIP files c...

Read Advisory

CVE-2019-25487

Mar 11, 2026

Critical (9.8)

SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endp...

Read Advisory

CVE-2026-27591

Mar 11, 2026

Critical (9.9)

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their...

Read Advisory

CVE-2026-28229

Mar 11, 2026

Critical (9.8)

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve Wo...

Read Advisory

CVE-2026-30903

Mar 11, 2026

Critical (9.6)

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access....

Read Advisory

CVE-2026-31852

Mar 11, 2026

Critical (10.0)

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due...

Read Advisory

CVE-2026-31896

Mar 11, 2026

Critical (9.8)

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produto_ocultar.php script uses extract(...

Read Advisory

CVE-2026-31957

Mar 11, 2026

Critical (10.0)

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentica...

Read Advisory

CVE-2026-32096

Mar 11, 2026

Critical (9.3)

Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vulnerability existed in the SNS webhook handler. An unauthenticated attacker could...

Read Advisory

CVE-2025-48611

Mar 10, 2026

Critical (10.0)

In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. ...

Read Advisory

CVE-2026-27685

Mar 10, 2026

Critical (9.1)

SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentialit...

Read Advisory

CVE-2026-28292

Mar 10, 2026

Critical (9.8)

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and...

Read Advisory

CVE-2026-28495

Mar 10, 2026

Critical (9.6)

GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php configuration fi...

Read Advisory

CVE-2026-30869

Mar 10, 2026

Critical (9.3)

SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By expl...

Read Advisory

CVE-2026-30887

Mar 10, 2026

Critical (9.9)

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites...

Read Advisory

CVE-2026-30966

Mar 10, 2026

Critical (10.0)

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field ma...

Read Advisory

CVE-2026-3843

Mar 10, 2026

Critical (9.8)

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially craf...

Read Advisory

CVE-2026-30240

Mar 9, 2026

Critical (9.6)

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in the PWA (Progressive Web App) ZIP processing endpoint...

Read Advisory

CVE-2026-3703

Mar 8, 2026

Critical (9.8)

A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Executing a manipulation of the argument ipaddr can lead to out-of-bounds write. T...

Read Advisory

CVE-2026-30861

Mar 7, 2026

Critical (9.9)

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated remote code execution (RCE) vulnera...

Read Advisory

CVE-2026-30860

Mar 7, 2026

Critical (9.9)

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's da...

Read Advisory

CVE-2026-28501

Mar 6, 2026

Critical (9.8)

WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components...

Read Advisory

CVE-2026-29183

Mar 6, 2026

Critical (9.3)

SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability exists in the dynamic icon API endpoint "GET /api/icon/getDynamicIcon" when typ...

Read Advisory

CVE-2026-29789

Mar 6, 2026

Critical (9.9)

Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Prior to version 3.20.3, a missing authorization check in workflow site-creation ac...

Read Advisory

CVE-2026-0848

Mar 5, 2026

Critical (10.0)

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verific...

Read Advisory

CVE-2026-21536

Mar 5, 2026

Critical (9.8)

Microsoft Devices Pricing Program Remote Code Execution Vulnerability...

Read Advisory

CVE-2026-24457

Mar 5, 2026

Critical (9.1)

An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In s...

Read Advisory

CVE-2026-2599

Mar 5, 2026

Critical (9.8)

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input ...

Read Advisory

CVE-2026-27944

Mar 5, 2026

Critical (9.8)

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt t...

Read Advisory

CVE-2026-28391

Mar 5, 2026

Critical (9.8)

OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests, allowing attackers to bypass command approval restrictions. Remote attack...

Read Advisory

CVE-2026-28392

Mar 5, 2026

Critical (9.8)

OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any direct message sender when dmPolicy is set to open ...

Read Advisory

CVE-2026-28469

Mar 5, 2026

Critical (9.8)

OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that allows cross-account policy context misrouting when multiple webhook targets shar...

Read Advisory

CVE-2026-28474

Mar 5, 2026

Critical (9.8)

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room all...

Read Advisory

CVE-2026-20079

Mar 4, 2026

Critical (10.0)

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an a...

Read Advisory

CVE-2026-20131

Mar 4, 2026

Critical (10.0)

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root o...

Read Advisory

CVE-2025-59059

Mar 3, 2026

Critical (9.8)

Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue....

Read Advisory

CVE-2026-22891

Mar 3, 2026

Critical (9.8)

A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead...

Read Advisory

CVE-2026-26266

Mar 3, 2026

Critical (9.3)

AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client ve...

Read Advisory

CVE-2026-26279

Mar 3, 2026

Critical (9.1)

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields dec...

Read Advisory

CVE-2026-27012

Mar 3, 2026

Critical (9.8)

OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allo...

Read Advisory

CVE-2026-28289

Mar 3, 2026

Critical (10.0)

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with f...

Read Advisory

CVE-2026-26710

Mar 2, 2026

Critical (9.8)

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php....

Read Advisory

CVE-2026-26711

Mar 2, 2026

Critical (9.8)

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php....

Read Advisory

CVE-2026-26712

Mar 2, 2026

Critical (9.8)

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php....

Read Advisory

CVE-2026-26713

Mar 2, 2026

Critical (9.8)

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php....

Read Advisory

CVE-2026-2999

Mar 2, 2026

Critical (9.8)

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from ...

Read Advisory

CVE-2026-3000

Mar 2, 2026

Critical (9.8)

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remot...

Read Advisory

CVE-2026-3431

Mar 2, 2026

Critical (9.8)

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endp...

Read Advisory

CVE-2025-11251

Feb 27, 2026

Critical (9.8)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows SQL Injection.This issue affec...

Read Advisory

CVE-2025-11252

Feb 27, 2026

Critical (9.8)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects w...

Read Advisory

CVE-2025-12981

Feb 27, 2026

Critical (9.8)

The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugin's user regi...

Read Advisory

CVE-2026-20781

Feb 27, 2026

Critical (9.4)

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can c...

Read Advisory

CVE-2026-21718

Feb 27, 2026

Critical (10.0)

An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execut...

Read Advisory

CVE-2026-2251

Feb 27, 2026

Critical (9.8)

Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow ...

Read Advisory

CVE-2026-24352

Feb 27, 2026

Critical (9.8)

PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID ...

Read Advisory

CVE-2026-24731

Feb 27, 2026

Critical (9.4)

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can c...

Read Advisory

CVE-2026-25851

Feb 27, 2026

Critical (9.4)

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can c...

Read Advisory

CVE-2026-2749

Feb 27, 2026

Critical (9.9)

Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, ...

Read Advisory

CVE-2026-27751

Feb 27, 2026

Critical (9.8)

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attacke...

Read Advisory

CVE-2026-27755

Feb 27, 2026

Critical (9.8)

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5...

Read Advisory

CVE-2026-27767

Feb 27, 2026

Critical (9.4)

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can c...

Read Advisory

CVE-2026-27772

Feb 27, 2026

Critical (9.4)

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can c...

Read Advisory

CVE-2026-28268

Feb 27, 2026

Critical (9.8)

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password r...

Read Advisory

CVE-2026-28363

Feb 27, 2026

Critical (9.9)

In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free executio...

Read Advisory

CVE-2026-28409

Feb 27, 2026

Critical (10.0)

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. A...

Read Advisory

CVE-2026-3301

Feb 27, 2026

Critical (9.8)

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Managemen...

Read Advisory

CVE-2025-50857

Feb 26, 2026

Critical (9.8)

ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code via a crafted file upload...

Read Advisory

CVE-2026-27941

Feb 26, 2026

Critical (9.9)

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out a...

Read Advisory

CVE-2026-27966

Feb 26, 2026

Critical (9.8)

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes...

Read Advisory

CVE-2026-28213

Feb 26, 2026

Critical (9.8)

EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response returns...

Read Advisory

CVE-2025-62878

Feb 25, 2026

Critical (9.9)

A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended ...

Read Advisory

CVE-2026-20127

Feb 25, 2026

Critical (10.0)

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, r...

Read Advisory

CVE-2026-20129

Feb 25, 2026

Critical (9.8)

A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the&nbsp;netadmin...

Read Advisory

CVE-2026-21902

Feb 25, 2026

Critical (9.8)

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-b...

Read Advisory

CVE-2026-24908

Feb 25, 2026

Critical (9.9)

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Patient REST API endpoint allows ...

Read Advisory

CVE-2026-24849

Feb 25, 2026

Critical (9.9)

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenti...

Read Advisory

CVE-2026-25785

Feb 25, 2026

Critical (9.8)

Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbitr...

Read Advisory

CVE-2026-2624

Feb 25, 2026

Critical (9.8)

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass.This issue affects Antikor N...

Read Advisory

CVE-2026-27597

Feb 25, 2026

Critical (10.0)

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be use...

Read Advisory

CVE-2026-27626

Feb 25, 2026

Critical (9.9)

OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) blocks several dange...

Read Advisory

CVE-2026-27637

Feb 25, 2026

Critical (9.8)

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication token computed as `MD5...

Read Advisory

CVE-2026-27641

Feb 25, 2026

Critical (9.8)

Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and re...

Read Advisory

CVE-2026-27702

Feb 25, 2026

Critical (9.9)

Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability in Budibase's view filtering implementation allows a...

Read Advisory

CVE-2026-27728

Feb 25, 2026

Critical (9.9)

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated...

Read Advisory

CVE-2025-13942

Feb 24, 2026

Critical (9.8)

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an ...

Read Advisory

CVE-2025-40538

Feb 24, 2026

Critical (9.1)

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via do...

Read Advisory

CVE-2025-40539

Feb 24, 2026

Critical (9.1)

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative pr...

Read Advisory

CVE-2025-40540

Feb 24, 2026

Critical (9.1)

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative pr...

Read Advisory

CVE-2025-40541

Feb 24, 2026

Critical (9.1)

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue require...

Read Advisory

CVE-2026-21410

Feb 24, 2026

Critical (9.8)

InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution....

Read Advisory

CVE-2026-22553

Feb 24, 2026

Critical (9.8)

All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able t...

Read Advisory

CVE-2026-26198

Feb 24, 2026

Critical (9.8)

Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-supplied column names directly into `sql...

Read Advisory

CVE-2026-27507

Feb 24, 2026

Critical (9.8)

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed by users. Knowledge of these credentials allows ful...

Read Advisory

CVE-2026-27593

Feb 24, 2026

Critical (9.3)

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's ...

Read Advisory

CVE-2025-70043

Feb 23, 2026

Critical (9.1)

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in...

Read Advisory

CVE-2026-23693

Feb 23, 2026

Critical (10.0)

ElementsKit Lite (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts cl...

Read Advisory

CVE-2026-24494

Feb 23, 2026

Critical (9.8)

SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a ...

Read Advisory

CVE-2026-27197

Feb 21, 2026

Critical (9.1)

Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to ta...

Read Advisory

CVE-2026-27574

Feb 21, 2026

Critical (9.9)

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a secur...

Read Advisory

CVE-2019-25441

Feb 20, 2026

Critical (9.8)

thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the run_command endpoint. Attackers...

Read Advisory

CVE-2021-35402

Feb 20, 2026

Critical (10.0)

PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status)....

Read Advisory

CVE-2025-10970

Feb 20, 2026

Critical (9.8)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL Injection.This issue affects Talentics: through 200...

Read Advisory

CVE-2025-30411

Feb 20, 2026

Critical (10.0)

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (...

Read Advisory

CVE-2025-30412

Feb 20, 2026

Critical (10.0)

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (...

Read Advisory

CVE-2025-30416

Feb 20, 2026

Critical (10.0)

Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Li...

Read Advisory

CVE-2026-25715

Feb 20, 2026

Critical (9.8)

The web management interface of the device allows the administrator username and password to be set to blank values. Once applied, the device permits authentication with empty credentials over the w...

Read Advisory

CVE-2026-25896

Feb 20, 2026

Critical (9.3)

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entit...

Read Advisory

CVE-2026-2635

Feb 20, 2026

Critical (9.8)

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not requi...

Read Advisory

CVE-2025-12107

Feb 19, 2026

Critical (10.0)

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. Successful...

Read Advisory

CVE-2025-12882

Feb 19, 2026

Critical (9.8)

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set...

Read Advisory

CVE-2025-13563

Feb 19, 2026

Critical (9.8)

The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_lms_pro_register_user_front_end' function not restri...

Read Advisory

CVE-2025-13851

Feb 19, 2026

Critical (9.8)

The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.0.7. This is due to the plugi...

Read Advisory

CVE-2026-0926

Feb 19, 2026

Critical (9.8)

The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.9 via the 'parameters[template_name]' parameter. This makes it possible for un...

Read Advisory

CVE-2026-1405

Feb 19, 2026

Critical (9.8)

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and includ...

Read Advisory

CVE-2026-1994

Feb 19, 2026

Critical (9.8)

The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's id...

Read Advisory

CVE-2026-23542

Feb 19, 2026

Critical (9.8)

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10....

Read Advisory

CVE-2026-25242

Feb 19, 2026

Critical (9.8)

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSigninView setting is disabled (default), any ...

Read Advisory

CVE-2026-26030

Feb 19, 2026

Critical (9.9)

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The ...

Read Advisory

CVE-2026-2686

Feb 19, 2026

Critical (9.8)

A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. The manipulation of the argument User leads to os c...

Read Advisory

CVE-2019-25360

Feb 18, 2026

Critical (9.8)

Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code by crafting a specially designed payload. Attackers ...

Read Advisory

CVE-2019-25361

Feb 18, 2026

Critical (9.8)

Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted SYST comman...

Read Advisory

CVE-2019-25362

Feb 18, 2026

Critical (9.8)

WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers c...

Read Advisory

CVE-2019-25364

Feb 18, 2026

Critical (9.8)

MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers can send a crafted oversized buffer to the POP3 ser...

Read Advisory

CVE-2019-25365

Feb 18, 2026

Critical (9.8)

ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by overwriting the Structured Exception Handler. Attackers...

Read Advisory

CVE-2025-14009

Feb 18, 2026

Critical (10.0)

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path ...

Read Advisory

CVE-2025-65791

Feb 18, 2026

Critical (9.8)

ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function....

Read Advisory

CVE-2025-70149

Feb 18, 2026

Critical (9.8)

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter....

Read Advisory

CVE-2025-70150

Feb 18, 2026

Critical (9.8)

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id par...

Read Advisory

CVE-2025-70152

Feb 18, 2026

Critical (9.8)

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack...

Read Advisory

CVE-2025-70998

Feb 18, 2026

Critical (9.8)

UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowing a remote attacker to gain root access via a craft...

Read Advisory

CVE-2026-1435

Feb 18, 2026

Critical (9.8)

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId...

Read Advisory

CVE-2026-1937

Feb 18, 2026

Critical (9.8)

The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yayma...

Read Advisory

CVE-2026-27174

Feb 18, 2026

Critical (9.8)

MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in modules/panel.class.php causes execution to contin...

Read Advisory

CVE-2026-27175

Feb 18, 2026

Critical (9.8)

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is interpolated into a command string within double qu...

Read Advisory

CVE-2026-27180

Feb 18, 2026

Critical (9.8)

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning. The saverestore module exposes its admin() method...

Read Advisory

CVE-2025-65753

Feb 17, 2026

Critical (9.0)

An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root....

Read Advisory

CVE-2025-70830

Feb 17, 2026

Critical (9.9)

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker ...

Read Advisory

CVE-2026-1670

Feb 17, 2026

Critical (9.8)

The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address....

Read Advisory

CVE-2026-22208

Feb 17, 2026

Critical (9.6)

OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contain a remote code execution vulnerability via an unrestricted Lua interpreter. The Portrayal Engine initializes Lua usi...

Read Advisory

CVE-2026-22769

Feb 17, 2026

Critical (10.0)

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of...

Read Advisory

CVE-2026-23647

Feb 17, 2026

Critical (9.8)

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user...

Read Advisory

CVE-2025-15578

Feb 16, 2026

Critical (9.8)

Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in...

Read Advisory

CVE-2025-65717

Feb 16, 2026

Critical (9.1)

An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page....

Read Advisory

CVE-2026-2439

Feb 16, 2026

Critical (9.8)

Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uuidgen command to gene...

Read Advisory

CVE-2026-2550

Feb 16, 2026

Critical (9.8)

A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack ma...

Read Advisory

CVE-2026-2577

Feb 16, 2026

Critical (10.0)

The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauthe...

Read Advisory

CVE-2025-32058

Feb 15, 2026

Critical (9.3)

The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability duri...

Read Advisory

CVE-2026-1490

Feb 15, 2026

Critical (9.8)

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoof...

Read Advisory

CVE-2026-26366

Feb 15, 2026

Critical (9.8)

eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Un...

Read Advisory

CVE-2026-26369

Feb 15, 2026

Critical (9.8)

eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can s...

Read Advisory

CVE-2025-8572

Feb 14, 2026

Critical (9.8)

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user ...

Read Advisory

CVE-2026-1306

Feb 14, 2026

Critical (9.8)

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1...

Read Advisory

CVE-2025-69633

Feb 13, 2026

Critical (9.8)

A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7) allows remote unauthenticated attackers to execut...

Read Advisory

CVE-2025-69770

Feb 13, 2026

Critical (10.0)

A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file....

Read Advisory

CVE-2026-26190

Feb 13, 2026

Critical (9.8)

Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr deb...

Read Advisory

CVE-2026-26273

Feb 13, 2026

Critical (9.8)

Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset token within a hidden ...

Read Advisory

CVE-2019-25319

Feb 12, 2026

Critical (9.8)

Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft ...

Read Advisory

CVE-2019-25321

Feb 12, 2026

Critical (9.8)

FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious ...

Read Advisory

CVE-2019-25327

Feb 12, 2026

Critical (9.8)

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and pas...

Read Advisory

CVE-2019-25337

Feb 12, 2026

Critical (9.8)

OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /...

Read Advisory

CVE-2020-37167

Feb 12, 2026

Critical (9.8)

ClamAV ClamBC bytecode interpreter contains a vulnerability in function name processing that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation in ...

Read Advisory

CVE-2025-10969

Feb 12, 2026

Critical (9.8)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Blind SQL Injection.This issue...

Read Advisory

CVE-2025-14014

Feb 12, 2026

Critical (9.8)

Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality N...

Read Advisory

CVE-2025-69634

Feb 12, 2026

Critical (9.0)

Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is disputed by a third party who ind...

Read Advisory

CVE-2025-70314

Feb 12, 2026

Critical (9.8)

webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable...

Read Advisory

CVE-2025-70981

Feb 12, 2026

Critical (9.8)

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter....

Read Advisory

CVE-2026-1358

Feb 12, 2026

Critical (9.8)

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain r...

Read Advisory

CVE-2026-25227

Feb 12, 2026

Critical (9.1)

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping ...

Read Advisory

CVE-2026-26216

Feb 12, 2026

Critical (10.0)

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using...

Read Advisory

CVE-2026-26219

Feb 12, 2026

Critical (9.1)

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who ob...

Read Advisory

CVE-2026-26218

Feb 12, 2026

Critical (9.8)

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset t...

Read Advisory

CVE-2025-64075

Feb 11, 2026

Critical (10.0)

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by ...

Read Advisory

CVE-2025-66277

Feb 11, 2026

Critical (9.8)

A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended loc...

Read Advisory

CVE-2025-8025

Feb 11, 2026

Critical (9.8)

Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs.This iss...

Read Advisory

CVE-2026-1357

Feb 11, 2026

Critical (9.8)

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper...

Read Advisory

CVE-2026-0488

Feb 10, 2026

Critical (9.9)

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the abi...

Read Advisory

CVE-2026-26009

Feb 10, 2026

Critical (9.9)

Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server templates execute directly on the host operating syst...

Read Advisory

CVE-2026-1615

Feb 9, 2026

Critical (9.8)

All versions of the package jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JS...

Read Advisory

CVE-2026-1868

Feb 9, 2026

Critical (9.9)

GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in w...

Read Advisory

CVE-2026-22903

Feb 9, 2026

Critical (9.8)

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to c...

Read Advisory

CVE-2026-22904

Feb 9, 2026

Critical (9.8)

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resultin...

Read Advisory

CVE-2026-22906

Feb 9, 2026

Critical (9.8)

User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords...

Read Advisory

CVE-2025-15027

Feb 8, 2026

Critical (9.8)

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user met...

Read Advisory

CVE-2024-0001

Jan 15, 2024

Critical (9.8)

A critical remote code execution vulnerability in Example Software allows attackers to execute arbitrary code...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.