Total CVEs

116,961

Critical Severity

1,419

High Severity

4,677

Last 7 Days

1,106
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 13,366 CVEs
CVE-2026-33054 CRITICAL - 10.0

Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion

Vendor: pip
Product: mesop
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33177 MEDIUM - 4.3

Statamic is missing authorization check on taxonomy term creation via fieldtype

Vendor: composer
Product: statamic/cms
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33171 MEDIUM - 4.3

Statamic has a path traversal in file dictionary fieldtype

Vendor: composer
Product: statamic/cms
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33172 HIGH - 8.7

Statamic has Stored XSS via SVG Sanitization Bypass

Vendor: composer
Product: statamic/cms
Published: Mar 18, 2026
Source: GitHub

Gossipsub PRUNE.backoff Duration Overflow

Vendor: rust
Product: libp2p-gossipsub
Published: Mar 18, 2026
Source: GitHub
CVE-2026-33166 HIGH - 8.6

Allure Report has an Arbitrary File Read via Path Traversal in Attachment Processing (Allure 1, Allure 2, and XCTest Readers)

Vendor: maven
Product: io.qameta.allure:allure-generator
Published: Mar 18, 2026
Source: GitHub

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the LiveQuery server leaks protected fields and `authData` to all subscribers of tha...

Vendor: npm
Product: parse-server
Published: Mar 18, 2026
Source: GitHub
CVE-2026-32731 CRITICAL - 10.0

ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `gzip.js` constructs file-write paths using `fs.createWriteStream(path.join(exportPath, header.name))`. `path.join()` does not resolve or sanitise trave...

Vendor: npm
Product: @apostrophecms/import-export
Published: Mar 18, 2026
Source: GitHub
CVE-2026-32730 HIGH - 8.1

ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incorrect MongoDB query that allows incomplete login tokens โ€” where the password was verified but TOTP/MF...

Vendor: npm
Product: apostrophe
Published: Mar 18, 2026
Source: GitHub

pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

Published: Mar 18, 2026
Source: NVD

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the `cram_decode_slice()` function called while reading CRAM records, validation of the reference id field occurred too late, allowing two out of bounds r...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data using a variety of encodings and compression methods. While most alignment records store DNA sequence and quality values, the format also allows them to omit...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one method of removing redundant data, CRAM uses reference-based compression so that instead of storing the full sequence for each alignment record it sto...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD

Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting...

Published: Mar 18, 2026
Source: NVD

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. While most alignment records store DNA sequence and quality values, the format also allows them to omit this data in certain cases to save space. Due to some...

Vendor: samtools
Product: htslib
Published: Mar 18, 2026
Source: NVD

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB

Published: Mar 18, 2026
Source: NVD

A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi endpoint improperly sanitizes user-supplied input provided to a command-related parameter in the sysCMD functionality.

Published: Mar 18, 2026
Source: NVD

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to bypass authentication by directly accessing restricted web application endpoints...

Published: Mar 18, 2026
Source: NVD

The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of Server Side Include) within multiple server-side web pages, including login.shtml and settings.shtml. These pages embed server-side execution directives...

Published: Mar 18, 2026
Source: NVD

A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized before being stored and rendered in the chat conversation history. This allows an attacker to inject arbitrary JavaScript code which is executed when th...

Published: Mar 18, 2026
Source: NVD