| CVE-2026-2364 |
CODESYS Installer TOCTOU Privilege Escalation |
10.03.2026 |
7.3 |
| CVE-2026-1508 |
Court Reservation < 1.10.9 - Event Deletion via CSRF |
10.03.2026 |
|
| CVE-2026-0953 |
Tutor LMS Pro <= 3.9.5 - Authentication Bypass via Social Login |
10.03.2026 |
9.8 |
| CVE-2025-2399 |
Denial of Service (DoS) Vulnerability in Mitsubishi Electric CNC Series |
10.03.2026 |
5.9 |
| CVE-2026-3585 |
The Events Calendar <= 6.15.17 - Authenticated (Author+) Arbitrary File Read via ajax_create_import |
10.03.2026 |
7.5 |
| CVE-2026-1919 |
Booktics <= 1.0.16 - Missing Authorization to Get Items via REST API endpoints |
10.03.2026 |
5.3 |
| CVE-2026-1920 |
Booktics <= 1.0.16 - Missing Authorization to Addon Plugin Installation |
10.03.2026 |
5.3 |
| CVE-2025-36173 |
InfoSphere Data Architect (IDA) 9.2.1 Vulnerability Fixes. |
10.03.2026 |
6.1 |
| CVE-2025-36105 |
IBM Planning Analytics Advanced Certified Containers is vulnerable to a sensitive information disclosure vulnerability |
10.03.2026 |
4.4 |
| CVE-2026-0489 |
DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service) |
10.03.2026 |
6.1 |
| CVE-2026-24309 |
Missing Authorization check in SAP NetWeaver Application Server for ABAP |
10.03.2026 |
6.4 |
| CVE-2026-24310 |
Missing Authorization check in SAP NetWeaver Application Server for ABAP |
10.03.2026 |
3.5 |
| CVE-2026-24311 |
Insecure Storage Protection vulnerability in SAP Customer Checkout 2.0 |
10.03.2026 |
5.6 |
| CVE-2026-24313 |
Missing Authorization check in SAP Solution Tools Plug-In (ST-PI) |
10.03.2026 |
5 |
| CVE-2026-24316 |
Server-Side Request Forgery (SSRF) in SAP NetWeaver Application Server for ABAP |
10.03.2026 |
6.4 |
| CVE-2026-24317 |
DLL Hijacking vulnerability in SAP GUI for Windows with active GuiXT |
10.03.2026 |
5 |
| CVE-2026-27684 |
SQL Injection Vulnerability in SAP NetWeaver (Feedback Notification) |
10.03.2026 |
6.4 |
| CVE-2026-27685 |
Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration |
10.03.2026 |
9.1 |
| CVE-2026-27686 |
Missing Authorization check in SAP Business Warehouse (Service API) |
10.03.2026 |
5.9 |
| CVE-2026-27687 |
Missing Authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal |
10.03.2026 |
5.8 |
| CVE-2026-27688 |
Missing Authorization check in SAP NetWeaver Application Server for ABAP |
10.03.2026 |
5 |
| CVE-2026-27689 |
Denial of service (DOS) in SAP Supply Chain Management |
10.03.2026 |
7.7 |
| CVE-2026-30925 |
Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery |
09.03.2026 |
|
| CVE-2026-30927 |
Admidio: Event participation IDOR - non-leaders can register other users for events via user_uuid parameter |
09.03.2026 |
|
| CVE-2026-30917 |
Stored XSS on Bucket namespace pages |
09.03.2026 |
|
| CVE-2026-30918 |
facileManager Affected by Reflected Cross-Site Scripting (XSS) |
09.03.2026 |
7.6 |
| CVE-2026-30919 |
facileManager Affected by Stored Cross-Site Scripting (XSS) |
09.03.2026 |
7.6 |
| CVE-2026-30920 |
OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding |
09.03.2026 |
8.6 |
| CVE-2026-30921 |
OneUptime Synthetic Monitor RCE via exposed Playwright browser object |
09.03.2026 |
10 |
| CVE-2026-30887 |
OneUptime Affected by Unsandboxed Code Execution in Probe Allows Any Project Member to Achieve RCE |
09.03.2026 |
10 |
| CVE-2026-30913 |
flarum/nickname: Display name injection in notification emails (autolink & markdown) |
09.03.2026 |
4.6 |
| CVE-2026-30916 |
Shescape has possible misidentification of shell due to link chains |
09.03.2026 |
|
| CVE-2026-28267 |
|
09.03.2026 |
|
| CVE-2026-29773 |
kubewarden-controller cross-namespace data exfiltration via deprecated host callback binding |
09.03.2026 |
4.3 |
| CVE-2026-30862 |
Critical Stored XSS & Privilege Escalation in Appsmith |
09.03.2026 |
9.1 |
| CVE-2026-30869 |
SiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret Leakage |
09.03.2026 |
9.3 |
| CVE-2026-30870 |
Some sync filters in PowerSync Service ignored using `config.edition: 3` |
09.03.2026 |
6.5 |
| CVE-2026-30885 |
WWBN AVideo - Unauthenticated IDOR - Playlist Information Disclosure |
09.03.2026 |
|
| CVE-2025-11158 |
Hitachi Vantara Pentaho Data Integration & Analytics - Missing Authorization |
09.03.2026 |
9.1 |
| CVE-2026-28281 |
InstantCMS has Multiple CSRF Vulnerabilities |
09.03.2026 |
7.1 |
| CVE-2026-28512 |
Pocket ID: OAuth redirect_uri validation bypass via userinfo/host confusion |
09.03.2026 |
7.1 |
| CVE-2026-28513 |
Pocket ID: OIDC authorization code validation uses AND instead of OR, allowing cross-client token exchange |
09.03.2026 |
8.5 |
| CVE-2026-30929 |
ImageMagick has a stack buffer overflow in MagnifyImage |
09.03.2026 |
7.7 |
| CVE-2026-30931 |
ImageMagick has a heap-based buffer overflow in UHDR encoder |
09.03.2026 |
6.8 |
| CVE-2026-30935 |
ImageMagick has a heap Buffer Over-Read in BilateralBlurImage |
09.03.2026 |
4.4 |
| CVE-2026-30936 |
ImageMagick has a heap Buffer Overflow in WaveletDenoiseImage |
09.03.2026 |
5.5 |
| CVE-2026-30937 |
ImageMagick has a heap buffer overflow in WriteXWDImage due to CARD32 arithmetic overflow in bytes_per_line calculation |
09.03.2026 |
6.8 |
| CVE-2026-28494 |
ImageMagick affected by stack corruption through long morphology kernel names or arrays |
09.03.2026 |
7.1 |
| CVE-2026-28686 |
ImageMagick has a write heap-buffer-overflow in PCL encoder via undersized output buffer |
09.03.2026 |
6.8 |
| CVE-2026-28687 |
ImageMagick has a Heap Use-After-Free in ImageMagick MSL decoder |
09.03.2026 |
5.3 |
| CVE-2026-28688 |
ImageMagick has a heap use-after-free in the MSL encoder |
09.03.2026 |
4 |
| CVE-2026-28689 |
ImageMagick has a Path Policy TOCTOU symlink race bypass |
09.03.2026 |
6.3 |
| CVE-2026-28690 |
ImageMagick has a stack write buffer overflow in MNG encoder |
09.03.2026 |
6.9 |
| CVE-2026-28691 |
ImageMagick has an uninitialized pointer dereference in JBIG decoder |
09.03.2026 |
7.5 |
| CVE-2026-28692 |
ImageMagick has a heap buffer over-read via 32-bit integer overflow in MAT decoder |
09.03.2026 |
4.8 |
| CVE-2026-28693 |
ImageMagick has an integer overflow in DIB coder can result in out of bounds read or write |
09.03.2026 |
8.1 |
| CVE-2026-30883 |
ImageMagick has a Heap Overflow when writing extremely large image profile in the PNG encoder |
09.03.2026 |
5.7 |
| CVE-2026-28431 |
Misskey lacks proper authorization checks and input validation |
09.03.2026 |
|
| CVE-2026-28432 |
HTTP signature verification can be bypassed |
09.03.2026 |
|
| CVE-2026-28433 |
Misskey lacks resource ownership validation |
09.03.2026 |
|
| CVE-2026-28493 |
ImageMagick has a Integer Overflow leading to out of bounds write in SIXEL decoder |
09.03.2026 |
6.5 |
| CVE-2026-1776 |
Camaleon CMS AWS Uploader Authenticated Path Traversal Arbitrary File Read |
09.03.2026 |
|
| CVE-2026-26982 |
Ghostty affected by arbitrary command execution via control characters in paste and drag-and-drop operations |
09.03.2026 |
6.3 |
| CVE-2026-30926 |
SiYuan Note publish service authorization bypass allows low-privilege users to modify notebook content |
09.03.2026 |
7.1 |
| CVE-2026-31802 |
node-tar Symlink Path Traversal via Drive-Relative Linkpath |
09.03.2026 |
|
| CVE-2026-25960 |
SSRF Protection Bypass in vLLM |
09.03.2026 |
7.1 |
| CVE-2026-30240 |
Budibase PWA ZIP Upload Path Traversal Allows Reading Arbitrary Server Files Including All Environment Secrets |
09.03.2026 |
9.6 |
| CVE-2026-31816 |
Budibase Universal Auth Bypass via Webhook Query Param Injection |
09.03.2026 |
9.1 |
| CVE-2026-3288 |
ingress-nginx rewrite-target nginx configuration injection |
09.03.2026 |
8.8 |
| CVE-2025-15603 |
open-webui JWT Key start_windows.bat random values |
09.03.2026 |
|
| CVE-2025-70028 |
|
09.03.2026 |
|
| CVE-2025-70973 |
|
09.03.2026 |
|
| CVE-2026-25045 |
Budibase Critical Privilege Escalation & IDOR via Missing RBAC on User Role Management (Creator-Role) |
09.03.2026 |
|
| CVE-2026-25737 |
Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS) |
09.03.2026 |
8.9 |
| CVE-2026-25041 |
Budibase has a Command Injection in PostgreSQL Dump Command |
09.03.2026 |
|
| CVE-2025-62166 |
FreshRSS has an IDOR which allows for viewing feeds of any user and leaking tokens |
09.03.2026 |
7.5 |
| CVE-2025-68402 |
FreshRSS has an authentication bypass due to truncated bcrypt hash [edge branch] |
09.03.2026 |
|
| CVE-2025-70030 |
|
09.03.2026 |
|
| CVE-2025-70031 |
|
09.03.2026 |
|
| CVE-2026-0846 |
Arbitrary File Read via Absolute Path Input in nltk.util.filestring() |
09.03.2026 |
|
| CVE-2025-70032 |
|
09.03.2026 |
|
| CVE-2026-3638 |
|
09.03.2026 |
|
| CVE-2026-30140 |
|
09.03.2026 |
|
| CVE-2026-29023 |
Keygraph Shannon Hard-coded Router API Key |
09.03.2026 |
|
| CVE-2025-70033 |
|
09.03.2026 |
|
| CVE-2025-70034 |
|
09.03.2026 |
|
| CVE-2025-70038 |
|
09.03.2026 |
|
| CVE-2025-70039 |
|
09.03.2026 |
|
| CVE-2025-70037 |
|
09.03.2026 |
|
| CVE-2025-15568 |
Command Injection Vulnerability on TP-Link Archer AXE75 |
10.03.2026 |
|
| CVE-2024-14027 |
xattr: switch to CLASS(fd) |
09.03.2026 |
|
| CVE-2025-70040 |
|
09.03.2026 |
|
| CVE-2025-70060 |
|
09.03.2026 |
|
| CVE-2026-3588 |
Server-Side Request Forgery (SSRF) in ikea dirigera |
09.03.2026 |
7.5 |
| CVE-2025-70042 |
|
09.03.2026 |
|
| CVE-2025-70046 |
|
09.03.2026 |
|
| CVE-2025-70050 |
|
09.03.2026 |
|
| CVE-2026-25866 |
MobaXterm < 26.1 Notepad++ Unquoted Service Path |
09.03.2026 |
|
| CVE-2025-70047 |
|
09.03.2026 |
|
| CVE-2025-70048 |
|
09.03.2026 |
|
| CVE-2025-70059 |
|
09.03.2026 |
|
| CVE-2025-70238 |
|
09.03.2026 |
|
| CVE-2025-69647 |
|
09.03.2026 |
|
| CVE-2025-69648 |
|
09.03.2026 |
|
| CVE-2025-70243 |
|
09.03.2026 |
|
| CVE-2025-70250 |
|
09.03.2026 |
|
| CVE-2026-3089 |
Actual Sync Server 26.2.1 - Authenticated Path Traversal |
09.03.2026 |
|
| CVE-2026-2919 |
Attacker-controlled content shown under spoofed domains in Focus for iOS via stalled navigation and iframe redirect |
09.03.2026 |
|
| CVE-2026-3819 |
SourceCodester Resort Reservation System Reservation Management page cross site scripting |
09.03.2026 |
|
| CVE-2026-21736 |
GPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabled |
09.03.2026 |
|
| CVE-2026-2261 |
blocklistd(8) socket leak |
09.03.2026 |
|
| CVE-2026-3038 |
Local DoS and possible privilege escalation via routing sockets |
09.03.2026 |
|
| CVE-2025-15576 |
Jail chroot escape via fd exchange with a different jail |
09.03.2026 |
|
| CVE-2026-3818 |
Tiandy Easy7 CMS Windows GetDBData.jsp sql injection |
09.03.2026 |
|
| CVE-2025-15547 |
Jail escape by a privileged user via nullfs |
09.03.2026 |
|
| CVE-2025-14558 |
Remote code execution via ND6 Router Advertisements |
10.03.2026 |
|
| CVE-2025-14769 |
ipfw denial of service |
09.03.2026 |
|
| CVE-2026-3817 |
SourceCodester Patients Waiting Area Queue Management System patient-search.php improper authorization |
09.03.2026 |
|
| CVE-2026-3816 |
OWASP DefectDojo SonarQubeParser/MSDefenderParser parser.py input_zip.read denial of service |
09.03.2026 |
|
| CVE-2026-25604 |
Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass |
09.03.2026 |
|
| CVE-2026-3815 |
UTT HiPER 810G formApMail strcpy buffer overflow |
09.03.2026 |
|