| CVE-2024-51222 |
|
23.03.2026 |
|
| CVE-2024-51223 |
|
23.03.2026 |
|
| CVE-2024-51224 |
|
23.03.2026 |
|
| CVE-2024-51225 |
|
23.03.2026 |
|
| CVE-2024-51226 |
|
23.03.2026 |
|
| CVE-2026-33488 |
AVideo has a PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in LoginControl Plugin |
23.03.2026 |
7.4 |
| CVE-2026-33492 |
AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration |
23.03.2026 |
7.3 |
| CVE-2026-4591 |
kalcaddle kodbox fileThumb Endpoint app.php checkBin os command injection |
23.03.2026 |
|
| CVE-2026-4404 |
Use of hard coded credentials in GoHarbor Harbor |
23.03.2026 |
|
| CVE-2026-4590 |
kalcaddle kodbox loginSubmit API index.class.php cross-site request forgery |
23.03.2026 |
|
| CVE-2026-33354 |
AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php` |
23.03.2026 |
7.6 |
| CVE-2026-33478 |
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection |
23.03.2026 |
10 |
| CVE-2026-33479 |
AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin |
23.03.2026 |
8.8 |
| CVE-2026-33480 |
AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy |
23.03.2026 |
8.6 |
| CVE-2026-33482 |
AVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand() |
23.03.2026 |
8.1 |
| CVE-2026-33483 |
AVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.php |
23.03.2026 |
7.5 |
| CVE-2026-33485 |
AVideo has an Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream Name Parameter |
23.03.2026 |
7.5 |
| CVE-2019-25620 |
Tree Studio 2.17 Denial of Service via Malformed Input |
23.03.2026 |
|
| CVE-2019-25621 |
Pixel Studio 2.17 Denial of Service via Malformed Input |
23.03.2026 |
|
| CVE-2019-25622 |
Paint Studio 2.17 Denial of Service via Malformed Input |
23.03.2026 |
|
| CVE-2019-25623 |
Luminance Studio 2.17 Denial of Service via Malformed Input |
23.03.2026 |
|
| CVE-2019-25624 |
Liquid Studio 2.17 Denial of Service via Malformed Input |
23.03.2026 |
|
| CVE-2019-25625 |
Blob Studio 2.17 Denial of Service via Malformed Input |
23.03.2026 |
|
| CVE-2026-33297 |
AVideo has an IDOR - Any Admin Can Set Another User's Channel Password via setPassword.json.php |
23.03.2026 |
|
| CVE-2026-33351 |
AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass |
23.03.2026 |
9.1 |
| CVE-2026-33352 |
AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass) |
23.03.2026 |
9.8 |
| CVE-2026-3635 |
Fastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function |
23.03.2026 |
6.1 |
| CVE-2026-4589 |
kalcaddle kodbox fileGet Endpoint editor.class.php PathDriverUrl server-side request forgery |
23.03.2026 |
|
| CVE-2026-4645 |
Github.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions |
23.03.2026 |
|
| CVE-2026-4647 |
Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library |
23.03.2026 |
|
| CVE-2025-41008 |
SQL Injection in Sinturno |
23.03.2026 |
|
| CVE-2026-1958 |
Hard-coded passwords in KlinikaXP |
23.03.2026 |
|
| CVE-2026-4587 |
HybridAuth SSL Curl.php certificate validation |
23.03.2026 |
|
| CVE-2026-4588 |
kalcaddle kodbox Site-level API key shareOut.class.php shareSafeGroup hard-coded key |
23.03.2026 |
|
| CVE-2025-41007 |
SQL Injection in Cuantis |
23.03.2026 |
|
| CVE-2026-31847 |
Hidden functionality allows remote Telnet enablement in Nexxt Nebula 300+ |
23.03.2026 |
|
| CVE-2026-31848 |
Reversible ecos_pw cookie allows administrative authentication in Nexxt Nebula 300+ |
23.03.2026 |
|
| CVE-2026-31849 |
Missing CSRF protection on state-changing endpoints in Nexxt Nebula 300+ |
23.03.2026 |
|
| CVE-2026-31850 |
Plaintext storage of credentials in configuration backup in Nexxt Nebula 300+ |
23.03.2026 |
|
| CVE-2026-31851 |
Lack of rate limiting allows brute-force attacks in Nexxt Nebula 300+ |
23.03.2026 |
|
| CVE-2026-4586 |
CodePhiliaX Chat2DB JDBC Driver Upload JdbcDriverController.java upload unrestricted upload |
23.03.2026 |
|
| CVE-2026-31846 |
|
23.03.2026 |
|
| CVE-2026-32968 |
Unauthenticated RCE in com_mb24sysapi |
23.03.2026 |
9.8 |
| CVE-2026-32969 |
Pre-Auth Blind SQLi in userinfo Endpoint |
23.03.2026 |
7.5 |
| CVE-2026-4584 |
Shenzhen HCC Technology MPOS M6 PLUS Cardholder Data cleartext transmission |
23.03.2026 |
|
| CVE-2026-4585 |
Tiandy Easy7 Integrated Management Platform Configuration ImportSystemConfiguration.jsp os command injection |
23.03.2026 |
|
| CVE-2026-4633 |
Keycloak: keycloak: user enumeration via differential error messages |
23.03.2026 |
|
| CVE-2026-28809 |
XXE in esaml SAML library allows local file read and potential SSRF |
23.03.2026 |
|
| CVE-2026-4583 |
Shenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replay |
23.03.2026 |
|
| CVE-2026-4581 |
code-projects Simple Laundry System Parameters checklogin.php sql injection |
23.03.2026 |
|
| CVE-2026-4582 |
Shenzhen HCC Technology MPOS M6 PLUS Bluetooth missing authentication |
23.03.2026 |
|
| CVE-2026-4580 |
code-projects Simple Laundry System Parameters checkupdatestatus.php sql injection |
23.03.2026 |
|
| CVE-2026-4628 |
Keycloak: org.keycloak.authorization: keycloak: unauthorized resource modification due to improper access control |
23.03.2026 |
|
| CVE-2026-3587 |
Hidden CLI Function Allows Root Access |
23.03.2026 |
10 |
| CVE-2026-4578 |
code-projects Exam Form Submission update_s3.php cross site scripting |
23.03.2026 |
|
| CVE-2026-4579 |
code-projects Simple Laundry System Parameters viewdetail.php sql injection |
23.03.2026 |
|
| CVE-2026-23554 |
Use after free of paging structures in EPT |
23.03.2026 |
|
| CVE-2026-23555 |
Xenstored DoS by unprivileged domain |
23.03.2026 |
|
| CVE-2025-13997 |
King Addons for Elementor <= 51.1.49 - Unauthenticated API Keys Disclosure |
23.03.2026 |
5.3 |
| CVE-2025-6229 |
Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Fancy Text Widget` And `Countdown Widget` |
23.03.2026 |
6.4 |
| CVE-2026-4577 |
code-projects Exam Form Submission update_s4.php cross site scripting |
23.03.2026 |
|
| CVE-2026-1969 |
ThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload |
23.03.2026 |
|
| CVE-2025-10679 |
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execution |
23.03.2026 |
7.3 |
| CVE-2025-10731 |
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure to Data Export |
23.03.2026 |
5.3 |
| CVE-2025-10734 |
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure |
23.03.2026 |
5.3 |
| CVE-2026-4573 |
SourceCodester Simple E-learning System HTTP GET Parameter delete_post.php sql injection |
23.03.2026 |
|
| CVE-2026-4574 |
SourceCodester Simple E-learning System User Profile Update sql injection |
23.03.2026 |
|
| CVE-2026-4575 |
code-projects Exam Form Submission update_s2.php cross site scripting |
23.03.2026 |
|
| CVE-2026-4576 |
code-projects Exam Form Submission update_s5.php cross site scripting |
23.03.2026 |
|
| CVE-2026-4598 |
|
23.03.2026 |
7.5 |
| CVE-2026-4599 |
|
23.03.2026 |
9.1 |
| CVE-2026-4600 |
|
23.03.2026 |
7.4 |
| CVE-2026-4601 |
|
23.03.2026 |
8.7 |
| CVE-2026-4602 |
|
23.03.2026 |
7.5 |
| CVE-2026-4603 |
|
23.03.2026 |
5.9 |
| CVE-2025-10736 |
ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation |
23.03.2026 |
6.5 |
| CVE-2026-4572 |
SourceCodester Sales and Inventory System HTTP POST Request view_product.php sql injection |
23.03.2026 |
|
| CVE-2026-4570 |
SourceCodester Sales and Inventory System HTTP POST Request view_customers.php sql injection |
23.03.2026 |
|
| CVE-2026-4571 |
SourceCodester Sales and Inventory System HTTP POST Request view_payments.php sql injection |
23.03.2026 |
|
| CVE-2026-4569 |
SourceCodester Sales and Inventory System HTTP POST Request view_category.php sql injection |
23.03.2026 |
|
| CVE-2026-4566 |
Belkin F9K1122 formWISP5G stack-based overflow |
23.03.2026 |
|
| CVE-2026-4567 |
Tenda A15 UploadCfg stack-based overflow |
23.03.2026 |
|
| CVE-2026-4568 |
SourceCodester Sales and Inventory System HTTP GET Request update_supplier.php sql injection |
23.03.2026 |
|
| CVE-2026-4606 |
GeoVision ERM Improper Privilege Assignment Leads to SYSTEM-Level Privilege |
23.03.2026 |
|
| CVE-2026-4565 |
Tenda AC21 SetNetControlList formSetQosBand buffer overflow |
23.03.2026 |
|
| CVE-2026-4563 |
MacCMS Member Order Detail User.php order_info authorization |
22.03.2026 |
|
| CVE-2026-4564 |
yangzongzhuan RuoYi Quartz Job job code injection |
23.03.2026 |
|
| CVE-2026-2580 |
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter |
23.03.2026 |
7.5 |
| CVE-2026-4562 |
MacCMS Timming API Endpoint Timming.php weak authentication |
23.03.2026 |
|