| CVE-2026-3564 |
ScreenConnect Instance Level Cryptographic Material Exposure |
17.03.2026 |
9 |
| CVE-2026-4312 |
DrangSoft|GCB/FCB Audit Software - Missing Authentication |
17.03.2026 |
9.3 |
| CVE-2026-28430 |
Chamilo LMS Vulnerable to Unauthenticated SQL Injection in chamiko-lms model.ajax.php |
17.03.2026 |
9.3 |
| CVE-2026-27962 |
Authlib JWS JWK Header Injection: Signature Verification Bypass |
17.03.2026 |
9.1 |
| CVE-2026-4254 |
Tenda AC8 HTTP Endpoint SysToolChangePwd doSystemCmd stack-based overflow |
16.03.2026 |
9.3 |
| CVE-2026-23489 |
Fields GLPI plugin vulnerable to RCE in dropdown generation |
16.03.2026 |
9.1 |
| CVE-2026-4252 |
Tenda AC8 IPv6 check_is_ipv6 ip address for authentication |
16.03.2026 |
9.3 |
| CVE-2025-62319 |
Boolean-Based SQL Injection in Multiple Unica Components |
17.03.2026 |
9.8 |
| CVE-2017-20223 |
Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference |
16.03.2026 |
9.3 |
| CVE-2017-20224 |
Telesquare SKT LTE Router SDT-CS3B1 WebDAV Arbitrary File Upload |
16.03.2026 |
9.3 |
| CVE-2026-4184 |
D-Link DIR-816 goahead form2Wl5BasicSetup.cgi stack-based overflow |
16.03.2026 |
9.3 |
| CVE-2026-4183 |
D-Link DIR-816 goahead form2WlanBasicSetup.cgi stack-based overflow |
16.03.2026 |
9.3 |
| CVE-2026-4181 |
D-Link DIR-816 goahead form2RepeaterStep2.cgi stack-based overflow |
16.03.2026 |
9.3 |
| CVE-2026-4182 |
D-Link DIR-816 goahead form2Wl5RepeaterStep2.cgi stack-based overflow |
16.03.2026 |
9.3 |
| CVE-2016-20024 |
ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions Privilege Escalation |
16.03.2026 |
9.3 |
| CVE-2016-20026 |
ZKTeco ZKBioSecurity 3.0 Hardcoded Credentials Remote Code Execution |
16.03.2026 |
9.3 |
| CVE-2016-20030 |
ZKTeco ZKBioSecurity 3.0 User Enumeration via authLoginAction |
16.03.2026 |
9.3 |
| CVE-2026-4170 |
Topsec TopACM HTTP Request nmc_sync.php os command injection |
16.03.2026 |
9.3 |
| CVE-2026-4164 |
Wavlink WL-WN578W2 POST Request wireless.cgi GuestWifi command injection |
17.03.2026 |
9.3 |
| CVE-2026-4163 |
Wavlink WL-WN579A3 POST Request wireless.cgi GuestWifi command injection |
17.03.2026 |
9.3 |
| CVE-2025-15060 |
claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability |
16.03.2026 |
9.8 |
| CVE-2026-32621 |
Apollo Federation has prototype pollution via incomplete key sanitization |
16.03.2026 |
9.9 |
| CVE-2026-32626 |
AnythingLLM has a Streaming Phase XSS to RCE via LLM Response Injection |
16.03.2026 |
9.7 |
| CVE-2026-31886 |
Dagu has a Path Traversal via `dagRunId` in Inline DAG Execution |
13.03.2026 |
9.1 |
| CVE-2026-31806 |
FreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap Dimensions |
15.03.2026 |
9.3 |
| CVE-2026-32746 |
|
15.03.2026 |
9.8 |
| CVE-2026-26954 |
SandboxJS has a Sandbox Escape |
16.03.2026 |
10 |
| CVE-2026-3891 |
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload |
13.03.2026 |
9.8 |
| CVE-2026-22193 |
wpDiscuz before 7.6.47 - SQL Injection in getAllSubscriptions() |
13.03.2026 |
9.2 |
| CVE-2026-32301 |
Centrifugo: SSRF via unverified JWT claims interpolated into dynamic JWKS endpoint URL |
13.03.2026 |
9.3 |
| CVE-2026-32304 |
Locutus: RCE via unsanitized input in create_function() |
13.03.2026 |
9.8 |
| CVE-2026-32306 |
OneUptime ClickHouse SQL Injection via Aggregate Query Parameters |
14.03.2026 |
10 |
| CVE-2026-3611 |
Honeywell IQ4x BMS Controller Missing authentication for critical function |
13.03.2026 |
10 |
| CVE-2026-32248 |
Parse Server: Account takeover via operator injection in authentication data identifier |
13.03.2026 |
9.3 |
| CVE-2026-32251 |
Tolgee has an XXE Injection in Translation Import |
13.03.2026 |
9.3 |
| CVE-2026-32242 |
Parse Server OAuth2 adapter shares mutable state across providers via singleton instance |
12.03.2026 |
9.1 |
| CVE-2026-32140 |
Dataease: Redshift JDBC RCE Bypass |
13.03.2026 |
9.3 |
| CVE-2026-32137 |
DataEase SQL Injection Vulnerability |
13.03.2026 |
9.3 |
| CVE-2026-28252 |
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge |
13.03.2026 |
9.2 |
| CVE-2026-28792 |
Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS |
13.03.2026 |
9.7 |
| CVE-2026-21708 |
|
13.03.2026 |
10 |
| CVE-2026-21666 |
|
13.03.2026 |
10 |
| CVE-2026-21667 |
|
13.03.2026 |
10 |
| CVE-2026-21669 |
|
13.03.2026 |
10 |
| CVE-2026-21671 |
|
13.03.2026 |
9.1 |
| CVE-2026-28384 |
Authenticated RCE via unsanitized compression_algorithm |
13.03.2026 |
9.4 |
| CVE-2026-32136 |
AdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication Bypass |
12.03.2026 |
9.8 |
| CVE-2026-27591 |
Winter: Privilege escalation by authenticated backend users |
12.03.2026 |
10 |
| CVE-2026-32096 |
Plunk has SSRF via unvalidated AWS SNS SubscriptionConfirmation in POST /webhooks/sns |
12.03.2026 |
9.3 |
| CVE-2026-27478 |
Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation |
12.03.2026 |
9.1 |
| CVE-2026-31976 |
xygeni-action v5 tag poisoned with C2 backdoor |
12.03.2026 |
9.3 |
| CVE-2026-31957 |
Himmelblau unset domain configuration can allow any-tenant authentication at first login for remote deployments |
12.03.2026 |
10 |
| CVE-2026-31896 |
WeGIA has a Time-Based Blind SQL Injection in remover_produto_ocultar.php |
12.03.2026 |
9.8 |
| CVE-2018-25159 |
Epross AVCON6 OGNL Remote Code Execution via login.action |
11.03.2026 |
9.3 |
| CVE-2019-25468 |
NetGain EM Plus 10.1.68 Remote Code Execution via script_test.jsp |
11.03.2026 |
9.3 |
| CVE-2019-25471 |
FileThingie 2.5.7 Arbitrary File Upload via ft2.php |
11.03.2026 |
9.3 |
| CVE-2019-25487 |
SAPIDO RB-1732 V2.0.43 Remote Command Execution via formSysCmd |
11.03.2026 |
9.3 |
| CVE-2026-31874 |
Taskosaur Improper Role Assignment via Parameter Manipulation in User Registration |
12.03.2026 |
9.8 |
| CVE-2026-31877 |
Frappe SQL Injection due to improper field sanitization |
12.03.2026 |
9.3 |
| CVE-2026-31871 |
Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQL |
12.03.2026 |
9.3 |
| CVE-2026-31856 |
Parse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQL |
12.03.2026 |
9.3 |
| CVE-2026-31862 |
Cloud CLI has Command Injection via Multiple Parameters |
12.03.2026 |
9.1 |
| CVE-2026-31840 |
Parse Server has a SQL injection via dot-notation field name in PostgreSQL |
11.03.2026 |
9.3 |
| CVE-2026-31852 |
Jellyfin Possible Organization/Secret Compromise from dangerous CI implementation |
11.03.2026 |
10 |
| CVE-2026-27897 |
Vociferous Unauthenticated Remote Path Traversal (RCE via CSRF) |
11.03.2026 |
10 |
| CVE-2026-28229 |
Argo Workflows has unauthorized access to Argo Workflows Template |
11.03.2026 |
9.8 |
| CVE-2026-30903 |
|
12.03.2026 |
9.6 |
| CVE-2026-3826 |
WellChoose|IFTOP - Local File Inclusion |
11.03.2026 |
9.3 |
| CVE-2023-27573 |
|
11.03.2026 |
9 |
| CVE-2026-24448 |
|
11.03.2026 |
9.3 |
| CVE-2026-27842 |
|
11.03.2026 |
9.3 |
| CVE-2026-23813 |
Authentication Bypass in Web Interface allows Unauthenticated Admin Password Reset |
12.03.2026 |
9.8 |
| CVE-2026-29515 |
MiCode FileExplorer SwiFTP Server Authentication Bypass |
11.03.2026 |
9.3 |
| CVE-2026-28806 |
Improper authorization in device bulk actions and device update API allows cross-organization device control |
12.03.2026 |
9.4 |
| CVE-2026-0124 |
|
11.03.2026 |
10 |
| CVE-2026-30965 |
Parse Server session token exfiltration via `redirectClassNameForKey` query parameter |
11.03.2026 |
9.9 |
| CVE-2026-30966 |
Parse Server role escalation and CLP bypass via direct `_Join` table write |
11.03.2026 |
10 |
| CVE-2026-29792 |
Feathersjs has an OAuth Callback Account Takeover |
11.03.2026 |
9.3 |
| CVE-2026-29793 |
NoSQL Injection via WebSocket id Parameter in MongoDB Adapter |
11.03.2026 |
9.3 |
| CVE-2025-48611 |
|
16.03.2026 |
10 |
| CVE-2026-28495 |
GetSimple CMS has CSRF to Remote Code Execution via Arbitrary PHP Write in gsconfig.php |
10.03.2026 |
9.7 |
| CVE-2026-27825 |
MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment |
10.03.2026 |
9.1 |
| CVE-2026-28292 |
simple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key enables RCE |
11.03.2026 |
9.8 |