| CVE-2026-1870 |
Thim Kit for Elementor <= 1.3.7 - Missing Authorization to Unauthenticated Private Course Disclosure |
14.03.2026 |
5.3 |
| CVE-2025-54920 |
Apache Spark: Spark History Server Code Execution Vulnerability |
14.03.2026 |
|
| CVE-2026-1948 |
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license |
14.03.2026 |
4.3 |
| CVE-2026-0385 |
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability |
14.03.2026 |
5 |
| CVE-2026-32724 |
PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condition |
13.03.2026 |
5.3 |
| CVE-2026-32729 |
Runtipi has a TOTP two-factor authentication bypass via unrestricted brute-force on `/api/auth/verify-totp` |
13.03.2026 |
8.1 |
| CVE-2026-32732 |
XSS in @leanprover/unicode-input-component |
13.03.2026 |
|
| CVE-2026-3227 |
Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N |
13.03.2026 |
|
| CVE-2026-32708 |
Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot) |
13.03.2026 |
7.8 |
| CVE-2026-32709 |
PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete) |
13.03.2026 |
5.4 |
| CVE-2026-32713 |
PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptors |
13.03.2026 |
4.3 |
| CVE-2026-32715 |
AnythingLLM Manager Privilege Bypass Allows Access to Admin-Only System Preferences |
13.03.2026 |
3.8 |
| CVE-2026-32717 |
AnythingLLM access control bypass: suspended users can continue using Browser Extension API keys |
13.03.2026 |
2.7 |
| CVE-2026-32719 |
AnythingLLM has a Zip Slip Path Traversal and Code Execution via Community Hub Plugin Import |
13.03.2026 |
4.2 |
| CVE-2026-32720 |
Improper Access Control in github.com/ctfer-io/monitoring |
13.03.2026 |
|
| CVE-2026-26133 |
M365 Copilot Information Disclosure Vulnerability |
13.03.2026 |
7.1 |
| CVE-2026-32616 |
Pigeon has a Host Header Injection in email verification flow |
13.03.2026 |
8.2 |
| CVE-2026-32640 |
(SimpleEval) Objects (including modules) can leak dangerous modules through to direct access inside the sandbox. |
13.03.2026 |
|
| CVE-2026-32702 |
Cleanuparr has Username Enumeration via Timing Attack |
13.03.2026 |
|
| CVE-2026-32704 |
SiYuan renderSprig: missing admin check allows any user to read full workspace DB |
13.03.2026 |
6.5 |
| CVE-2026-32705 |
PX4 autopilot BST Device Name Length Can Overflow Driver Buffer |
13.03.2026 |
6.8 |
| CVE-2026-32706 |
PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet |
13.03.2026 |
7.1 |
| CVE-2026-32707 |
PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop |
13.03.2026 |
5.2 |
| CVE-2026-32628 |
AnythingLLM has SQL Injection in Built-in SQL Agent Plugin via Unsanitized table_name Parameter |
13.03.2026 |
|
| CVE-2026-32630 |
file-type affected by ZIP Decompression Bomb DoS via [Content_Types].xml entry |
13.03.2026 |
5.3 |
| CVE-2026-32635 |
Angular has XSS in i18n attribute bindings |
13.03.2026 |
|
| CVE-2026-32772 |
|
13.03.2026 |
3.4 |
| CVE-2025-15060 |
claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-2491 |
Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability |
13.03.2026 |
|
| CVE-2026-2493 |
IceWarp collaboration Directory Traversal Information Disclosure Vulnerability |
13.03.2026 |
|
| CVE-2026-2920 |
GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-2921 |
GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-2922 |
GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-2923 |
GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-32627 |
cpp-httplib has a Silent TLS Certificate Verification Bypass on HTTPS Redirect via Proxy |
13.03.2026 |
8.7 |
| CVE-2026-3081 |
GStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3082 |
GStreamer JPEG Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3083 |
GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3084 |
GStreamer H.266 Codec Parser Integer Underflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3085 |
GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3086 |
GStreamer H.266 Codec Parser Out-Of-Bounds Write Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3555 |
Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3556 |
Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3557 |
Philips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3558 |
Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability |
13.03.2026 |
|
| CVE-2026-3559 |
Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability |
13.03.2026 |
|
| CVE-2026-3560 |
Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3561 |
Philips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3562 |
Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability |
13.03.2026 |
|
| CVE-2026-3838 |
Unraid Update Request Path Traversal Remote Code Execution Vulnerability |
13.03.2026 |
|
| CVE-2026-3839 |
Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability |
13.03.2026 |
|
| CVE-2026-32621 |
Apollo Federation has prototype pollution via incomplete key sanitization |
13.03.2026 |
9.9 |
| CVE-2026-0977 |
IBM CICS Transaction Gateway for Multiplatforms Information Disclosure |
13.03.2026 |
5.1 |
| CVE-2026-32614 |
Go ShangMi SM9 Infinity-Point Ciphertext Forgery Vulnerability |
13.03.2026 |
7.5 |
| CVE-2026-32617 |
AnythingLLM Permissable CORS policy |
13.03.2026 |
7.1 |
| CVE-2026-32626 |
AnythingLLM has a Streaming Phase XSS to RCE via LLM Response Injection |
13.03.2026 |
9.7 |
| CVE-2025-13212 |
IBM Aspera Console Denial of Service |
13.03.2026 |
5.3 |
| CVE-2025-13459 |
IBM Aspera Console Denial of Service |
13.03.2026 |
2.7 |
| CVE-2025-13460 |
IBM Aspera Console Information Disclosure |
13.03.2026 |
5.3 |
| CVE-2026-32313 |
xmlseclibs is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption |
13.03.2026 |
8.2 |
| CVE-2026-32314 |
Yamux remote Panic via malformed Data frame with SYN set and len = 262145 |
13.03.2026 |
|
| CVE-2026-32594 |
Parse Server GraphQL WebSocket endpoint bypasses security middleware |
13.03.2026 |
|
| CVE-2026-32600 |
xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption |
13.03.2026 |
8.2 |
| CVE-2025-36368 |
IBM Sterling B2B Integrator and IBM Sterling File Gateway SQL Injection |
13.03.2026 |
6.5 |
| CVE-2026-31899 |
CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification |
13.03.2026 |
7.5 |
| CVE-2026-31944 |
LibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect link |
13.03.2026 |
7.6 |
| CVE-2026-31949 |
LibreChat Denial of Service (DoS) via Unhandled Exception in DELETE /api/convos |
13.03.2026 |
6.5 |
| CVE-2023-40693 |
IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting |
13.03.2026 |
5.4 |
| CVE-2026-31864 |
JumpServer has a Server-Side Template Injection Leading to RCE via YAML Rendering |
13.03.2026 |
6.8 |
| CVE-2026-31882 |
Dagu SSE Authentication Bypass in Basic Auth Mode |
13.03.2026 |
7.5 |
| CVE-2026-31886 |
Dagu has a Path Traversal via `dagRunId` in Inline DAG Execution |
13.03.2026 |
9.1 |
| CVE-2025-14483 |
IBM Sterling B2B Integrator and IBM Sterling File Gateway Information Disclosure |
13.03.2026 |
4.3 |
| CVE-2025-14504 |
IBM Sterling B2B Integrator and IBM Sterling File Gateway Cross-Site Scripting |
13.03.2026 |
5.4 |
| CVE-2026-30914 |
SFTPGo has a Path Traversal and Permission Bypass via Path Normalization Discrepancy |
13.03.2026 |
|
| CVE-2026-30915 |
SFTPGo improperly sanitizes placeholders in group home directories/key prefixes |
13.03.2026 |
|
| CVE-2026-30943 |
Gokapi has Privilege Escalation in File Replace |
13.03.2026 |
4.1 |
| CVE-2026-30955 |
Gokapi vulnerable to DoS in E2E Metadata Parser |
13.03.2026 |
6.5 |
| CVE-2026-30961 |
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload |
13.03.2026 |
4.3 |
| CVE-2026-31798 |
JumpServer Improper Certificate Validation in Custom SMS API Client |
13.03.2026 |
5 |
| CVE-2026-31814 |
Yamux remote Panic via malformed WindowUpdate credit |
13.03.2026 |
|
| CVE-2026-0835 |
|
13.03.2026 |
5.4 |
| CVE-2026-30853 |
calibre has a Path Traversal Leading to Arbitrary File Write |
13.03.2026 |
5 |
| CVE-2025-12453 |
Improper neutralization of input during web page generation vulnerability has been discovered in OpenText™ Vertica. |
13.03.2026 |
|
| CVE-2025-12454 |
Improper neutralization of input during web page generation vulnerability has been discovered in OpenText™ Vertica. |
13.03.2026 |
|
| CVE-2025-12455 |
Username Enumeration Observable Response Discrepancy vulnerability has been discovered in OpenText™ Vertica. |
13.03.2026 |
|
| CVE-2025-13702 |
IBM Sterling Partner Engagement Manager Cross-Site Scripting |
13.03.2026 |
6.1 |
| CVE-2025-13718 |
IBM Sterling Partner Engagement Manager Information Disclosure |
13.03.2026 |
3.7 |
| CVE-2025-13723 |
IBM Sterling Partner Engagement Manager Information Disclosure |
13.03.2026 |
5.3 |
| CVE-2025-13726 |
IBM Sterling Partner Engagement Manager Information Disclosure |
13.03.2026 |
5.3 |
| CVE-2025-71263 |
|
13.03.2026 |
7.4 |