| CVE-2019-25614 |
Free Float FTP 1.0 STOR Command Remote Buffer Overflow |
22.03.2026 |
9.3 |
| CVE-2019-25568 |
Memu Play 6.0.7 Privilege Escalation via Insecure File Permissions |
21.03.2026 |
9.3 |
| CVE-2026-24060 |
Automated Logic WebCTRL Premium Server Cleartext Transmission of Sensitive Information |
20.03.2026 |
9.1 |
| CVE-2026-29796 |
IGL-Technologies eParking.fi Missing Authentication for Critical Function |
20.03.2026 |
9.3 |
| CVE-2026-25192 |
CTEK Chargeportal Missing Authentication for Critical Function |
20.03.2026 |
9.3 |
| CVE-2026-33186 |
gRPC-Go has an authorization bypass via missing leading slash in :path |
20.03.2026 |
9.1 |
| CVE-2026-3584 |
Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process |
20.03.2026 |
9.8 |
| CVE-2026-22898 |
QVR Pro |
20.03.2026 |
9.3 |
| CVE-2026-22172 |
OpenClaw < 2026.3.12 - Scope Elevation in WebSocket Shared-Auth Connections |
20.03.2026 |
9.4 |
| CVE-2026-33134 |
WeGIA has Authenticated Time-Based Blind SQL Injection in `restaurar_produto.php` via `id_produto` parameter |
20.03.2026 |
9.3 |
| CVE-2026-33135 |
WeGIA has Reflected Cross-Site Scripting (XSS) in `novo_memorandoo.php` via `sccs` parameter |
20.03.2026 |
9.3 |
| CVE-2026-33136 |
WeGIA has Reflected Cross-Site Scripting (XSS) in `listar_memorandos_ativos.php` via `sccd` parameter |
20.03.2026 |
9.3 |
| CVE-2026-33075 |
FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml |
20.03.2026 |
9.4 |
| CVE-2026-33057 |
Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py |
20.03.2026 |
9.8 |
| CVE-2026-33054 |
Mesop: Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion |
20.03.2026 |
10 |
| CVE-2026-4478 |
Yi Technology YI Home Camera HTTP Firmware Update ipc signature verification |
20.03.2026 |
9.2 |
| CVE-2026-33017 |
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint |
21.03.2026 |
9.3 |
| CVE-2026-33024 |
AVideo-Encoder has Unauthenticated Blind Server-Side Request Forgery via Public Thumbnail Generator |
20.03.2026 |
9.3 |
| CVE-2026-32938 |
SiYuan has an Arbitrary File Read in its Desktop Publish Service |
20.03.2026 |
9.9 |
| CVE-2026-32940 |
SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183) |
20.03.2026 |
9.3 |
| CVE-2026-4038 |
Aimogen Pro <= 2.7.5 - Unauthenticated Privilege Escalation via Arbitrary Function Call |
20.03.2026 |
9.8 |
| CVE-2026-21992 |
|
20.03.2026 |
9.8 |
| CVE-2026-32890 |
Anchorr: Stored XSS in User Mapping dropdown allows unprivileged Discord users to exfiltrate all secrets via /api/config |
20.03.2026 |
9.7 |
| CVE-2026-32891 |
Anchorr Privilege Escalation: Jellyseerr User → Anchorr Admin via Stored XSS |
20.03.2026 |
9.1 |
| CVE-2026-32817 |
Admidio is Missing Authorization and CSRF Protection on Document and Folder Deletion |
20.03.2026 |
9.1 |
| CVE-2026-32767 |
SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API |
20.03.2026 |
9.8 |
| CVE-2026-32985 |
Xerte Online Toolkits <= 3.14 Unauthenticated Template Import Arbitrary File Upload Leading to Remote Code Execution |
20.03.2026 |
9.3 |
| CVE-2026-32760 |
File Browser Self Registration Grants Any User Admin Access When Default Permissions Include Admin |
19.03.2026 |
10 |
| CVE-2026-22732 |
Under Some Conditions Spring Security HTTP Headers Are not Written |
21.03.2026 |
9.1 |
| CVE-2026-29103 |
SuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner Bypass |
20.03.2026 |
9.1 |
| CVE-2026-32038 |
OpenClaw - Sandbox Network Isolation Bypass via docker.network=container Parameter |
20.03.2026 |
9.3 |
| CVE-2026-30872 |
OpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookup |
20.03.2026 |
9.5 |
| CVE-2026-30871 |
OpenWrt Project has Stack-based Buffer Overflow in DNS PTR Query |
20.03.2026 |
9.5 |
| CVE-2026-32754 |
FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!}) |
20.03.2026 |
9.3 |
| CVE-2026-32194 |
Microsoft Bing Images Remote Code Execution Vulnerability |
21.03.2026 |
9.8 |
| CVE-2026-32169 |
Azure Cloud Shell Elevation of Privilege Vulnerability |
21.03.2026 |
10 |
| CVE-2026-32191 |
Microsoft Bing Images Remote Code Execution Vulnerability |
21.03.2026 |
9.8 |
| CVE-2026-30924 |
qui CORS Misconfiguration: Arbitrary Origins Trusted |
20.03.2026 |
9 |
| CVE-2026-4428 |
CRL Distribution Point Scope Check Logic Error in AWS-LC |
19.03.2026 |
9.1 |
| CVE-2026-30836 |
Step CA: Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18) |
19.03.2026 |
10 |
| CVE-2026-32238 |
OpenEMR has Remote Code Execution in backup functionality |
20.03.2026 |
9.1 |
| CVE-2026-32865 |
OPEXUS eComplaint and eCase insecure password reset |
19.03.2026 |
9.2 |
| CVE-2026-22557 |
|
19.03.2026 |
10 |
| CVE-2026-27065 |
WordPress BuilderPress plugin <= 2.0.1 - Local File Inclusion vulnerability |
19.03.2026 |
9.8 |
| CVE-2026-27067 |
WordPress Mobile App Editor plugin <= 1.3.1 - Arbitrary File Upload vulnerability |
19.03.2026 |
9.1 |
| CVE-2025-60233 |
WordPress Zuut theme <= 1.4.2 - PHP Object Injection vulnerability |
19.03.2026 |
9.8 |
| CVE-2025-60237 |
WordPress Finag theme <= 1.5.0 - PHP Object Injection vulnerability |
19.03.2026 |
9.8 |
| CVE-2026-27413 |
WordPress Profile Builder Pro plugin <= 3.13.9 - SQL Injection vulnerability |
19.03.2026 |
9.3 |
| CVE-2026-27540 |
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability |
19.03.2026 |
9 |
| CVE-2026-27542 |
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerability |
19.03.2026 |
9.8 |
| CVE-2026-32731 |
ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction |
19.03.2026 |
10 |
| CVE-2026-32698 |
OpenProject has a SQL Injection via Custom Field Name that can be chained to Remote Code Execution |
19.03.2026 |
9.1 |
| CVE-2026-32703 |
OpenProject's repository files are served with the MIME type allowing them to be used to bypass Content Security Policy |
19.03.2026 |
9.1 |
| CVE-2026-25873 |
OmniGen2-RL Reward Server Unsafe Deserialization RCE |
19.03.2026 |
9.3 |
| CVE-2026-32633 |
Glances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist` |
18.03.2026 |
9.1 |
| CVE-2026-2991 |
KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login Token |
18.03.2026 |
9.8 |
| CVE-2026-25449 |
WordPress Traveler theme < 3.2.8.1 - PHP Object Injection vulnerability |
18.03.2026 |
9.8 |
| CVE-2026-30884 |
mdjnelson/moodle-mod_customcert Vulnerable to Authorization Bypass Through User-Controlled Key |
18.03.2026 |
9.6 |
| CVE-2026-31938 |
jsPDF has HTML Injection in New Window paths |
18.03.2026 |
9.6 |
| CVE-2026-21994 |
|
18.03.2026 |
9.8 |
| CVE-2026-32841 |
Edimax GS-5008PL <= 1.00.54 Global Authentication State Across All Clients |
18.03.2026 |
9.2 |
| CVE-2026-25769 |
Wazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization |
18.03.2026 |
9.1 |
| CVE-2026-25770 |
Wazuh has Privilege Escalation to Root via Cluster Protocol File Write |
18.03.2026 |
9.1 |
| CVE-2026-25534 |
Spinnaker clouddriver and orca URL validation bypass via underscores in hostnames |
17.03.2026 |
9.1 |
| CVE-2026-32292 |
GL-iNet Comet (GL-RM1) KVM insufficient login rate-limiting |
17.03.2026 |
9.3 |
| CVE-2026-32295 |
JetKVM insufficient login rate limiting |
17.03.2026 |
9.3 |
| CVE-2026-32297 |
Angeet ES3 KVM unauthenticated arbitrary file write |
17.03.2026 |
9.3 |
| CVE-2026-3564 |
ScreenConnect Instance Level Cryptographic Material Exposure |
18.03.2026 |
9 |
| CVE-2026-4312 |
DrangSoft|GCB/FCB Audit Software - Missing Authentication |
17.03.2026 |
9.3 |
| CVE-2026-28430 |
Chamilo LMS Vulnerable to Unauthenticated SQL Injection in chamiko-lms model.ajax.php |
17.03.2026 |
9.3 |
| CVE-2026-27962 |
Authlib JWS JWK Header Injection: Signature Verification Bypass |
18.03.2026 |
9.1 |
| CVE-2026-4254 |
Tenda AC8 HTTP Endpoint SysToolChangePwd doSystemCmd stack-based overflow |
16.03.2026 |
9.3 |
| CVE-2026-23489 |
Fields GLPI plugin vulnerable to RCE in dropdown generation |
16.03.2026 |
9.1 |
| CVE-2026-4252 |
Tenda AC8 IPv6 check_is_ipv6 ip address for authentication |
16.03.2026 |
9.3 |
| CVE-2025-62319 |
Boolean-Based SQL Injection in Multiple Unica Components |
17.03.2026 |
9.8 |
| CVE-2017-20223 |
Telesquare SKT LTE Router SDT-CS3B1 Insecure Direct Object Reference |
16.03.2026 |
9.3 |
| CVE-2017-20224 |
Telesquare SKT LTE Router SDT-CS3B1 WebDAV Arbitrary File Upload |
16.03.2026 |
9.3 |