| CVE-2026-29778 |
pyLoad: Arbitrary File Write via Path Traversal in edit_package() |
07.03.2026 |
7.1 |
| CVE-2026-29784 |
Ghost: Incomplete CSRF protections around OTC use |
07.03.2026 |
7.5 |
| CVE-2026-29786 |
node-tar: Hardlink Path Traversal via Drive-Relative Linkpath |
07.03.2026 |
|
| CVE-2026-29787 |
mcp-memory-service: System Information Disclosure via Health Endpoint |
07.03.2026 |
5.3 |
| CVE-2026-30834 |
PinchTab: SSRF with Full Response Exfiltration via Download Handler |
07.03.2026 |
7.5 |
| CVE-2026-3665 |
xlnt-community xlnt XLSX File xlsx_consumer.cpp read_office_document null pointer dereference |
07.03.2026 |
|
| CVE-2026-3667 |
Freedom Factory dGEN1 org.ethosmobile.ethoslauncher FakeAppService improper authorization |
07.03.2026 |
|
| CVE-2026-29190 |
Karapace: Path Traversal in Backup Reader |
07.03.2026 |
4.1 |
| CVE-2026-29771 |
Netmaker: Denial of Service via Server Shutdown Endpoint |
07.03.2026 |
|
| CVE-2026-29779 |
UptimeFlare: Montior config / Credentials in `workerConfig` exposed in client-side JavaScript bundle |
07.03.2026 |
7.5 |
| CVE-2026-29780 |
eml_parser: Path Traversal in Official Example Script Leading to Arbitrary File Write |
07.03.2026 |
5.5 |
| CVE-2026-29781 |
Sliver: Authenticated Nil-Pointer Dereference in Handlers |
07.03.2026 |
|
| CVE-2026-29067 |
ZITADEL: Account Takeover Due to Improper Instance Validation in V2 Login |
07.03.2026 |
8.1 |
| CVE-2026-29186 |
@backstage/plugin-techdocs-node: TechDocs Mkdocs Configuration Key Enables Arbitrary Code Execution |
07.03.2026 |
7.7 |
| CVE-2026-29191 |
ZITADEL: 1-Click Account Takeover via XSS in /saml-post Endpoint |
07.03.2026 |
9.3 |
| CVE-2026-29192 |
ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover |
07.03.2026 |
7.7 |
| CVE-2026-29193 |
ZITADEL: Bypassing Zitadel Login Behavior and Security Policy in Login V2 |
07.03.2026 |
8.2 |
| CVE-2026-29184 |
@backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redaction Bypass |
07.03.2026 |
2 |
| CVE-2026-29185 |
@backstage/integration: Potential reading of SCM URLs using built in token |
07.03.2026 |
2.7 |
| CVE-2026-3663 |
xlnt-community xlnt XLSX File compound_document.cpp xsgetn out-of-bounds |
07.03.2026 |
|
| CVE-2026-3664 |
xlnt-community xlnt Encrypted XLSX File compound_document.cpp read_directory out-of-bounds |
07.03.2026 |
|
| CVE-2026-3661 |
Wavlink WL-NU516U1 adm.cgi ota_new_upgrade command injection |
07.03.2026 |
|
| CVE-2026-3662 |
Wavlink WL-NU516U1 adm.cgi usb_p910 command injection |
07.03.2026 |
|
| CVE-2026-24281 |
Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManager |
07.03.2026 |
|
| CVE-2026-24308 |
Apache ZooKeeper: Sensitive information disclosure in client configuration handling |
07.03.2026 |
|
| CVE-2026-2219 |
|
07.03.2026 |
|
| CVE-2025-14675 |
Meta Box <= 5.11.1 - Authenticated (Contributor+) Arbitrary File Deletion |
07.03.2026 |
7.2 |
| CVE-2026-1071 |
Carta Online <= 2.13.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings |
07.03.2026 |
4.4 |
| CVE-2026-1073 |
Purchase Button For Affiliate Link <= 1.0.2 - Cross-Site Request Forgery to Settings Update |
07.03.2026 |
4.3 |
| CVE-2026-1074 |
WP App Bar <= 1.5 - Unauthenticated Stored Cross-Site Scripting via 'app-bar-features' Parameter |
07.03.2026 |
7.2 |
| CVE-2026-1085 |
True Ranker <= 2.2.9 - Cross-Site Request Forgery to Unauthorized True Ranker Disconnection |
07.03.2026 |
4.3 |
| CVE-2026-1086 |
Font Pairing Preview For Landing Pages <= 1.3 - Cross-Site Request Forgery to Settings Update |
07.03.2026 |
4.3 |
| CVE-2026-1087 |
The Guardian News Feed <= 1.2 - Cross-Site Request Forgery to Settings Update |
07.03.2026 |
4.3 |
| CVE-2026-1569 |
Wueen <= 0.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's Shortcode |
07.03.2026 |
6.4 |
| CVE-2026-1574 |
MyQtip – easy qTip2 <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
07.03.2026 |
6.4 |
| CVE-2026-1805 |
DA Media GigList <= 1.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'list_title' Shortcode Attribute |
07.03.2026 |
6.4 |
| CVE-2026-1820 |
Media Library Alt Text Editor <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'post_id' Shortcode Attribute |
07.03.2026 |
6.4 |
| CVE-2026-1823 |
Consensus Embed <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'src' Shortcode Attribute |
07.03.2026 |
6.4 |
| CVE-2026-1824 |
Infomaniak Connect for OpenID <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
07.03.2026 |
6.4 |
| CVE-2026-1825 |
Show YouTube video <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
07.03.2026 |
6.4 |
| CVE-2026-2420 |
LotekMedia Popup Form <= 1.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings |
07.03.2026 |
4.4 |
| CVE-2026-2433 |
RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.11 - Unauthenticated DOM-Based Reflected Cross-Site Scripting via postMessage |
07.03.2026 |
6.1 |
| CVE-2025-8899 |
Paid Videochat Turnkey Site – HTML5 PPV Live Webcams <= 7.3.20 - Authenticated (Author+) Privilege Escalation |
07.03.2026 |
8.8 |
| CVE-2026-27796 |
Homarr: Unauthenticated Information Disclosure (Integration Metadata Leak) |
07.03.2026 |
5.3 |
| CVE-2026-27797 |
Homarr: Unauthenticated SSRF in rssFeed.ts |
07.03.2026 |
5.3 |
| CVE-2026-30829 |
Checkmate: Unauthenticated Access to Unpublished Status Page |
07.03.2026 |
5.3 |
| CVE-2026-30830 |
Defuddle: XSS via unescaped string interpolation in _findContentBySchemaText image tag |
07.03.2026 |
|
| CVE-2026-30828 |
Wallos: SSRF via url parameter leading to File Traversal |
07.03.2026 |
|
| CVE-2026-30839 |
Wallos: SSRF via webhook test endpoint |
07.03.2026 |
|
| CVE-2026-30840 |
Wallos: Server-Side Request Forgery (SSRF) in Notification Testers |
07.03.2026 |
|
| CVE-2026-30841 |
Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php |
07.03.2026 |
|
| CVE-2026-30842 |
Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars |
07.03.2026 |
4.3 |
| CVE-2026-30823 |
Flowise: IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration |
07.03.2026 |
|
| CVE-2026-30824 |
Flowise: Missing Authentication on NVIDIA NIM Endpoints |
07.03.2026 |
|
| CVE-2026-30825 |
hoppscotch: IDOR - Any authenticated user can revoke any other user's Personal Access Token |
07.03.2026 |
0 |
| CVE-2026-30827 |
express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting (all IPv4 clients share one bucket on dual-stack servers) |
07.03.2026 |
7.5 |
| CVE-2026-30820 |
Flowise Authorization Bypass via Spoofed x-request-from Header |
07.03.2026 |
|
| CVE-2026-30821 |
Flowise: Arbitrary File Upload via MIME Spoofing |
07.03.2026 |
|
| CVE-2026-30822 |
Flowise: Mass Assignment in `/api/v1/leads` Endpoint |
07.03.2026 |
|
| CVE-2026-30247 |
WeKnora: SSRF via Redirection |
07.03.2026 |
5.9 |
| CVE-2025-14353 |
ZIP Code Based Content Protection <= 1.0.2 - Unauthenticated SQL Injection via 'zipcode' Parameter |
07.03.2026 |
7.5 |
| CVE-2026-1650 |
MDJM Event Management <= 1.7.8.1 - Missing Authorization to Unauthenticated Arbitrary Custom Event Field Deletion |
07.03.2026 |
5.3 |
| CVE-2026-1902 |
Hammas Calendar <= 1.5.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'apix' Shortcode Attribute |
07.03.2026 |
6.4 |
| CVE-2026-2020 |
JS Archive List <= 6.1.7 - Authenticated (Contributor+) PHP Object Injection via 'included' Shortcode Attribute |
07.03.2026 |
7.5 |
| CVE-2026-2429 |
Community Events <= 1.5.8 - Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Field |
07.03.2026 |
4.9 |
| CVE-2026-2431 |
CM Custom Reports <= 1.2.7 - Reflected Cross-Site Scripting via 'date_from' and 'date_to' Parameters |
07.03.2026 |
6.1 |
| CVE-2026-2488 |
ProfileGrid <= 5.9.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion |
07.03.2026 |
4.3 |
| CVE-2026-2494 |
ProfileGrid <= 5.9.8.2 - Cross-Site Request Forgery to Group Membership Request Approval/Denial |
07.03.2026 |
4.3 |
| CVE-2026-2721 |
MailArchiver <= 4.4.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Settings |
07.03.2026 |
4.8 |
| CVE-2026-2722 |
Stock Ticker <= 3.26.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Template |
07.03.2026 |
4.8 |
| CVE-2026-3352 |
Easy PHP Settings <= 1.0.4 - Authenticated (Administrator+) PHP Code Injection via 'wp_memory_limit' Setting |
07.03.2026 |
7.2 |
| CVE-2026-25070 |
XikeStor SKS8310-8X PingTestSet Command Injection |
07.03.2026 |
|
| CVE-2026-25071 |
XikeStor SKS8310-8X switch_config.src Missing Authentication |
07.03.2026 |
|
| CVE-2026-25072 |
XikeStor SKS8310-8X Predictable Session Identifiers |
07.03.2026 |
|
| CVE-2026-25073 |
XikeStor SKS8310-8X Stored XSS via System Name |
07.03.2026 |
|
| CVE-2026-1644 |
WP Frontend Profile <= 1.3.8 - Cross-Site Request Forgery to Unauthorized User Account Approval or Rejection |
06.03.2026 |
4.3 |
| CVE-2026-1981 |
Winston AI <= 0.0.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion |
06.03.2026 |
4.3 |
| CVE-2026-2371 |
Greenshift <= 12.8.3 - Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' |
06.03.2026 |
5.3 |
| CVE-2026-3233 |
|
06.03.2026 |
|
| CVE-2026-25679 |
Incorrect parsing of IPv6 host literals in net/url |
06.03.2026 |
|
| CVE-2026-27137 |
Incorrect enforcement of email constraints in crypto/x509 |
06.03.2026 |
|
| CVE-2026-27138 |
Panic in name constraint checking for malformed certificates in crypto/x509 |
06.03.2026 |
|
| CVE-2026-27139 |
FileInfo can escape from a Root in os |
06.03.2026 |
|
| CVE-2026-27142 |
URLs in meta content attribute actions are not escaped in html/template |
06.03.2026 |
|
| CVE-2026-30241 |
Mercurius: queryDepth limit bypassed for WebSocket subscriptions |
06.03.2026 |
|
| CVE-2026-30242 |
Plane: SSRF via Incomplete IP Validation in Webhook URL Serializer |
06.03.2026 |
8.5 |
| CVE-2026-30244 |
Plane: Unauthenticated Workspace Member Information Disclosure |
06.03.2026 |
7.5 |