| CVE-2026-26017 |
CoreDNS ACL Bypass |
06.03.2026 |
7.7 |
| CVE-2026-26018 |
CoreDNS Loop Detection Denial of Service Vulnerability |
06.03.2026 |
7.5 |
| CVE-2026-27123 |
|
06.03.2026 |
|
| CVE-2026-20748 |
Everon api.everon.io Insufficient Session Expiration |
06.03.2026 |
7.3 |
| CVE-2026-20882 |
Mobiliti e-mobi.hu Improper Restriction of Excessive Authentication Attempts |
06.03.2026 |
7.5 |
| CVE-2026-24696 |
Everon api.everon.io Improper Restriction of Excessive Authentication Attempts |
06.03.2026 |
7.5 |
| CVE-2026-26288 |
Everon api.everon.io Missing Authentication for Critical Function |
06.03.2026 |
9.4 |
| CVE-2026-27027 |
Everon api.everon.io Insufficiently Protected Credentials |
06.03.2026 |
6.5 |
| CVE-2026-27764 |
Mobiliti e-mobi.hu Insufficient Session Expiration |
06.03.2026 |
7.3 |
| CVE-2026-27777 |
Mobiliti e-mobi.hu Insufficiently Protected Credentials |
06.03.2026 |
6.5 |
| CVE-2026-26051 |
Mobiliti e-mobi.hu Missing Authentication for Critical Function |
06.03.2026 |
9.4 |
| CVE-2026-2752 |
|
06.03.2026 |
5.3 |
| CVE-2026-2753 |
|
06.03.2026 |
7.5 |
| CVE-2026-2754 |
|
06.03.2026 |
7.5 |
| CVE-2026-1799 |
|
06.03.2026 |
|
| CVE-2022-4947 |
|
06.03.2026 |
|
| CVE-2018-25161 |
Warranty Tracking System 11.06.3 SQL Injection via SearchCustomer.php |
06.03.2026 |
|
| CVE-2018-25162 |
2-Plan Team 1.0.4 Arbitrary File Upload via managefile.php |
06.03.2026 |
|
| CVE-2018-25163 |
BitZoom 1.0 SQL Injection via rollno Parameter |
06.03.2026 |
|
| CVE-2018-25164 |
EverSync 0.5 Arbitrary File Download via files Directory |
06.03.2026 |
|
| CVE-2018-25165 |
Galaxy Forces MMORPG 0.5.8 SQL Injection via ads.php |
06.03.2026 |
|
| CVE-2018-25166 |
Meneame English Pligg 5.8 SQL Injection via search Parameter |
06.03.2026 |
|
| CVE-2018-25167 |
Net-Billetterie 2.9 SQL Injection via login.inc.php |
06.03.2026 |
|
| CVE-2018-25168 |
Precurio Intranet Portal 2.0 Cross-Site Request Forgery Add Admin |
06.03.2026 |
|
| CVE-2018-25169 |
AMPPS 2.7 Denial of Service via Malformed Socket Connection |
06.03.2026 |
|
| CVE-2018-25170 |
DoceboLMS 1.2 SQL Injection via lesson.php |
06.03.2026 |
|
| CVE-2018-25171 |
EdTv 2 SQL Injection via id Parameter |
06.03.2026 |
|
| CVE-2018-25172 |
Pedidos 1.0 SQL Injection via load_proveedores.php |
06.03.2026 |
|
| CVE-2018-25173 |
Rmedia SMS 1.0 SQL Injection via editgrp.php |
06.03.2026 |
|
| CVE-2018-25174 |
ABC ERP 0.6.4 Cross-Site Request Forgery via _configurar_perfil.php |
06.03.2026 |
|
| CVE-2018-25175 |
Alienor Web Libre 2.0 SQL Injection via index.php |
06.03.2026 |
|
| CVE-2018-25176 |
Alive Parish 2.0.4 SQL Injection and Arbitrary File Upload |
06.03.2026 |
|
| CVE-2018-25177 |
Data Center Audit 2.6.2 Cross-Site Request Forgery via dca_resetpw.php |
06.03.2026 |
|
| CVE-2018-25178 |
Easyndexer 1.0 Arbitrary File Download via showtif.php |
06.03.2026 |
|
| CVE-2018-25179 |
Gumbo CMS 0.99 SQL Injection via settings endpoint |
06.03.2026 |
|
| CVE-2018-25180 |
Maitra 1.7.2 SQL Injection and Database File Download |
06.03.2026 |
|
| CVE-2018-25181 |
Musicco 2.0.0 Arbitrary Directory Download via Path Traversal |
06.03.2026 |
|
| CVE-2018-25182 |
Silurus Classifieds Script 2.0 SQL Injection via wcategory.php |
06.03.2026 |
|
| CVE-2018-25184 |
Surreal ToDo 0.6.1.2 Local File Inclusion via index.php |
06.03.2026 |
|
| CVE-2018-25186 |
Tina4 Stack 1.0.3 Cross-Site Request Forgery via profile |
06.03.2026 |
|
| CVE-2018-25187 |
Tina4 Stack 1.0.3 SQL Injection and Database File Download |
06.03.2026 |
|
| CVE-2018-25188 |
Webiness Inventory 2.3 SQL Injection via WsModelGrid.php |
06.03.2026 |
|
| CVE-2018-25189 |
Data Center Audit 2.6.2 SQL Injection via username Parameter |
06.03.2026 |
|
| CVE-2018-25190 |
Easyndexer 1.0 Cross-Site Request Forgery via createuser.php |
06.03.2026 |
|
| CVE-2018-25191 |
Facturation System 1.0 SQL Injection via editar_producto.php |
06.03.2026 |
|
| CVE-2018-25192 |
GPS Tracking System 2.12 SQL Injection via username Parameter |
06.03.2026 |
|
| CVE-2018-25193 |
Mongoose Web Server 6.9 Denial of Service via Socket Connection |
06.03.2026 |
|
| CVE-2018-25194 |
Nominas 0.27 SQL Injection via username Parameter |
06.03.2026 |
|
| CVE-2018-25196 |
ServerZilla 1.0 SQL Injection via email Parameter |
06.03.2026 |
|
| CVE-2018-25197 |
PlayJoom 0.10.1 SQL Injection via catid Parameter |
06.03.2026 |
|
| CVE-2018-25198 |
eToolz 3.4.8.0 Denial of Service via Buffer Overflow |
06.03.2026 |
|
| CVE-2018-25199 |
OOP CMS BLOG 1.0 SQL Injection via search parameter |
06.03.2026 |
|
| CVE-2018-25200 |
OOP CMS BLOG 1.0 Cross-Site Request Forgery via addUser.php |
06.03.2026 |
|
| CVE-2026-28080 |
WordPress Rank Math SEO PRO plugin <= 3.0.95 - Broken Access Control vulnerability |
06.03.2026 |
4.3 |
| CVE-2026-28106 |
WordPress B2BKing Premium plugin <= 5.3.80 - Open Redirection vulnerability |
06.03.2026 |
4.7 |
| CVE-2024-35644 |
WordPress Preferred Languages plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability |
06.03.2026 |
5.9 |
| CVE-2026-1468 |
Cross-Site Request Forgery in QuickCMS |
06.03.2026 |
|
| CVE-2026-3589 |
WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF |
06.03.2026 |
|
| CVE-2026-23925 |
Unauthorized host creation via configuration.import API by low-privilege user with write permissions |
06.03.2026 |
|
| CVE-2026-2330 |
CVE-2026-2330 |
06.03.2026 |
9.4 |
| CVE-2026-2331 |
CVE-2026-2331 |
06.03.2026 |
9.8 |
| CVE-2026-29059 |
Windmill: SUPERADMIN_SECRET (rarely used) can be accessed publicly |
06.03.2026 |
|
| CVE-2026-29062 |
jackson-core: Nesting Depth Constraint Bypass in `UTF8DataInputJsonParser` potentially allowing Resource Exhaustion |
06.03.2026 |
|
| CVE-2026-29073 |
SiYuan: Direct SQL Query API accessible to Reader-level users enables unauthorized database access |
06.03.2026 |
|
| CVE-2026-29074 |
SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs) |
06.03.2026 |
7.5 |
| CVE-2026-29183 |
SiYuan: Unauthenticated reflected SVG XSS in `/api/icon/getDynamicIcon` (`type=8`) enables arbitrary JavaScript execution |
06.03.2026 |
9.3 |
| CVE-2026-2830 |
WP All Import <= 4.0.0 - Reflected Cross-Site Scripting via 'filepath' |
06.03.2026 |
6.1 |
| CVE-2026-29038 |
changedetection.io: Reflected XSS in RSS Tag Error Response |
06.03.2026 |
6.1 |
| CVE-2026-29039 |
changedetection.io: XPath - Arbitrary File Read via unparsed-text() |
06.03.2026 |
|
| CVE-2026-29042 |
Nuclio Shell Runtime Command Injection Leading to Privilege Escalation |
06.03.2026 |
|
| CVE-2026-29048 |
HumHub: XSS in Button component |
06.03.2026 |
|
| CVE-2026-29049 |
melange: unbounded HTTP download in `melange update-cache` can exhaust disk in CI |
06.03.2026 |
4.3 |
| CVE-2026-29058 |
AVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.php |
06.03.2026 |
9.8 |
| CVE-2026-29065 |
changedetection.io: Zip Slip vulnerability in the backup restore functionality |
06.03.2026 |
|
| CVE-2026-28438 |
CocoIndex Doris target connector didn't verify table name when constructing ALTER TABLE statements |
06.03.2026 |
|
| CVE-2026-28799 |
PJSIP: Heap use-after-free in PJSIP presence subscription termination handler |
06.03.2026 |
|
| CVE-2026-28800 |
Natro Macro: Malicious actions allowed through Discord RC Commands by any user |
06.03.2026 |
6.4 |
| CVE-2026-28801 |
Natro Macro: Code Injection through Pattern/Path files |
06.03.2026 |
6.6 |
| CVE-2026-28802 |
Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification |
06.03.2026 |
|
| CVE-2026-28804 |
pypdf: Inefficient decoding of ASCIIHexDecode streams |
06.03.2026 |
|
| CVE-2026-29068 |
PJSIP: Stack buffer overflow in Opus codec parser |
06.03.2026 |
|
| CVE-2026-28795 |
OpenChatBI: Critical Path Traversal Vulnerability in save_report Tool of OpenChatBI |
06.03.2026 |
|
| CVE-2026-1128 |
WP eCommerce <= 3.15.1 - Coupon Deletion via CSRF |
06.03.2026 |
|
| CVE-2026-2446 |
Powerpack for LearnDash < 1.3.0 - Unauthenticated Arbitrary Option Update |
06.03.2026 |
|
| CVE-2026-28428 |
Talishar: Authentication Bypass via Empty authKey Parameter Allows Unauthenticated Game Actions |
06.03.2026 |
5.3 |
| CVE-2026-28429 |
Talishar: Critical Path Traversal in gameName Parameter |
06.03.2026 |
7.5 |
| CVE-2026-28682 |
Gokapi: Data Leak in Upload Status Stream |
06.03.2026 |
6.4 |
| CVE-2026-28683 |
Gokapi: Stored XSS in SVG Hotlinks |
06.03.2026 |
8.7 |
| CVE-2026-28685 |
Kimai: API invoice endpoint missing customer-level access control (IDOR) |
06.03.2026 |
6.5 |
| CVE-2026-28787 |
OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay |
06.03.2026 |
8.2 |
| CVE-2026-28794 |
oRPC: Prototype Pollution in `@orpc/client` via `StandardRPCJsonSerializer` Deserialization |
06.03.2026 |
|
| CVE-2026-29060 |
Gokapi: Privilege escalation with auth token |
06.03.2026 |
5 |
| CVE-2026-29061 |
Gokapi: Privilege escalation via incomplete API-key permission revocation on user rank demotion |
06.03.2026 |
5.4 |
| CVE-2026-29084 |
Gokapi: CSRF in Login Endpoint |
06.03.2026 |
4.6 |
| CVE-2026-25877 |
Chartbrew: Insecure Direct Object Reference (IDOR) in Chart Operations |
06.03.2026 |
6.5 |
| CVE-2026-25887 |
Chartbrew: Remote Code Execution (RCE) via MongoDB Dataset Query |
06.03.2026 |
7.2 |
| CVE-2026-25888 |
Chartbrew: Remote Code Execution (RCE) via Vulnerable API |
06.03.2026 |
8.8 |
| CVE-2026-27005 |
Chartbrew: SQL injection in date-type variable handling (applyMysqlOrPostgresVariables) |
06.03.2026 |
|
| CVE-2026-27603 |
Chartbrew: Unauthenticated Chart Filter Endpoint: POST /project/:project_id/chart/:chart_id/filter missing verifyToken + checkPermissions |
06.03.2026 |
|
| CVE-2026-27605 |
Chartbrew: Stored Cross-Site Scripting (XSS) via File Upload API |
06.03.2026 |
6.3 |
| CVE-2026-28507 |
Idno: Remote Code Execution via Chained Import File Write and Template Path Traversal |
06.03.2026 |
|
| CVE-2026-28508 |
Idno: Unauthenticated SSRF via URL Unfurl Endpoint |
06.03.2026 |
|
| CVE-2026-28509 |
LangBot has a Cross Site Scripting(XSS) Vulnerability |
06.03.2026 |
6.3 |
| CVE-2026-28675 |
OpenSift: Sensitive implementation details exposed via raw exception messages and token-returning endpoints |
06.03.2026 |
5.3 |
| CVE-2026-28676 |
OpenSift: Insufficient path containment checks in storage helpers could allow path traversal-style file operations |
06.03.2026 |
8.8 |
| CVE-2026-28677 |
OpenSift: Insufficient URL destination restrictions in ingest flow could enable SSRF-style internal access |
06.03.2026 |
8.2 |
| CVE-2026-28679 |
HomeGallery: Path Traversal (Arbitrary File Read) |
06.03.2026 |
8.6 |
| CVE-2026-28680 |
Ghostfolio: Full-Read SSRF in Manual Asset Import |
06.03.2026 |
9.3 |
| CVE-2026-28681 |
IRRd: web UI host header injection allows password reset poisoning via attacker-controlled email links |
06.03.2026 |
8.1 |
| CVE-2026-28785 |
Ghostfolio: Time-Based Blind SQL Injection in Manual Asset Import |
06.03.2026 |
|
| CVE-2025-55289 |
Chamilo: Stored Cross Site Scripting in Skills Argumentation |
06.03.2026 |
8.8 |
| CVE-2025-59540 |
Chamilo: Stored Cross-Site Scripting (XSS) in Chamilo LMS Exercise Feedback |
06.03.2026 |
|
| CVE-2025-59541 |
Chamilo: CSRF Vulnerability in Project Deletion |
06.03.2026 |
8.1 |
| CVE-2025-59542 |
Chamilo: Account Takeover via Stored XSS in Course Learning Paths |
06.03.2026 |
9.1 |
| CVE-2025-59543 |
Chamilo: Account Takeover via Stored XSS in Course Description |
06.03.2026 |
9.1 |
| CVE-2025-59544 |
Chamilo: Unauthorized access to update category of any user |
06.03.2026 |
|
| CVE-2026-29041 |
Chamilo: Authenticated Remote Code Execution via Unrestricted File Upload |
06.03.2026 |
8.8 |
| CVE-2026-25962 |
MarkUs: Zip bomb in config upload enables DoS |
06.03.2026 |
6.5 |
| CVE-2026-27807 |
MarkUs: YAML alias (‘billion laughs’) DoS in config upload |
06.03.2026 |
4.9 |
| CVE-2026-28497 |
TinyWeb: Integer Overflow in `_Val` (HTTP Request Smuggling) |
06.03.2026 |
|
| CVE-2026-28501 |
WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php |
06.03.2026 |
9.8 |
| CVE-2026-28502 |
WWBN AVideo: Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction |
06.03.2026 |
|
| CVE-2026-29046 |
TinyWeb: HTTP Header Control Character Injection into CGI Environment |
06.03.2026 |
|
| CVE-2026-29093 |
WWBN AVideo: Unauthenticated PHP session store exposed to host network via published memcached port |
06.03.2026 |
8.1 |
| CVE-2026-3616 |
DefaultFuction Jeson Customer Relationship Management System edit.php sql injection |
06.03.2026 |
|
| CVE-2026-3613 |
Wavlink WL-NU516U1 login.cgi sub_401A0C stack-based overflow |
06.03.2026 |
|
| CVE-2026-3610 |
HSC Cybersecurity Mailinspector URL mliUserValidation.php cross site scripting |
06.03.2026 |
|
| CVE-2026-3612 |
Wavlink WL-NU516U1 OTA Online Upgrade adm.cgi sub_405AF4 command injection |
06.03.2026 |
|