Total
336347 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-26892 | 1 Oretnom23 | 1 Simple Logistic Hub Parcel\'s Management System | 2026-03-05 | N/A | 7.2 HIGH |
|
Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.
|
|||||
| CVE-2026-28546 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 5.9 MEDIUM |
|
Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-3136 | 1 Google | 1 Cloud Build | 2026-03-05 | N/A | 9.8 CRITICAL |
|
An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment.
This vulnerability was patched on 26 January 2026, and no customer action is needed.
|
|||||
| CVE-2026-28547 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 6.8 MEDIUM |
|
Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-28548 | 1 Huawei | 2 Emui, Harmonyos | 2026-03-05 | N/A | 7.1 HIGH |
|
Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2025-66680 | 1 Wisecleaner | 1 Wise Force Deleter | 2026-03-05 | N/A | 7.1 HIGH |
|
An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to delete arbitrary files via a crafted request.
|
|||||
| CVE-2026-28549 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 6.6 MEDIUM |
|
Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-24103 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2026-03-05 | N/A | 9.8 CRITICAL |
|
A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.
|
|||||
| CVE-2026-28551 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 4.7 MEDIUM |
|
Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2025-70821 | 1 Renren | 1 Renren-security | 2026-03-05 | N/A | 9.8 CRITICAL |
|
renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component
|
|||||
| CVE-2026-28542 | 1 Huawei | 2 Emui, Harmonyos | 2026-03-05 | N/A | 7.3 HIGH |
|
Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-28552 | 1 Huawei | 2 Emui, Harmonyos | 2026-03-05 | N/A | 6.5 MEDIUM |
|
Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-28550 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 4.0 MEDIUM |
|
Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-28545 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 5.9 MEDIUM |
|
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-28544 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 6.2 MEDIUM |
|
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-28543 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 4.4 MEDIUM |
|
Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-28541 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 4.0 MEDIUM |
|
Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-28540 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 4.0 MEDIUM |
|
Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2026-28539 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 6.2 MEDIUM |
|
Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
|
|||||
| CVE-2026-28538 | 1 Huawei | 1 Harmonyos | 2026-03-05 | N/A | 5.9 MEDIUM |
|
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.
|
|||||
| CVE-2026-3437 | 1 Portwell | 1 Engineering Toolkits | 2026-03-05 | N/A | 7.8 HIGH |
|
An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.
|
|||||
| CVE-2026-3484 | 1 Phialsbasement | 1 Mcp Nmap Server | 2026-03-05 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The patch is identi ...
Show More |
|||||
| CVE-2026-2201 | 1 Zerowdd | 1 Studentmanager | 2026-03-05 | 3.3 LOW | 2.4 LOW |
|
A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLeave of the file src/main/java/com/wdd/studentmanager/controller/LeaveController.java. The manipulation of the argument Reason for Leave leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, spec ...
Show More |
|||||
| CVE-2026-2178 | 1 R-huijts | 1 Xcode Mcp Server | 2026-03-05 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file src/tools/xcode/index.ts of the component run_lldb. The manipulation of the argument args results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affecte ...
Show More |
|||||
| CVE-2026-2153 | 1 Mwielgoszewski | 1 Doorman | 2026-03-05 | 5.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can lead to open redirect. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
|
|||||
| CVE-2026-1567 | 1 Ibm | 1 Infosphere Information Server | 2026-03-05 | N/A | 7.1 HIGH |
|
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.
|
|||||
| CVE-2025-14480 | 1 Ibm | 1 Aspera Faspio Gateway | 2026-03-05 | N/A | 5.1 MEDIUM |
|
IBM Aspera faspio Gateway 1.3.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information
|
|||||
| CVE-2026-2145 | 1 Cym1102 | 1 Nginxwebui | 2026-03-05 | 4.0 MEDIUM | 3.5 LOW |
|
A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the file /adminPage/conf/check of the component Web Management Interface. Such manipulation of the argument nginxDir leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
|
|||||
| CVE-2026-24502 | 1 Dell | 1 Command \| Intel Vpro Out Of Band | 2026-03-05 | N/A | 8.8 HIGH |
|
Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
|
|||||
| CVE-2026-25906 | 1 Dell | 1 Optimizer | 2026-03-05 | N/A | 7.3 HIGH |
|
Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
|
|||||
| CVE-2026-21866 | 1 Dify | 1 Dify | 2026-03-05 | N/A | 5.4 MEDIUM |
|
Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid configuration uses securityLevel: loose, which allows potentially unsafe content to execute. This vulnerability is fixed in 1.11.2.
|
|||||
| CVE-2026-25590 | 1 Glpi-project | 1 Glpi Inventory | 2026-03-05 | N/A | 4.5 MEDIUM |
|
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents. Prior to 1.6.6, there is a reflected XSS vulnerability in task jobs. This vulnerability is fixed in 1.6.6.
|
|||||
| CVE-2026-26266 | 1 Aliasvault | 1 Aliasvault | 2026-03-05 | N/A | 9.3 CRITICAL |
|
AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an alias, the HTML content is rendered in an iframe using srcdoc, which does not provide origin isolation. An attacker can send a crafted email containing malicious JavaScript to any AliasVault email alias. When the victim views the email in t ...
Show More |
|||||
| CVE-2026-2141 | 1 5kcrm | 1 Wukongcrm | 2026-03-05 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A security flaw has been discovered in WuKongOpenSource WukongCRM up to 11.3.3. This affects an unknown part of the file gateway/src/main/java/com/kakarote/gateway/service/impl/PermissionServiceImpl.java of the component URL Handler. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2026-26272 | 1 Sysadminsmedia | 1 Homebox | 2026-03-05 | N/A | 4.6 MEDIUM |
|
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does not properly validate or restrict uploaded file types, allowing an authenticated user to upload malicious HTML or SVG files containing executable JavaScript (also, potentially other formats that render scripts). Uploaded attachments are accessible via direct links. When a user accesses such a file in ...
Show More |
|||||
| CVE-2026-26279 | 1 Froxlor | 1 Froxlor | 2026-03-05 | N/A | 9.1 CRITICAL |
|
Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings in the panel.adminmail setting. This value is later concatenated into a shell command executed as root by a cron job, where the pipe character | is explicitly whitelisted. The result is full root-level Remote Code Exe ...
Show More |
|||||
| CVE-2026-29188 | 2026-03-05 | N/A | 9.1 CRITICAL | ||
|
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.1, a broken access control vulnerability in the TUS protocol DELETE endpoint allows authenticated users with only Create permission to delete arbitrary files and directories within their scope, bypassing the intended Delete permission restriction. Any multi-user deployment where administrators explicitly restrict file deletion fo ...
Show More |
|||||
| CVE-2026-29081 | 2026-03-05 | N/A | 6.5 MEDIUM | ||
|
Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to SQL injection through specially crafted requests, which would allow a malicious actor to extract sensitive information. This issue has been patched in versions 14.100.1 and 15.100.0.
|
|||||
| CVE-2026-29077 | 2026-03-05 | N/A | 7.1 HIGH | ||
|
Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user could share a document with a permission that they themselves didn't have. This issue has been patched in versions 15.98.0 and 14.100.0.
|
|||||
| CVE-2026-28492 | 2026-03-05 | N/A | N/A | ||
|
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.0, when a user creates a public share link for a directory, the withHashFile middleware in http/public.go uses filepath.Dir(link.Path) to compute the BasePathFs root. This sets the filesystem root to the parent directory instead of the shared directory itself, allowing anyone with the share link to browse and download files from ...
Show More |
|||||