CVEDatabase.com Logo

SearchCVE Vulnerabilities withAI-Powered Remediation Guidance

Powerful Analysis Tools

Everything you need to secure your infrastructure

CVE Trends & Highlights

Timeframe:
#1
CVE-2026-33054
CRITICAL

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that...

Mar 20
10.0CVSS
#2
CVE-2026-20079
CRITICAL

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypa...

Mar 4
10.0CVSS
#3
CVE-2026-2743
CRITICAL

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfe...

Mar 5
10.0CVSS
#4
CVE-2026-4725
CRITICAL

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149 and Thunderbird < 149.

Mar 24
10.0CVSS
#5
CVE-2026-28775
CRITICAL

An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series Supe...

Mar 4
10.0CVSS
#6
CVE-2026-21628
CRITICAL

A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

Mar 5
10.0CVSS
#7
CVE-2026-32169
CRITICAL

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

Mar 19
10.0CVSS
#8
CVE-2026-32760
CRITICAL

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2...

Mar 20
10.0CVSS
#9
CVE-2026-4688
CRITICAL

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbi...

Mar 24
10.0CVSS
#10
CVE-2026-4692
CRITICAL

Sandbox escape in the Responsive Design Mode component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbi...

Mar 24
10.0CVSS
#11
CVE-2026-4689
CRITICAL

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability affects Firefox < 149, Firefox ESR < ...

Mar 24
10.0CVSS
#12
CVE-2026-31852
CRITICAL

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code executi...

Mar 11
10.0CVSS
#13
CVE-2026-24898
CRITICAL

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disc...

Mar 3
10.0CVSS
#14
CVE-2026-30965
CRITICAL

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerabi...

Mar 10
9.9CVSS
#15
CVE-2026-30860
CRITICAL

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution ...

Mar 7
9.9CVSS
#16
CVE-2026-24109
CRITICAL

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this valu...

Mar 2
9.8CVSS
#17
CVE-2026-24111
CRITICAL

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo...

Mar 2
9.8CVSS
#18
CVE-2026-24114
CRITICAL

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`.

Mar 2
9.8CVSS
#19
CVE-2026-24115
CRITICAL

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before concatenating them into `gstrule...

Mar 2
9.8CVSS
#20
CVE-2026-24113
CRITICAL

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value i...

Mar 2
9.8CVSS

Latest from the Blog

View All
NIST NVD • CISA KEV • EPSS