Vulnerebility MARCH H  ECV  KB  KEV |  2026()  2025() |
Vulnerebility Calendar  Top Vulnerebility  List of Attack  CWE   Anti-Debug Tricks


2026  January  February  March  April  May  June  July  August  September  October  November  December


DATE

NAME

INFO

CATEGORY

SUBCATE

28.3.26 CVE-2025-53521 F5 BIG-IP Unspecified Vulnerability: F5 BIG-IP AMP contains an unspecified vulnerability that could allow a threat actor to achieve remote code execution. VULNEREBILITY VULNEREBILITY
28.3.26 CVE-2026-3055 Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread VULNEREBILITY VULNEREBILITY
28.3.26 CVE-2026-4681 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. VULNEREBILITY VULNEREBILITY
28.3.26 CVE-2025-15517 A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations. VULNEREBILITY VULNEREBILITY
27.3.26 Open Sesame Open Sesame: How a Fail-Open Bug in Open VSX's New Scanner Let Malware Walk Right In VULNEREBILITY VULNEREBILITY
26.3.26 CVE-2026-3564 A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios.

VULNEREBILITY

VULNEREBILITY

26.3.26 CVE-2026-22557 A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.

VULNEREBILITY

VULNEREBILITY

24.3.26 CVE-2026-3055 (CVSS score: 9.3) - Insufficient input validation leading to memory overread

VULNEREBILITY

VULNEREBILITY

24.3.26 CVE-2026-4368 (CVSS score: 7.7) - Race condition leading to user session mixup

VULNEREBILITY

VULNEREBILITY

24.3.26 CVE-2025-32975 Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover.

VULNEREBILITY

VULNEREBILITY

22.3.26 CVE-2025-27889 Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker.

VULNEREBILITY

VULNEREBILITY

22.3.26 CVE-2025-47812 In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default).

VULNEREBILITY

VULNEREBILITY

21.3.26 CVE-2026-21992 Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).

VULNEREBILITY

VULNEREBILITY

21.3.26 CVE-2025-31277 (CVSS score: 8.8) - A vulnerability in Apple WebKit that could result in memory corruption when processing maliciously crafted web content. (Fixed in July 2025)

VULNEREBILITY

VULNEREBILITY

21.3.26 CVE-2025-43510 (CVSS score: 7.8) - A memory corruption vulnerability in Apple's kernel component that could allow a malicious application to cause unexpected changes in memory shared between processes. (Fixed in December 2025)

VULNEREBILITY

VULNEREBILITY

21.3.26 CVE-2025-43520 (CVSS score: 8.8) - A memory corruption vulnerability in Apple's kernel component that could allow a malicious application to cause unexpected system termination or write kernel memory. (Fixed in December 2025)

VULNEREBILITY

VULNEREBILITY

21.3.26 CVE-2025-32432 (CVSS score: 10.0) - A code injection vulnerability in Craft CMS that could allow a remote attacker to execute arbitrary code. (Fixed in April 2025)

VULNEREBILITY

VULNEREBILITY

21.3.26 CVE-2025-54068 (CVSS score: 9.8) - A code injection vulnerability in Laravel Livewire that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. (Fixed in July 2025)

VULNEREBILITY

VULNEREBILITY

19.3.26 DarkSword Inside DarkSword: A New iOS Exploit Kit Delivered Via Compromised Legitimate Websites

VULNEREBILITY

VULNEREBILITY

19.3.26 CVE-2025-43520 Memory corruption vulnerability in the iOS kernel (Patched in versions 18.7.2 and 26.1)

VULNEREBILITY

VULNEREBILITY

19.3.26 CVE-2025-43510 Memory management vulnerability in the iOS kernel (Patched in versions 18.7.2 and 26.1)

VULNEREBILITY

VULNEREBILITY

19.3.26 CVE-2025-14174 Memory corruption vulnerability in ANGLE (Patched in versions 18.7.3 and 26.2)

VULNEREBILITY

VULNEREBILITY

19.3.26 CVE-2025-43529 Memory corruption vulnerability in JavaScriptCore (Patched in versions 18.7.3 and 26.2)

VULNEREBILITY

VULNEREBILITY

19.3.26 CVE-2026-20700 User-mode Pointer Authentication Code (PAC) bypass in dyld (Patched in version 26.3)

VULNEREBILITY

VULNEREBILITY

19.3.26 CVE-2025-31277 Memory corruption vulnerability in JavaScriptCore (Patched in version 18.6)

VULNEREBILITY

VULNEREBILITY

19.3.26 CVE-2026-20963 (CVSS score: 8.8) - A deserialization of untrusted data vulnerability in Microsoft Office SharePoint that allows an unauthorized attacker to execute code over a network. (Fixed in January 2026)

VULNEREBILITY

VULNEREBILITY

19.3.26 CVE-2025-66376 (CVSS score: 7.2) - A stored cross-site scripting vulnerability in the Classic UI of ZCS, where attackers could abuse Cascading Style Sheets (CSS) @import directives in an HTML e-mail message. (Fixed in versions 10.0.18 and 10.1.13 in November 2025)

VULNEREBILITY

VULNEREBILITY

19.3.26 CVE-2026-20131 A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream.

VULNEREBILITY

VULNEREBILITY

18.3.26 CVE-2026-32746 telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

VULNEREBILITY

VULNEREBILITY

18.3.26 CVE-2026-3888 Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

VULNEREBILITY

VULNEREBILITY

18.3.26 CVE-2026-20643 A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2.

VULNEREBILITY

VULNEREBILITY

17.3.26 CVE-2025-47813 Wing FTP Server Information Disclosure Vulnerability: Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.

VULNEREBILITY

VULNEREBILITY

15.3.26 CVE-2023-43000 Apple Multiple products Use-After-Free Vulnerability: Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption.

VULNEREBILITY

VULNEREBILITY

15.3.26 CVE-2021-30952 Apple Multiple Products Integer Overflow or Wraparound Vulnerability: Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution.

VULNEREBILITY

VULNEREBILITY

15.3.26 CVE-2023-41974 Apple iOS and iPadOS Use-After-Free Vulnerability: Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.

VULNEREBILITY

VULNEREBILITY

13.3.26 CVE-2026-21671 (CVSS score: 9.1) - A vulnerability that allows an authenticated user with the Backup Administrator role to perform remote code execution in high availability (HA) deployments of Veeam Backup & Replication.

VULNEREBILITY

VULNEREBILITY

13.3.26 CVE-2026-21669 (CVSS score: 9.9) - A vulnerability that allows an authenticated domain user to perform remote code execution on the Backup Server.

VULNEREBILITY

VULNEREBILITY

13.3.26 CVE-2026-21666 (CVSS score: 9.9) - A vulnerability that allows an authenticated domain user to perform remote code execution on the Backup Server.

VULNEREBILITY

VULNEREBILITY

13.3.26 CVE-2026-21667 (CVSS score: 9.9) - A vulnerability that allows an authenticated domain user to perform remote code execution on the Backup Server.

VULNEREBILITY

VULNEREBILITY

13.3.26 CVE-2026-21668 (CVSS score: 8.8) - A vulnerability that allows an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

VULNEREBILITY

VULNEREBILITY

13.3.26 CVE-2026-21672 (CVSS score: 8.8) - A vulnerability that allows local privilege escalation on Windows-based Veeam Backup & Replication servers.

VULNEREBILITY

VULNEREBILITY

13.3.26 CVE-2026-21708 (CVSS score: 9.9) - A vulnerability that allows a Backup Viewer to perform remote code execution as the postgres user.

VULNEREBILITY

VULNEREBILITY

13.3.26 CVE-2026-3909 (CVSS score: 8.8) - An out-of-bounds write vulnerability in the Skia 2D graphics library that allows a remote attacker to perform out-of-bounds memory access via a crafted HTML page.

VULNEREBILITY

VULNEREBILITY

13.3.26 CVE-2026-3910 (CVSS score: 8.8) - An inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

VULNEREBILITY

VULNEREBILITY

13.3.26 CrackArmor CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root

VULNEREBILITY

VULNEREBILITY

12.3.26 CVE-2023-43010 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

VULNEREBILITY

VULNEREBILITY

12.3.26 CVE-2025-68613 n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system.

VULNEREBILITY

VULNEREBILITY

11.3.26 CVE-2026-27577 (CVSS score: 9.4) - Expression sandbox escape leading to remote code execution (RCE)

VULNEREBILITY

VULNEREBILITY

11.3.26 CVE-2026-27493 (CVSS score: 9.5) - Unauthenticated expression evaluation via n8n's Form nodes

VULNEREBILITY

VULNEREBILITY

11.3.26 CVE-2026-26144 Microsoft Excel Information Disclosure Vulnerability

VULNEREBILITY

VULNEREBILITY

11.3.26 CVE-2026-26118 Azure MCP Server Tools Elevation of Privilege Vulnerability

VULNEREBILITY

VULNEREBILITY

11.3.26 CVE-2026-25187 Winlogon Elevation of Privilege Vulnerability

VULNEREBILITY

VULNEREBILITY

11.3.26 CVE-2026-21536 Microsoft Devices Pricing Program Remote Code Execution Vulnerability

VULNEREBILITY

VULNEREBILITY

11.3.26 CVE-2026-21262 SQL Server Elevation of Privilege Vulnerability

VULNEREBILITY

VULNEREBILITY

11.3.26 CVE-2026-26127 .NET Denial of Service Vulnerability

VULNEREBILITY

VULNEREBILITY

11.3.26 CVE-2026-27685 SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.

VULNEREBILITY

VULNEREBILITY

11.3.26 CVE-2019-17571 Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

VULNEREBILITY

VULNEREBILITY

11.3.26 LeakyLooker LeakyLooker: Hacking Google Cloud’s Data via Dangerous Looker Studio Vulnerabilities

VULNEREBILITY

VULNEREBILITY

10.3.26 CVE-2021-22054 (CVSS score: 7.5) - A server-side request forgery (SSRF) vulnerability in Omnissa Workspace One UEM (formerly VMware Workspace One UEM) that could allow a malicious actor with network access to UEM to send requests without authentication and to gain access to sensitive information.

VULNEREBILITY

VULNEREBILITY

10.3.26 CVE-2025-26399 (CVSS score: 9.8) - A deserialization of untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk that could allow an attacker to run commands on the host machine.

VULNEREBILITY

VULNEREBILITY

10.3.26 CVE-2026-1603 (CVSS score: 8.6) - An authentication bypass using an alternate path or channel vulnerability in Ivanti Endpoint Manager that could allow a remote unauthenticated attacker to leak specific stored credential data.

VULNEREBILITY

VULNEREBILITY

8.3.26 CVE-2026-27636 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/Misc/Helper.php` does not include `.htaccess` or `.user.ini` files.

VULNEREBILITY

VULNEREBILITY

8.3.26 CVE-2026-28289 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check

VULNEREBILITY

VULNEREBILITY

8.3.26 CVE-2026-20131 Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability

VULNEREBILITY

VULNEREBILITY

8.3.26 CVE-2026-20079 Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

VULNEREBILITY

VULNEREBILITY

6.3.26 CVE-2026-20122 A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system.

VULNEREBILITY

VULNEREBILITY

6.3.26 CVE-2026-20128 A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges on an affected system.

VULNEREBILITY

VULNEREBILITY

6.3.26 CVE-2017-7921 (CVSS score: 9.8) - An improper authentication vulnerability affecting multiple Hikvision products that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.

VULNEREBILITY

VULNEREBILITY

6.3.26 CVE-2021-22681 (CVSS score: 9.8) - An insufficiently protected credentials vulnerability affecting multiple Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers that could allow an unauthorized user with network access to the controller to bypass the verification mechanism and authenticate with it, as well as alter its configuration and/or application code.

VULNEREBILITY

VULNEREBILITY

5.3.26 CVE-2026-1459 A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device.

VULNEREBILITY

VULNEREBILITY

5.3.26 CVE-2025-13943 A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.

VULNEREBILITY

VULNEREBILITY

5.3.26 CVE-2025-13942 A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.

VULNEREBILITY

VULNEREBILITY

5.3.26 CVE-2025-11848 A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.

VULNEREBILITY

VULNEREBILITY

5.3.26 CVE-2025-11847 A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.

VULNEREBILITY

VULNEREBILITY

5.3.26 CVE-2025-11846 A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.

VULNEREBILITY

VULNEREBILITY

5.3.26 CVE-2025-11845 A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request.

VULNEREBILITY

VULNEREBILITY

4.3.26 CVE-2026-21902 An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root.

VULNEREBILITY

VULNEREBILITY

4.3.26 CVE-2026-22719 VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.

VULNEREBILITY

VULNEREBILITY

3.3.26 CVE-2026-21385 Memory corruption while using alignments for memory allocation.

VULNEREBILITY

VULNEREBILITY

3.3.26 CVE-2026-0628 Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

VULNEREBILITY

VULNEREBILITY

1.3.26 ClawJacked OpenClaw Vulnerability: Website-to-Local Agent Takeover

VULNEREBILITY

VULNEREBILITY

1.3.26 CVE-2026-25593 Unauthenticated Local RCE via WebSocket config.apply

VULNEREBILITY

VULNEREBILITY

1.3.26 CVE-2026-24763 Command Injection in Clawdbot Docker Execution via PATH Environment Variable

VULNEREBILITY

VULNEREBILITY

1.3.26 CVE-2026-25157 OS Command Injection via Project Root Path in sshNodeCommand

VULNEREBILITY

VULNEREBILITY

1.3.26 CVE-2026-25475 OpenClaw may disclose local files via MEDIA: path staging

VULNEREBILITY

VULNEREBILITY

1.3.26 CVE-2025-49113 Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

VULNEREBILITY

VULNEREBILITY