Vulnerebility MARCH
H
ECV
KB
KEV
|
2026()
2025()
|
Vulnerebility Calendar
Top Vulnerebility
List of Attack
CWE
Anti-Debug
Tricks
2026 January February March April May June July August September October November December
|
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
| 28.3.26 | CVE-2025-53521 | F5 BIG-IP Unspecified Vulnerability: F5 BIG-IP AMP contains an unspecified vulnerability that could allow a threat actor to achieve remote code execution. | VULNEREBILITY | VULNEREBILITY |
| 28.3.26 | CVE-2026-3055 | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | VULNEREBILITY | VULNEREBILITY |
| 28.3.26 | CVE-2026-4681 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. | VULNEREBILITY | VULNEREBILITY |
| 28.3.26 | CVE-2025-15517 | A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations. | VULNEREBILITY | VULNEREBILITY |
| 27.3.26 | Open Sesame | Open Sesame: How a Fail-Open Bug in Open VSX's New Scanner Let Malware Walk Right In | VULNEREBILITY | VULNEREBILITY |
| 26.3.26 | CVE-2026-3564 | A condition in ScreenConnect may allow an actor with access to server-level cryptographic material used for authentication to obtain unauthorized access, including elevated privileges, in certain scenarios. | ||
| 26.3.26 | CVE-2026-22557 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account. | ||
| 24.3.26 | CVE-2026-3055 | (CVSS score: 9.3) - Insufficient input validation leading to memory overread | ||
| 24.3.26 | CVE-2026-4368 | (CVSS score: 7.7) - Race condition leading to user session mixup | ||
| 24.3.26 | CVE-2025-32975 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover. | ||
| 22.3.26 | CVE-2025-27889 | Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an arbitrary link. If a user clicks a crafted link, this discloses a cleartext password to the attacker. | ||
| 22.3.26 | CVE-2025-47812 | In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). | ||
| 21.3.26 | CVE-2026-21992 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). | ||
| 21.3.26 | CVE-2025-31277 | (CVSS score: 8.8) - A vulnerability in Apple WebKit that could result in memory corruption when processing maliciously crafted web content. (Fixed in July 2025) | ||
| 21.3.26 | CVE-2025-43510 | (CVSS score: 7.8) - A memory corruption vulnerability in Apple's kernel component that could allow a malicious application to cause unexpected changes in memory shared between processes. (Fixed in December 2025) | ||
| 21.3.26 | CVE-2025-43520 | (CVSS score: 8.8) - A memory corruption vulnerability in Apple's kernel component that could allow a malicious application to cause unexpected system termination or write kernel memory. (Fixed in December 2025) | ||
| 21.3.26 | CVE-2025-32432 | (CVSS score: 10.0) - A code injection vulnerability in Craft CMS that could allow a remote attacker to execute arbitrary code. (Fixed in April 2025) | ||
| 21.3.26 | CVE-2025-54068 | (CVSS score: 9.8) - A code injection vulnerability in Laravel Livewire that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. (Fixed in July 2025) | ||
| 19.3.26 | DarkSword | Inside DarkSword: A New iOS Exploit Kit Delivered Via Compromised Legitimate Websites | ||
| 19.3.26 | CVE-2025-43520 | Memory corruption vulnerability in the iOS kernel (Patched in versions 18.7.2 and 26.1) | ||
| 19.3.26 | CVE-2025-43510 | Memory management vulnerability in the iOS kernel (Patched in versions 18.7.2 and 26.1) | ||
| 19.3.26 | CVE-2025-14174 | Memory corruption vulnerability in ANGLE (Patched in versions 18.7.3 and 26.2) | ||
| 19.3.26 | CVE-2025-43529 | Memory corruption vulnerability in JavaScriptCore (Patched in versions 18.7.3 and 26.2) | ||
| 19.3.26 | CVE-2026-20700 | User-mode Pointer Authentication Code (PAC) bypass in dyld (Patched in version 26.3) | ||
| 19.3.26 | CVE-2025-31277 | Memory corruption vulnerability in JavaScriptCore (Patched in version 18.6) | ||
| 19.3.26 | CVE-2026-20963 | (CVSS score: 8.8) - A deserialization of untrusted data vulnerability in Microsoft Office SharePoint that allows an unauthorized attacker to execute code over a network. (Fixed in January 2026) | ||
| 19.3.26 | CVE-2025-66376 | (CVSS score: 7.2) - A stored cross-site scripting vulnerability in the Classic UI of ZCS, where attackers could abuse Cascading Style Sheets (CSS) @import directives in an HTML e-mail message. (Fixed in versions 10.0.18 and 10.1.13 in November 2025) | ||
| 19.3.26 | CVE-2026-20131 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. | ||
| 18.3.26 | CVE-2026-32746 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full. | ||
| 18.3.26 | CVE-2026-3888 | Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS. | ||
| 18.3.26 | CVE-2026-20643 | A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. | ||
| 17.3.26 | CVE-2025-47813 | Wing FTP Server Information Disclosure Vulnerability: Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie. | ||
| 15.3.26 | CVE-2023-43000 | Apple Multiple products Use-After-Free Vulnerability: Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption. | ||
| 15.3.26 | CVE-2021-30952 | Apple Multiple Products Integer Overflow or Wraparound Vulnerability: Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web content that may lead to arbitrary code execution. | ||
| 15.3.26 | CVE-2023-41974 | Apple iOS and iPadOS Use-After-Free Vulnerability: Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges. | ||
| 13.3.26 | CVE-2026-21671 | (CVSS score: 9.1) - A vulnerability that allows an authenticated user with the Backup Administrator role to perform remote code execution in high availability (HA) deployments of Veeam Backup & Replication. | ||
| 13.3.26 | CVE-2026-21669 | (CVSS score: 9.9) - A vulnerability that allows an authenticated domain user to perform remote code execution on the Backup Server. | ||
| 13.3.26 | CVE-2026-21666 | (CVSS score: 9.9) - A vulnerability that allows an authenticated domain user to perform remote code execution on the Backup Server. | ||
| 13.3.26 | CVE-2026-21667 | (CVSS score: 9.9) - A vulnerability that allows an authenticated domain user to perform remote code execution on the Backup Server. | ||
| 13.3.26 | CVE-2026-21668 | (CVSS score: 8.8) - A vulnerability that allows an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository. | ||
| 13.3.26 | CVE-2026-21672 | (CVSS score: 8.8) - A vulnerability that allows local privilege escalation on Windows-based Veeam Backup & Replication servers. | ||
| 13.3.26 | CVE-2026-21708 | (CVSS score: 9.9) - A vulnerability that allows a Backup Viewer to perform remote code execution as the postgres user. | ||
| 13.3.26 | CVE-2026-3909 | (CVSS score: 8.8) - An out-of-bounds write vulnerability in the Skia 2D graphics library that allows a remote attacker to perform out-of-bounds memory access via a crafted HTML page. | ||
| 13.3.26 | CVE-2026-3910 | (CVSS score: 8.8) - An inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | ||
| 13.3.26 | CrackArmor | CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root | ||
| 12.3.26 | CVE-2023-43010 | The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption. | ||
| 12.3.26 | CVE-2025-68613 | n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. | ||
| 11.3.26 | CVE-2026-27577 | (CVSS score: 9.4) - Expression sandbox escape leading to remote code execution (RCE) | ||
| 11.3.26 | CVE-2026-27493 | (CVSS score: 9.5) - Unauthenticated expression evaluation via n8n's Form nodes | ||
| 11.3.26 | CVE-2026-26144 | Microsoft Excel Information Disclosure Vulnerability | ||
| 11.3.26 | CVE-2026-26118 | Azure MCP Server Tools Elevation of Privilege Vulnerability | ||
| 11.3.26 | CVE-2026-25187 | Winlogon Elevation of Privilege Vulnerability | ||
| 11.3.26 | CVE-2026-21536 | Microsoft Devices Pricing Program Remote Code Execution Vulnerability | ||
| 11.3.26 | CVE-2026-21262 | SQL Server Elevation of Privilege Vulnerability | ||
| 11.3.26 | CVE-2026-26127 | .NET Denial of Service Vulnerability | ||
| 11.3.26 | CVE-2026-27685 | SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system. | ||
| 11.3.26 | CVE-2019-17571 | Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17. | ||
| 11.3.26 | LeakyLooker | LeakyLooker: Hacking Google Cloud’s Data via Dangerous Looker Studio Vulnerabilities | ||
| 10.3.26 | CVE-2021-22054 | (CVSS score: 7.5) - A server-side request forgery (SSRF) vulnerability in Omnissa Workspace One UEM (formerly VMware Workspace One UEM) that could allow a malicious actor with network access to UEM to send requests without authentication and to gain access to sensitive information. | ||
| 10.3.26 | CVE-2025-26399 | (CVSS score: 9.8) - A deserialization of untrusted data vulnerability in the AjaxProxy component of SolarWinds Web Help Desk that could allow an attacker to run commands on the host machine. | ||
| 10.3.26 | CVE-2026-1603 | (CVSS score: 8.6) - An authentication bypass using an alternate path or channel vulnerability in Ivanti Endpoint Manager that could allow a remote unauthenticated attacker to leak specific stored credential data. | ||
| 8.3.26 | CVE-2026-27636 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/Misc/Helper.php` does not include `.htaccess` or `.user.ini` files. | ||
| 8.3.26 | CVE-2026-28289 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check | ||
| 8.3.26 | CVE-2026-20131 | Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability | ||
| 8.3.26 | CVE-2026-20079 | Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability | ||
| 6.3.26 | CVE-2026-20122 | A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. | ||
| 6.3.26 | CVE-2026-20128 | A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges on an affected system. | ||
| 6.3.26 | CVE-2017-7921 | (CVSS score: 9.8) - An improper authentication vulnerability affecting multiple Hikvision products that could allow a malicious user to escalate privileges on the system and gain access to sensitive information. | ||
| 6.3.26 | CVE-2021-22681 | (CVSS score: 9.8) - An insufficiently protected credentials vulnerability affecting multiple Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers that could allow an unauthorized user with network access to the controller to bypass the verification mechanism and authenticate with it, as well as alter its configuration and/or application code. | ||
| 5.3.26 | CVE-2026-1459 | A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.7)C0 could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on an affected device. | ||
| 5.3.26 | CVE-2025-13943 | A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device. | ||
| 5.3.26 | CVE-2025-13942 | A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests. | ||
| 5.3.26 | CVE-2025-11848 | A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. | ||
| 5.3.26 | CVE-2025-11847 | A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. | ||
| 5.3.26 | CVE-2025-11846 | A null pointer dereference vulnerability in the account settings CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. | ||
| 5.3.26 | CVE-2025-11845 | A null pointer dereference vulnerability in the certificate downloader CGI program of the Zyxel VMG3625-T50B firmware versions through 5.50(ABPM.9.6)C0 and the Zyxel WX3100-T0 firmware versions through 5.50(ABVL.4.8)C0 could allow an authenticated attacker with administrator privileges to trigger a denial-of-service (DoS) condition by sending a crafted HTTP request. | ||
| 4.3.26 | CVE-2026-21902 | An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. | ||
| 4.3.26 | CVE-2026-22719 | VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress. | ||
| 3.3.26 | CVE-2026-21385 | Memory corruption while using alignments for memory allocation. | ||
| 3.3.26 | CVE-2026-0628 | Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High) | ||
| 1.3.26 | ClawJacked | OpenClaw Vulnerability: Website-to-Local Agent Takeover | ||
| 1.3.26 | CVE-2026-25593 | Unauthenticated Local RCE via WebSocket config.apply | ||
| 1.3.26 | CVE-2026-24763 | Command Injection in Clawdbot Docker Execution via PATH Environment Variable | ||
| 1.3.26 | CVE-2026-25157 | OS Command Injection via Project Root Path in sshNodeCommand | ||
| 1.3.26 | CVE-2026-25475 | OpenClaw may disclose local files via MEDIA: path staging | ||
| 1.3.26 | CVE-2025-49113 | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. | ||