Export limit exceeded: 339902 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (339902 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-32911 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32910 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32909 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32908 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32907 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32904 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32903 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32902 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32901 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32900 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32066 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32047 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-32012 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-28483 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-28455 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-22173 | 2026-03-23 | N/A | ||
| This CVE ID has been rejected. | ||||
| CVE-2026-33476 | 2 B3log, Siyuan | 2 Siyuan, Siyuan | 2026-03-23 | 7.5 High |
| SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory traversal and read arbitrary files accessible to the server process. Authentication checks explicitly exclude this endpoint, allowing exploitation without valid credentials. Version 3.6.2 fixes this issue. | ||||
| CVE-2026-32810 | 2 Halloy, Squidowl | 2 Halloy, Halloy | 2026-03-23 | 5.5 Medium |
| Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb, halloy creates its config directory and files using default umask permissions, which typically results in `0644` on files and `0755` on directories. This allows any local user on the system to read plaintext credentials stored in `config.toml` or referenced `password_file` paths. Commit f180e41061db393acf65bc99f5c5e7397586d9cb patches the issue. | ||||
| CVE-2026-33171 | 1 Statamic | 2 Cms, Statamic | 2026-03-23 | 4.3 Medium |
| Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticated Control Panel users could read arbitrary `.json`, `.yaml`, and `.csv` files from the server by manipulating the file dictionary's `filename` configuration parameter in the fieldtype's endpoint. This has been fixed in 5.73.14 and 6.7.0. | ||||
| CVE-2026-33210 | 1 Ruby | 1 Json | 2026-03-23 | 6.5 Medium |
| Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_duplicate_key: false parsing option is used to parse user supplied documents. This issue has been patched in versions 2.15.2.1, 2.17.1.2, and 2.19.2. | ||||