CVE Find is a real-time vulnerability database indexing 340 630 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 1875 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-4960 |
2026-03-27 17h16 +00:00 |
A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle o... Overflow |
8.8 |
High |
|
CVE-2026-28369 |
2026-03-27 17h16 +00:00 |
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line sta... |
8.7 |
High |
|
CVE-2026-28368 |
2026-03-27 17h16 +00:00 |
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially cra... |
8.7 |
High |
|
CVE-2026-28367 |
2026-03-27 16h13 +00:00 |
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` a... |
8.7 |
High |
|
CVE-2026-4961 |
2026-03-27 16h09 +00:00 |
A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the funct... Overflow |
8.7 |
High |
|
CVE-2026-33757 |
2026-03-27 15h16 +00:00 |
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao ... |
9.6 |
Critical |
|
CVE-2026-33755 |
2026-03-27 15h16 +00:00 |
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions... SQL Injection |
8.8 |
High |
|
CVE-2026-27876 |
2026-03-27 15h16 +00:00 |
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary ... Code Injection |
9.1 |
Critical |
|
CVE-2026-5027 |
2026-03-27 14h54 +00:00 |
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form... Directory Traversal |
8.8 |
High |
|
CVE-2026-4984 |
2026-03-27 14h13 +00:00 |
The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twili... |
8.2 |
High |