🛡️ CVE Vulnerability Database
CVE vulnerabilities with bilingual AI analysis tailored for Saudi Arabia
| CVE ID | Title / Description | Severity | CVSS | Status | Published |
|---|---|---|---|---|---|
| CVE-2026-3502 |
TrueConf Client Code Integrity Vulnerability - Arbitrary Code Exe…
TrueConf Client — CVE-2026-3502
TrueConf Client contains a download of code without integrity check …
|
CRITICAL |
9.8
|
KEV AI | Apr 2, 2026 |
| CVE-2026-5281 |
Google Dawn — CVE-2026-5281
Google Dawn contains an use-after-fre…
Google Dawn — CVE-2026-5281
Google Dawn contains an use-after-free vulnerability that could allow a …
|
CRITICAL |
9.8
|
KEV AI | Apr 1, 2026 |
| CVE-2026-30877 |
baserCMS is a website development framework. Prior to version 5.2…
baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injectio…
|
CRITICAL |
9.1
|
AI | Mar 31, 2026 |
| CVE-2026-21861 |
baserCMS is a website development framework. Prior to version 5.2…
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command…
|
CRITICAL |
9.1
|
⚡ AI | Mar 31, 2026 |
| CVE-2026-34714 |
Vim before 9.2.0272 allows code execution that happens immediatel…
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in th…
|
CRITICAL |
9.2
|
✅ AI | Mar 30, 2026 |
| CVE-2026-3055 |
Citrix NetScaler SAML IDP Out-of-Bounds Read Vulnerability (CVE-2…
Citrix NetScaler — CVE-2026-3055
Citrix NetScaler ADC (formerly Citrix ADC), NetScaler Gateway (form…
|
CRITICAL |
9.8
|
KEV AI | Mar 30, 2026 |
| CVE-2026-33757 |
OpenBao JWT/OIDC Authentication Bypass via Direct Callback Mode
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao …
|
CRITICAL |
9.6
|
✅ AI | Mar 27, 2026 |
| CVE-2025-53521 |
F5 BIG-IP APM Stack-Based Buffer Overflow Remote Code Execution
F5 BIG-IP — CVE-2025-53521
F5 BIG-IP APM contains a stack-based buffer overflow vulnerability that c…
|
CRITICAL |
9.8
|
KEV AI | Mar 27, 2026 |
| CVE-2026-33670 |
SiYuan Path Traversal Vulnerability in /api/file/readDir Interfac…
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir inte…
|
CRITICAL |
9.8
|
⚡ AI | Mar 26, 2026 |
| CVE-2026-33669 |
SiYuan Knowledge Management System Unauthorized Document Access v…
SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieve…
|
CRITICAL |
9.8
|
⚡ AI | Mar 26, 2026 |
| CVE-2026-33152 |
Tandoor Recipes is an application for managing recipes, planning …
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists.…
|
CRITICAL |
9.1
|
⚡ AI | Mar 26, 2026 |
| CVE-2026-33017 |
Langflow Unauthenticated Code Injection Vulnerability (CVE-2026-3…
Langflow Langflow — CVE-2026-33017
Langflow contains a code injection vulnerability that could allow…
|
CRITICAL |
9.8
|
KEV AI | Mar 25, 2026 |
| CVE-2026-33502 |
WWBN AVideo is an open source video platform. In versions up to a…
WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticat…
|
CRITICAL |
9.3
|
⚡ ✅ AI | Mar 23, 2026 |
| CVE-2025-60949 |
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP i…
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unaut…
|
CRITICAL |
9.1
|
✅ AI | Mar 23, 2026 |
| CVE-2026-33136 |
WeGIA is a web manager for charitable institutions. Versions 3.6.…
WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-…
|
CRITICAL |
9.3
|
⚡ ✅ AI | Mar 20, 2026 |
| CVE-2026-33135 |
WeGIA is a web manager for charitable institutions. Versions 3.6.…
WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-…
|
CRITICAL |
9.3
|
⚡ ✅ AI | Mar 20, 2026 |
| CVE-2025-54068 |
Laravel Livewire Remote Code Injection Vulnerability (CVE-2025-54…
Laravel Livewire — CVE-2025-54068
Laravel Livewire contain a code injection vulnerability that could…
|
CRITICAL |
9.8
|
KEV AI | Mar 20, 2026 |
| CVE-2025-43520 |
Apple Multiple Products Buffer Overflow - CVE-2025-43520
Apple Multiple Products — CVE-2025-43520
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS conta…
|
CRITICAL |
9.8
|
KEV AI | Mar 20, 2026 |
| CVE-2025-43510 |
Apple Multiple Products Memory Locking Vulnerability (CVE-2025-43…
Apple Multiple Products — CVE-2025-43510
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS conta…
|
CRITICAL |
9.8
|
KEV AI | Mar 20, 2026 |
| CVE-2025-32432 |
Craft CMS Remote Code Execution Vulnerability (CVE-2025-32432)
Craft CMS Craft CMS — CVE-2025-32432
Craft CMS contains a code injection vulnerability that allows a…
|
CRITICAL |
9.8
|
KEV AI | Mar 20, 2026 |
| CVE-2025-31277 |
Apple Multiple Products — CVE-2025-31277
Apple Safari, iOS, watch…
Apple Multiple Products — CVE-2025-31277
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tv…
|
CRITICAL |
9.8
|
KEV AI | Mar 20, 2026 |
| CVE-2026-20131 |
Cisco Secure Firewall Management Center Unauthenticated Remote Co…
Cisco Secure Firewall Management Center (FMC) — CVE-2026-20131
Cisco Secure Firewall Management Cent…
|
CRITICAL |
9.8
|
KEV AI | Mar 19, 2026 |
| CVE-2025-66376 |
Synacor Zimbra Collaboration Suite XSS Vulnerability via CSS @imp…
Synacor Zimbra Collaboration Suite (ZCS) — CVE-2025-66376
Synacor Zimbra Collaboration Suite (ZCS) c…
|
CRITICAL |
9.8
|
KEV AI | Mar 18, 2026 |
| CVE-2025-47813 |
Wing FTP Server Sensitive Information Disclosure via UID Cookie
Wing FTP Server Wing FTP Server — CVE-2025-47813
Wing FTP Server contains a generation of error mess…
|
CRITICAL |
9.8
|
KEV AI | Mar 16, 2026 |
| CVE-2026-3910 |
Google Chromium V8 — CVE-2026-3910
Google Chromium V8 contains an…
Google Chromium V8 — CVE-2026-3910
Google Chromium V8 contains an improper restriction of operations…
|
CRITICAL |
9.8
|
KEV AI | Mar 13, 2026 |