Total CVEs

113,593

Critical Severity

1,059

High Severity

3,317

Last 7 Days

955
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 61 - 80 of 9,998 CVEs
CVE-2026-28423 MEDIUM - 6.8

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in insecure mode (which is not the default), the image proxy can be abused by an unauthenticated user to make the server send HTTP requests to arbitrary ...

Vendor: statamic
Product: cms
Published: Feb 27, 2026
Source: NVD

Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 containย an authenticated server-side request forgery vulnerability that allows Author-level users to fetch internal HTTP resources. Attackers can exploit insecure URL fetching and file write operations t...

Vendor: Dhrumil Kumbhani
Product: Featured Image from Content
Published: Feb 27, 2026
Source: NVD

Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a very wide terminal. Version 9.2.0078 patches the issue.

Vendor: vim
Product: vim
Published: Feb 27, 2026
Source: NVD
CVE-2026-28421 MEDIUM - 5.3

Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks within a swap file. Version 9.2.0077 fixes the ...

Vendor: vim
Product: vim
Published: Feb 27, 2026
Source: NVD
CVE-2026-28420 MEDIUM - 4.4

Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.

Vendor: vim
Product: vim
Published: Feb 27, 2026
Source: NVD
CVE-2026-28419 MEDIUM - 5.3

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim attempts to read memory immediately precedin...

Vendor: vim
Product: vim
Published: Feb 27, 2026
Source: NVD
CVE-2026-28418 MEDIUM - 4.4

Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up to 7 bytes beyond the allocated memory bound...

Vendor: vim
Product: vim
Published: Feb 27, 2026
Source: NVD
CVE-2026-28417 MEDIUM - 4.4

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell comm...

Vendor: vim
Product: vim
Published: Feb 27, 2026
Source: NVD
CVE-2026-28416 HIGH - 8.2

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP requests from a victim's server by hosting a malicious Gradio Space. When a victim application u...

Vendor: gradio-app
Product: gradio
Published: Feb 27, 2026
Source: NVD
CVE-2026-28415 MEDIUM - 4.3

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query parameter, allowing redirection to arbitrary external URLs. This affects the /logout and /login/call...

Vendor: gradio-app
Product: gradio
Published: Feb 27, 2026
Source: NVD
CVE-2026-28414 HIGH - 7.5

Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables unauthenticated attackers to read arbitrary files from the file system. Python 3.13+ changed t...

Vendor: gradio-app
Product: gradio
Published: Feb 27, 2026
Source: NVD
CVE-2026-28411 CRITICAL - 9.8

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This vulnerability can be leveraged to completely bypass authe...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Feb 27, 2026
Source: NVD
CVE-2026-28409 CRITICAL - 10.0

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authen...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Feb 27, 2026
Source: NVD
CVE-2026-28408 CRITICAL - 9.8

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its own authentication and permission checks. A malicious user could make a request through tools lik...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Feb 27, 2026
Source: NVD

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives ...

Vendor: chainguard-dev
Product: malcontent
Published: Feb 27, 2026
Source: NVD
CVE-2026-28406 HIGH - 8.2

kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to version 1.25.10, kaniko unpacks build context archives using `filepath.Join(dest, cleanedName)` without enforcing that the final path stays within `dest`. A...

Vendor: chainguard-forks
Product: kaniko
Published: Feb 27, 2026
Source: NVD
CVE-2026-28402 HIGH - 7.1

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.2.2, a malicious or compromised validator that is elected as proposer can publish a macro block proposal where `header.body_root` does not match the ac...

Vendor: nimiq
Product: core-rs-albatross
Published: Feb 27, 2026
Source: NVD
CVE-2026-28400 HIGH - 7.5

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint that accepts arbitrary runtime flags without authentication. These flags are passed directly to the underlying inference server (llama...

Vendor: docker
Product: model-runner
Published: Feb 27, 2026
Source: NVD
CVE-2026-27939 HIGH - 8.8

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitiv...

Vendor: statamic
Product: cms
Published: Feb 27, 2026
Source: NVD

Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are used. When ...

Vendor: gradio-app
Product: gradio
Published: Feb 27, 2026
Source: NVD