Total CVEs

113,593

Critical Severity

1,059

High Severity

3,317

Last 7 Days

955
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 81 - 100 of 9,998 CVEs

Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Scripting vulnerability in the "PWA" Canarytoken, whereby the Canarytoken's creator can attack themselves or someone they share the link with. The creator of a PWA Canaryt...

Vendor: thinkst
Product: canarytokens
Published: Feb 27, 2026
Source: NVD
CVE-2026-28352 MEDIUM - 6.5

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event series is missing an access check, allowing unauthenticated/unauthorized access to this endpoint. The impact of this is ...

Vendor: indico
Product: indico
Published: Feb 27, 2026
Source: NVD

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream using the RunLengthDecode filter. This has been fixed in pypdf 6.7.4. As a workaround, ...

Vendor: py-pdf
Product: pypdf
Published: Feb 27, 2026
Source: NVD
CVE-2026-28338 MEDIUM - 6.8

PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report formats insert rule violation messages into HTML output without escaping. When PMD analyzes untrusted source code containing crafted string literals, the generated HTML report co...

Vendor: pmd
Product: pmd
Published: Feb 27, 2026
Source: NVD

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.

Vendor: langgenius
Product: dify
Published: Feb 27, 2026
Source: NVD
CVE-2026-28272 HIGH - 8.1

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a configuration interface. The stored script executes when users interact with the affected user interface....

Vendor: kiteworks
Product: security-advisories
Published: Feb 27, 2026
Source: NVD
CVE-2026-28271 MEDIUM - 6.5

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Malicious administrators could exploit this to access internal services that should be restricted. Version 9...

Vendor: kiteworks
Product: security-advisories
Published: Feb 27, 2026
Source: NVD
CVE-2026-28270 MEDIUM - 4.9

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system. Version 9.2.0 contains a patch for...

Vendor: kiteworks
Product: security-advisories
Published: Feb 27, 2026
Source: NVD
CVE-2026-28268 CRITICAL - 9.8

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a critical...

Vendor: go-vikunja
Product: vikunja
Published: Feb 27, 2026
Source: NVD

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend. For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject m...

Vendor: TOKUHIROM
Product: HTTP::Session2
Published: Feb 27, 2026
Source: NVD

HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP::Session2 session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epo...

Published: Feb 27, 2026
Source: NVD

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws, allowing a normal authenticated user to modify another user’s collection items. This affects both add item (/actions/add_to_collection.php) due to mis...

Vendor: MacWarrior
Product: clipbucket-v5
Published: Feb 27, 2026
Source: NVD

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds r...

Vendor: bigcat88
Product: pillow_heif
Published: Feb 27, 2026
Source: NVD

Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, and 6.8.154 have an authenticated Remote Code Execution vulnerability in the TNEF attachment processing flow. The vulnerable path extracts attacker-controlled files from `winmail.dat...

Vendor: Intermesh
Product: groupoffice
Published: Feb 27, 2026
Source: NVD
CVE-2026-27836 HIGH - 7.5

phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/prepare`) creates new active user accounts without any authentication, CSRF protection, captcha, or configuration checks. This allows unauthenticated attackers to create unlimited u...

Vendor: thorsten
Product: phpMyFAQ
Published: Feb 27, 2026
Source: NVD

Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, and 6.8.153 have a SQL Injection (SQLi) vulnerability, exploitable through the `advancedQueryData` parameter (`comparator` field) on an authenticated endpoint. The endpoint `index.ph...

Vendor: Intermesh
Product: groupoffice
Published: Feb 27, 2026
Source: NVD
CVE-2026-27824 MEDIUM - 5.3

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both `remote_addr` and the `X-Forwarded-For` header. Since the `X-Forwarded-For`...

Vendor: kovidgoyal
Product: calibre
Published: Feb 27, 2026
Source: NVD
CVE-2026-27810 MEDIUM - 6.4

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, an HTTP Response Header Injection vulnerability in the calibre Content Server allows any authenticated user to inject arbitrary HTTP headers into server responses via an unsan...

Vendor: kovidgoyal
Product: calibre
Published: Feb 27, 2026
Source: NVD
CVE-2026-27793 MEDIUM - 6.5

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `GET /api/v1/user/:id` endpoint returns the full settings object for any user, including Pushover, Pushbullet, and Telegram credentials, to any authenticated requester regardless of ...

Vendor: seerr-team
Product: seerr
Published: Feb 27, 2026
Source: NVD
CVE-2026-27792 MEDIUM - 5.4

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified in the application starting in version 2.7.0 and prior to version 3.1.0. It allows authenticated users to access and modify data belonging to other user...

Vendor: seerr-team
Product: seerr
Published: Feb 27, 2026
Source: NVD