Total CVEs

113,593

Critical Severity

1,059

High Severity

3,317

Last 7 Days

949
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 101 - 120 of 9,998 CVEs
CVE-2026-27734 MEDIUM - 6.5

Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/containers/logs and GET /api/beszel/containers/info pass the user-supplied "container" query parameter to the agent without validation. The agent constructs Docker En...

Vendor: henrygd
Product: beszel
Published: Feb 27, 2026
Source: NVD
CVE-2026-27707 HIGH - 7.3

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and prior to version 3.1.0, an authentication guard logic flaw in `POST /api/v1/auth/jellyfin` allows an unauthenticated attacker to register a new Seerr account on any Plex-configured...

Vendor: seerr-team
Product: seerr
Published: Feb 27, 2026
Source: NVD

Rejected reason: Further research determined the situation described is not a vulnerability.

Published: Feb 27, 2026
Source: NVD

Rejected reason: Further research determined the situation described is not a vulnerability.

Published: Feb 27, 2026
Source: NVD

Rejected reason: Further research determined the situation described is not a vulnerability.

Published: Feb 27, 2026
Source: NVD

Rejected reason: Further research determined the situation described is not a vulnerability.

Published: Feb 27, 2026
Source: NVD

Rejected reason: Further research determined the situation described is not a vulnerability.

Published: Feb 27, 2026
Source: NVD

Rejected reason: Further research determined the situation described is not a vulnerability.

Published: Feb 27, 2026
Source: NVD

Rejected reason: Further research determined the situation described is not a vulnerability.

Published: Feb 27, 2026
Source: NVD

Rejected reason: Further research determined the situation described is not a vulnerability.

Published: Feb 27, 2026
Source: NVD

Rejected reason: Further research determined the situation described is not a vulnerability.

Published: Feb 27, 2026
Source: NVD

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can store the XSS payload. The payload is triggered by administrator. Version 5.5.3 #59 fixes the issue.

Vendor: MacWarrior
Product: clipbucket-v5
Published: Feb 27, 2026
Source: NVD

Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.

Vendor: VMware
Product: Workstation
Published: Feb 27, 2026
Source: NVD

A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example, app.use('/secret', auth)). When Fastify router normalization options are enabled (such as ignoreDuplicateSlashes, useSemicolonDelimiter,...

Vendor: npm
Product: @fastify/middie
Published: Feb 27, 2026
Source: NVD
CVE-2026-27758 MEDIUM - 4.3

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its management interface that allows attackers to induce authenticated users into submitting forged requests. Attackers can craft malicious requests that execute unauthorized configuratio...

Vendor: Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks)
Product: SODOLA SL902-SWTGW124AS
Published: Feb 27, 2026
Source: NVD
CVE-2026-27757 HIGH - 7.1

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authenticated users to change account passwords without verifying the current password. Attackers who gain access to an authenticated session can modify credentials to maintain persistent a...

Vendor: Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks)
Product: SODOLA SL902-SWTGW124AS
Published: Feb 27, 2026
Source: NVD
CVE-2026-27756 MEDIUM - 6.1

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the management interface where user input is not properly encoded before output. Attackers can craft malicious URLs that execute arbitrary JavaScript in the web interface when visited...

Vendor: Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks)
Product: SODOLA SL902-SWTGW124AS
Published: Feb 27, 2026
Source: NVD
CVE-2026-27755 CRITICAL - 9.8

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies. Attackers who know or guess valid credentials can calculate the session identifier o...

Vendor: Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks)
Product: SODOLA SL902-SWTGW124AS
Published: Feb 27, 2026
Source: NVD
CVE-2026-27754 MEDIUM - 6.5

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for session cookie generation, weakening session security. Attackers can exploit predictable session tokens combined with MD5's collision vulnerabilities to forge valid session cookies ...

Vendor: Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks)
Product: SODOLA SL902-SWTGW124AS
Published: Feb 27, 2026
Source: NVD

Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.

Vendor: VMware
Product: Workstation
Published: Feb 27, 2026
Source: NVD