Total CVEs

125,574

Critical Severity

2,253

High Severity

7,771

Last 7 Days

1,109
Quick preset (or use dates below)
Clear Filters
Showing 181 - 200 of 1,441 CVEs

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: update last_gc only when GC has been performed Currently last_gc is being updated everytime a new connection is tracked, that means that it is updated even if a GC wasn't performed. With a sufficientl...

Vendor: Linux
Product: Linux
Published: Feb 14, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: libceph: reset sparse-read state in osd_fault() When a fault occurs, the connection is abandoned, reestablished, and any pending operations are retried. The OSD client tracks the progress of a sparse-read reply using a separate st...

Vendor: Linux
Product: Linux
Published: Feb 14, 2026
Source: NVD

Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default ObjectURIs (including EndeavorServer.rem and RemoteFileReceiver.rem) and permits the use of SOAP and binary formatters with TypeFilterLevel set to Full. An ...

Vendor: Calero
Product: VeraSMART
Published: Feb 13, 2026
Source: NVD
CVE-2026-2327 MEDIUM - 5.3

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching character, which triggers exc...

Vendor: npm
Product: markdown-it
Published: Feb 12, 2026
Source: NVD
CVE-2026-2391 LOW - 3.7

### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6...

Vendor: npm
Product: qs
Published: Feb 12, 2026
Source: NVD
CVE-2026-25676 HIGH - 7.8

The installer of M-Track Duo HD version 1.0.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrator privileges.

Vendor: M-Audio
Product: M-Track Duo HD
Published: Feb 12, 2026
Source: NVD
CVE-2026-20676 MEDIUM - 5.3

This issue was addressed through improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, Safari 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.

Vendor: Apple
Product: Safari, macOS, visionOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD
CVE-2025-69873 HIGH - 7.5

ajv (Another JSON Schema Validator) through version 8.17.1 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() construct...

Vendor: npm
Product: ajv
Published: Feb 11, 2026
Source: NVD
CVE-2026-1215 MEDIUM - 4.3

The MMA Call Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.15. This is due to missing nonce validation when saving plugin configuration on the `mma_call_tracking_menu` admin page. This makes it possible for unauthenticated attacke...

Published: Feb 11, 2026
Source: NVD
CVE-2026-26006 MEDIUM - 6.5

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. The autogpt before 0.6.32 is vulnerable to Regular Expression Denial of Service due to the use of regex at Code Extraction Block. The two Regex are used co...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Feb 10, 2026
Source: NVD
CVE-2025-7347 HIGH - 8.8

Authorization Bypass Through User-Controlled Key vulnerability in Dinibh Puzzle Software Solutions Dinibh Patrol Tracking System allows Exploitation of Trusted Identifiers.This issue affects Dinibh Patrol Tracking System: through 10022026. NOTE: The vendor was contacted early about this disclosure ...

Published: Feb 10, 2026
Source: NVD
CVE-2026-25846 MEDIUM - 6.5

In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

Vendor: JetBrains
Product: YouTrack
Published: Feb 09, 2026
Source: NVD
CVE-2026-22904 CRITICAL - 9.8

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.

Vendor: WAGO
Product: 0852-1322, 0852-1328
Published: Feb 09, 2026
Source: NVD
CVE-2026-1611 MEDIUM - 6.4

The Wikiloops Track Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wikiloops` shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

Published: Feb 07, 2026
Source: NVD

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injection vulnerability occurs in the time tracking function of OpenProject. The application does not escape HTML tags, an attacker with administrator privileges can create a work packa...

Vendor: opf
Product: openproject
Published: Feb 06, 2026
Source: NVD
CVE-2026-25544 CRITICAL - 9.8

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attacks. An unauthenticated attacker could extract sensitive data (emails, password r...

Vendor: npm
Product: @payloadcms/drizzle
Published: Feb 05, 2026
Source: GitHub
CVE-2026-1897 MEDIUM - 4.3

A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization. The attack may be performed from remote. Upgrading to versi...

Vendor: wekan_project
Product: wekan
Published: Feb 05, 2026
Source: NVD
CVE-2026-25508 MEDIUM - 6.3

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, an out-of-bounds read vulnerability was reported in the BLE ATT Prepare Write handling of the BLE provisioning transport (protocomm_ble). The issue can be triggered by a remote...

Vendor: espressif
Product: esp-idf
Published: Feb 04, 2026
Source: NVD
CVE-2020-37092 HIGH - 7.5

Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to access the device with predefined credentials. Attackers can leverage the embedded root account with a crackable password to gain full administrative access to the network device.

Vendor: Netis Systems Co., Ltd.
Product: Netis E1+
Published: Feb 03, 2026
Source: NVD
CVE-2026-22229 HIGH - 7.2

A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe ...

Vendor: TP-Link Systems Inc.
Product: Archer BE230 v1.2
Published: Feb 02, 2026
Source: NVD