Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,647
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,541 - 2,560 of 3,451 CVEs
CVE-2026-28215 CRITICAL - 9.1

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials and SMTP settings by sending a single HTTP POST request with...

Vendor: hoppscotch
Product: hoppscotch
Published: Feb 26, 2026
Source: NVD
CVE-2026-28213 CRITICAL - 9.8

EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password" functionality. When specifying a target email address, the API response returns the password reset token. This allows an attacker to take over the associated account. Ve...

Vendor: evershopcommerce
Product: evershop
Published: Feb 26, 2026
Source: NVD
CVE-2026-22207 CRITICAL - 9.8

OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows unauthenticated attackers to gain ROOT privileges when the root_api_key configuration is omitted. Attackers can send requests to protected endpoints without authentication headers t...

Vendor: Volcengine
Product: OpenViking
Published: Feb 26, 2026
Source: NVD
CVE-2026-27510 CRITICAL - 9.6

Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores programs in a local SQLit...

Vendor: UnitreeRobotics
Product: Unitree Go2
Published: Feb 26, 2026
Source: NVD
CVE-2025-50857 CRITICAL - 9.8

ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code via a crafted file upload

Published: Feb 26, 2026
Source: NVD
CVE-2026-27975 CRITICAL - 9.8

Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access to a server to execute arbitrary code on this server. This is fixed in the version 2.2.13.

Vendor: ajenti
Product: ajenti
Published: Feb 26, 2026
Source: NVD
CVE-2026-27969 CRITICAL - 8.8

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that files in the manifest — which may be files that they have also ad...

Vendor: vitessio
Product: vitess
Published: Feb 26, 2026
Source: NVD
CVE-2026-27966 CRITICAL - 9.8

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). As a result, an attacker can execute arbitrary Py...

Vendor: langflow-ai
Product: langflow
Published: Feb 26, 2026
Source: NVD
CVE-2026-27941 CRITICAL - 9.9

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in OpenLIT's GitHub repository use the `pull_request_target` event while checking out and executing untrusted code from forked pull requests. These workflows run with the security co...

Vendor: openlit
Product: openlit
Published: Feb 26, 2026
Source: NVD
CVE-2026-27812 CRITICAL - 9.1

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vulnerability in versions prior to 0.1.85 is a Password Reset Poisoning (Host Header / Forwarded Header trust issue), which allows attackers to manipulate the password reset link. Atta...

Vendor: Wei-Shaw
Product: sub2api
Published: Feb 26, 2026
Source: NVD
CVE-2026-27613 CRITICAL - 9.8

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web server's CGI parameter security controls. Depending on the server configuration and the specific CGI executable in use, the impa...

Vendor: maximmasiutin
Product: TinyWeb
Published: Feb 25, 2026
Source: NVD
CVE-2026-27577 CRITICAL - 10.0

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user with permission to create or modify workflows could abuse crafte...

Vendor: n8n-io
Product: n8n
Published: Feb 25, 2026
Source: NVD
CVE-2026-27498 CRITICAL - 8.6

n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify workflows could chain the Read/Write Files from Disk node with git operations to achieve remote code execution. By writing to specific configuration file...

Vendor: n8n-io
Product: n8n
Published: Feb 25, 2026
Source: NVD
CVE-2026-27497 CRITICAL - 10.0

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could leverage the Merge node's SQL query mode to execute arbitrary code and write arbitrary files on the n8n server. The issues...

Vendor: n8n-io
Product: n8n
Published: Feb 25, 2026
Source: NVD
CVE-2026-27495 CRITICAL - 9.9

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could exploit a vulnerability in the JavaScript Task Runner sandbox to execute arbitrary code outside the sandbox boundary. On instan...

Vendor: n8n-io
Product: n8n
Published: Feb 25, 2026
Source: NVD
CVE-2026-27493 CRITICAL - 9.1

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability existed in n8n's Form nodes that could allow an unauthenticated attacker to inject and evaluate arbitrary n8n expressions by submitting crafted fo...

Vendor: n8n-io
Product: n8n
Published: Feb 25, 2026
Source: NVD
CVE-2026-27804 CRITICAL - 9.1

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an unauthenticated attacker can forge a Google authentication token with `alg: "none"` to log in as any user linked to a Google account, withou...

Vendor: npm
Product: parse-server
Published: Feb 25, 2026
Source: GitHub
CVE-2026-27575 CRITICAL - 9.1

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes their password. An attack...

Vendor: go-vikunja
Product: vikunja
Published: Feb 25, 2026
Source: NVD
CVE-2026-25997 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_clipboard_format_equal` reads freed `lastSentFormats` memory because `xf_clipboard_formats_free` (called from the cliprdr channel thread during auto-reconnect) frees the array while the X11 event thread con...

Vendor: FreeRDP
Product: FreeRDP
Published: Feb 25, 2026
Source: NVD
CVE-2026-25959 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprdr_provide_data_` passes freed `pDstData` to `XChangeProperty` because the cliprdr channel thread calls `xf_cliprdr_server_format_data_response` which converts and uses the clipboard data without holdi...

Vendor: FreeRDP
Product: FreeRDP
Published: Feb 25, 2026
Source: NVD