Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,641
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,561 - 2,580 of 3,451 CVEs
CVE-2026-25955 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` whose `data` pointer references a freed RDPGFX surface buffer, because `gdi_DeleteSurface` frees `surface->data` without invalidating the `appWindow-&...

Vendor: FreeRDP
Product: FreeRDP
Published: Feb 25, 2026
Source: NVD
CVE-2026-25953 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWindow` because the RDPGFX DVC thread obtains a bare pointer via `xf_rail_get_window` without any lifetime protection, while the main thread can concurre...

Vendor: FreeRDP
Product: FreeRDP
Published: Feb 25, 2026
Source: NVD
CVE-2026-25952 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer from the `railWindows` hash table, and the main t...

Vendor: FreeRDP
Product: FreeRDP
Published: Feb 25, 2026
Source: NVD
CVE-2026-24908 CRITICAL - 9.9

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Patient REST API endpoint allows authenticated users with API access to execute arbitrary SQL queries through the `_sort` parameter. ...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD

The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-Side Request Forgery (SSRF) vulnerability in the Angular SSR request handling pipeline. The vulnerability exists because Angular’s internal URL reconstr...

Vendor: angular
Product: angular-cli, @nguniversal/common, @nguniversal/express-engine
Published: Feb 25, 2026
Source: NVD
CVE-2026-21902 CRITICAL - 9.8

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reacha...

Vendor: Juniper Networks
Product: Junos OS Evolved
Published: Feb 25, 2026
Source: NVD
CVE-2026-27849 CRITICAL - 9.8

Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normally used for configuring devices inside the mesh network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

Vendor: Linksys
Product: MR9600, MX4200
Published: Feb 25, 2026
Source: NVD
CVE-2026-27728 CRITICAL - 9.9

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating system commands on the Probe server by injecting shell ...

Vendor: OneUptime
Product: oneuptime
Published: Feb 25, 2026
Source: NVD
CVE-2026-20129 CRITICAL - 9.8

A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that are sent to the ...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: Feb 25, 2026
Source: NVD
CVE-2026-20127 CRITICAL - 10.0

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. ...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: Feb 25, 2026
Source: NVD
CVE-2026-27848 CRITICAL - 9.8

Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as the root user. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

Vendor: Linksys
Product: MR9600, MX4200
Published: Feb 25, 2026
Source: NVD
CVE-2026-27847 CRITICAL - 9.8

Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inject known credentials into the database that can be utilized to successfully complete the handshake and use the protected service. This issue affects M...

Vendor: Linksys
Product: MR9600, MX4200
Published: Feb 25, 2026
Source: NVD
CVE-2026-27702 CRITICAL - 9.9

Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability in Budibase's view filtering implementation allows any authenticated user (including free tier accounts) to execute arbitrary JavaScript code on th...

Vendor: Budibase
Product: budibase
Published: Feb 25, 2026
Source: NVD
CVE-2025-69771 CRITICAL - 9.6

An arbitrary file upload vulnerability in the subtitle loading function of asbplayer v1.13.0 allows attackers to execute arbitrary code via uploading a crafted subtitle file.

Vendor: killergerbah
Product: asbplayer
Published: Feb 25, 2026
Source: NVD
CVE-2025-1242 CRITICAL - 9.1

The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attacker gaining full administrative access to the Gardyn IoT Hub exposing connected devices to malicious...

Published: Feb 25, 2026
Source: NVD
CVE-2026-27699 CRITICAL - 9.1

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause files to be written out...

Vendor: patrickjuchli
Product: basic-ftp
Published: Feb 25, 2026
Source: NVD
CVE-2026-2624 CRITICAL - 9.8

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass.This issue affects Antikor Next Generation Firewall (NGFW): from v.2.0.1298 before v.2.0.1301.

Vendor: epati
Product: antikor_next_generation_firewall
Published: Feb 25, 2026
Source: NVD
CVE-2026-0704 CRITICAL - 9.1

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

Vendor: octopus
Product: octopus_server
Published: Feb 25, 2026
Source: NVD
CVE-2026-25785 CRITICAL - 9.8

Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbitrary code on the affected system.

Vendor: MOTEX Inc.
Product: Lanscope Endpoint Manager (On-Premises) Sub-Manager Server
Published: Feb 25, 2026
Source: NVD
CVE-2026-27744 CRITICAL - 9.8

The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for public ticket pages. The plugin appends untrusted request parameters into HTML that is later rendered by a template using unfiltered environment rendering ...

Vendor: SPIP
Product: tickets
Published: Feb 25, 2026
Source: NVD