Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,641
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,581 - 2,600 of 3,451 CVEs
CVE-2026-27743 CRITICAL - 9.8

The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_spam_supprimer action handlers. The handlers read the url parameter from a GET request and interpolate it directly into SQL LIKE clauses without input v...

Vendor: SPIP
Product: referer_spam
Published: Feb 25, 2026
Source: NVD
CVE-2026-27641 CRITICAL - 9.8

Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI). Flask-Reuploaded has been patched...

Vendor: jugmac00
Product: flask-reuploaded
Published: Feb 25, 2026
Source: NVD
CVE-2026-27637 CRITICAL - 9.8

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication token computed as `MD5(user_id + created_at + APP_KEY)`. This token is static (never expires/rotates), and if an...

Vendor: freescout-help-desk
Product: freescout
Published: Feb 25, 2026
Source: NVD
CVE-2026-27597 CRITICAL - 10.0

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version 2.11.1.

Vendor: agentfront
Product: enclave
Published: Feb 25, 2026
Source: NVD
CVE-2026-27822 CRITICAL - 9.0

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows an attacker to execute arbitrary JavaScript in the context of the management console. By bypassing the PDF preview logic, an at...

Vendor: rustfs
Product: rustfs
Published: Feb 25, 2026
Source: NVD
CVE-2026-27626 CRITICAL - 9.9

OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) blocks several dangerous argument types but not `password`. A user supplying a `password`-typed argument can inject...

Vendor: OliveTin
Product: OliveTin
Published: Feb 25, 2026
Source: NVD
CVE-2026-27614 CRITICAL - 9.3

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the affected Stacktrace in the web UI. When Pygments retu...

Vendor: bugsink
Product: bugsink
Published: Feb 25, 2026
Source: NVD
CVE-2026-27608 CRITICAL - 8.1

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) does not enforce authorization. Authenticated users scoped to specific apps can access any other app's agent endpoint...

Vendor: parse-community
Product: parse-dashboard
Published: Feb 25, 2026
Source: NVD
CVE-2026-27606 CRITICAL - 9.8

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to...

Vendor: rollup
Product: rollup
Published: Feb 25, 2026
Source: NVD
CVE-2026-27595 CRITICAL - 7.5

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (POST `/apps/:appId/agent`) has multiple security vulnerabilities that, when chained, allow unauthenticated remote attackers to perform arbitrary read...

Vendor: parse-community
Product: parse-dashboard
Published: Feb 25, 2026
Source: NVD
CVE-2026-24849 CRITICAL - 9.9

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. Any authenticated user (regardless o...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD
CVE-2026-27593 CRITICAL - 9.3

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email address of a val...

Vendor: statamic
Product: cms
Published: Feb 24, 2026
Source: NVD
CVE-2026-22553 CRITICAL - 9.8

All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

Vendor: InSAT
Product: MasterSCADA BUK-TS
Published: Feb 24, 2026
Source: NVD
CVE-2026-21410 CRITICAL - 9.8

InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

Vendor: InSAT
Product: MasterSCADA BUK-TS
Published: Feb 24, 2026
Source: NVD
CVE-2026-26342 CRITICAL - 9.8

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared system) can continue to aut...

Vendor: Tattile s.r.l.
Product: Smart+, Tolling+, Smart+ Speed, Smart+ Traffic Light, Axle Counter, Vega53, Vega33, Vega11, Basic MK2, ANPR Mobile
Published: Feb 24, 2026
Source: NVD
CVE-2026-26341 CRITICAL - 9.8

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain adminis...

Vendor: Tattile s.r.l.
Product: Smart+, Tolling+, Smart+ Speed, Smart+ Traffic Light, Axle Counter, Vega53, Vega33, Vega11, Basic MK2, ANPR Mobile
Published: Feb 24, 2026
Source: NVD
CVE-2026-26222 CRITICAL - 9.8

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe object unmar...

Vendor: Beyond Limits Inc.
Product: Altec DocLink
Published: Feb 24, 2026
Source: NVD
CVE-2026-27515 CRITICAL - 9.1

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web management interface. An attacker can guess valid session IDs and hijack authenticated sessions.

Vendor: Binardat Ltd.
Product: 10G08-0800GSM Network Switch
Published: Feb 24, 2026
Source: NVD
CVE-2026-27507 CRITICAL - 9.8

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed by users. Knowledge of these credentials allows full administrative access to the device.

Vendor: Binardat Ltd.
Product: 10G08-0800GSM Network Switch
Published: Feb 24, 2026
Source: NVD
CVE-2025-69985 CRITICAL - 9.8

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attack...

Vendor: npm
Product: @frangoteam/fuxa
Published: Feb 24, 2026
Source: NVD