Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,751
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,661 - 2,680 of 3,469 CVEs
CVE-2026-2759 CRITICAL - 9.8

Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2758 CRITICAL - 9.8

Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2757 CRITICAL - 9.8

Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2634 CRITICAL - 9.8

Malicious scripts could cause desynchronization between the address bar and web content before a response is received in Firefox iOS, allowing attacker-controlled pages to be presented under spoofed domains. This vulnerability affects Firefox for iOS < 147.4.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2025-14577 CRITICAL - 9.8

Slican NCP/IPL/IPM/IPU devices are vulnerable to PHP Function Injection. An unauthenticated remote attacker is able to execute arbitrary PHP commands by sending specially crafted requests to /webcti/session_ajax.php endpoint. This issue was fixed in version 1.24.0190 (Slican NCP) and 6.61.0010 (Sl...

Vendor: Slican
Product: NCP, IPL, IPM, IPU
Published: Feb 24, 2026
Source: NVD
CVE-2025-11165 CRITICAL - 9.9

A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to bypass class and package restrictions enforced by SecureUberspectorImpl. By dynamically modifying the Velocity engine’s runtime configuration and reiniti...

Vendor: dotCMS
Product: dotCMS
Published: Feb 24, 2026
Source: NVD
CVE-2025-40541 CRITICAL - 9.1

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because...

Vendor: SolarWinds
Product: Serv-U
Published: Feb 24, 2026
Source: NVD
CVE-2025-40540 CRITICAL - 9.1

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequentl...

Vendor: SolarWinds
Product: Serv-U
Published: Feb 24, 2026
Source: NVD
CVE-2025-40539 CRITICAL - 9.1

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequentl...

Vendor: SolarWinds
Product: Serv-U
Published: Feb 24, 2026
Source: NVD
CVE-2025-40538 CRITICAL - 9.1

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative privileges to abuse. On Wi...

Vendor: SolarWinds
Product: Serv-U
Published: Feb 24, 2026
Source: NVD
CVE-2025-13942 CRITICAL - 9.8

A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remote attacker to execute operating system (OS) commands on an affected device by sending specially crafted UPnP SOAP requests.

Vendor: Zyxel
Product: EX3510-B0 firmware
Published: Feb 24, 2026
Source: NVD
CVE-2024-58041 CRITICAL - 9.1

Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Smolder::DB::Developer use...

Vendor: WONKO
Product: Smolder
Published: Feb 24, 2026
Source: NVD
CVE-2026-3062 CRITICAL - 9.8

Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Feb 23, 2026
Source: NVD
CVE-2026-3061 CRITICAL - 9.1

Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Feb 23, 2026
Source: NVD
CVE-2026-26198 CRITICAL - 9.8

Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-supplied column names directly into `sqlalchemy.text()` without any validation or sanitization. The `min()` and `max()` methods in the `Quer...

Vendor: pip
Product: ormar
Published: Feb 23, 2026
Source: GitHub
CVE-2026-23693 CRITICAL - 10.0

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API cred...

Vendor: Roxnor
Product: ElementsKit Lite
Published: Feb 23, 2026
Source: NVD
CVE-2025-71056 CRITICAL - 9.1

Improper session management in GCOM EPON 1GE ONU version C00R371V00B01 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.

Published: Feb 23, 2026
Source: NVD
CVE-2025-70327 CRITICAL - 9.8

TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through CsteSystem without validating if the input starts with a hyphen ...

Vendor: totolink
Product: x5000r_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2025-70043 CRITICAL - 9.1

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in TLS socket options

Published: Feb 23, 2026
Source: NVD
CVE-2026-23552 CRITICAL - 9.1

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy config...

Vendor: Apache Software Foundation
Product: Apache Camel
Published: Feb 23, 2026
Source: NVD