Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,725
Quick preset (or use dates below)
Clear Filters
Showing 2,681 - 2,700 of 3,597 CVEs
CVE-2026-23552 CRITICAL - 9.1

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.ย  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy config...

Vendor: Apache Software Foundation
Product: Apache Camel
Published: Feb 23, 2026
Source: NVD
CVE-2026-24494 CRITICAL - 9.8

SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request.

Vendor: Order Up
Product: Online Ordering System
Published: Feb 23, 2026
Source: NVD
CVE-2026-2588 CRITICAL - 9.1

Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems. Sodium.xs casts a STRLEN (size_t) to unsigned long long when passing a length pointer to libsodium functions. On 32-bit systems size_t is typically 32-bits while an unsigned long long is at least 64...

Published: Feb 23, 2026
Source: NVD
CVE-2026-27574 CRITICAL - 9.9

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allowing trivial sandbox escape via a well-known ...

Vendor: OneUptime
Product: oneuptime
Published: Feb 21, 2026
Source: NVD
CVE-2026-27471 CRITICAL - 9.1

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lacked access validation which allowed for unauthorized document access. This issue has been fixed in versions 15.98.1 and 16.6.1.

Vendor: frappe
Product: erpnext
Published: Feb 21, 2026
Source: NVD
CVE-2026-27211 CRITICAL - 10.0

Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (constrained by process privileges) when using virtio-block devices backed by raw images. A malicious guest can overwrite its disk header with a crafted QCO...

Vendor: cloud-hypervisor
Product: cloud-hypervisor
Published: Feb 21, 2026
Source: NVD
CVE-2026-27197 CRITICAL - 9.1

Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the...

Vendor: getsentry
Product: sentry
Published: Feb 21, 2026
Source: NVD
CVE-2026-2635 CRITICAL - 9.8

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the basic_auth.ini file. The fil...

Published: Feb 20, 2026
Source: NVD
CVE-2019-25441 CRITICAL - 9.8

thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the run_command endpoint. Attackers can send POST requests with shell commands in the command parameter to execute arbitrary code on th...

Vendor: kostasmitroglou
Product: thesystem
Published: Feb 20, 2026
Source: NVD
CVE-2021-35402 CRITICAL - 10.0

PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status).

Vendor: PROLiNK
Product: PRC2402M
Published: Feb 20, 2026
Source: NVD
CVE-2026-25896 CRITICAL - 9.3

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow buil...

Vendor: npm
Product: fast-xml-parser
Published: Feb 20, 2026
Source: GitHub
CVE-2026-2848 CRITICAL - 9.8

A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the argument Username causes sql injection. The attack may be initi...

Vendor: oretnom23
Product: simple_responsive_tourism_website
Published: Feb 20, 2026
Source: NVD
CVE-2026-2333 CRITICAL - 9.8

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted network request.

Vendor: owlcyberdefense
Product: opds-talon
Published: Feb 20, 2026
Source: NVD
CVE-2026-26747 CRITICAL - 9.1

A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default misconfiguration where the "app.force_url" is not set and default is "false". The application generates...

Vendor: monicahq
Product: monica
Published: Feb 20, 2026
Source: NVD
CVE-2026-26725 CRITICAL - 9.8

An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 allows a remote attacker to escalate privileges via the AccessID parameter.

Vendor: edubusinesssolutions
Product: print_shop_pro_webdesk
Published: Feb 20, 2026
Source: NVD
CVE-2026-26722 CRITICAL - 9.4

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of the login functionality.

Vendor: keystorage
Product: global_facilities_management_software
Published: Feb 20, 2026
Source: NVD
CVE-2026-26093 CRITICAL - 9.8

Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted network request.

Vendor: Owl
Product: opds
Published: Feb 20, 2026
Source: NVD
CVE-2026-25715 CRITICAL - 9.8

The web management interface of the device allows the administrator username and password to be set to blank values. Once applied, the device permits authentication with empty credentials over the web management interface and Telnet service. This effectively disables authentication across all cr...

Vendor: Jinan USR IOT Technology Limited (PUSR)
Product: USR-W610
Published: Feb 20, 2026
Source: NVD
CVE-2025-70833 CRITICAL - 9.4

An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administrator) and fully takeover the account by manipulating POST parameters. The issue stems from insecure permission validation in check-power.php.

Vendor: lkw199711
Product: smanga
Published: Feb 20, 2026
Source: NVD
CVE-2026-24956 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download Manager Addons for Elementor wpdm-elementor allows Blind SQL Injection.This issue affects Download Manager Addons for Elementor: from n/a through <= 1.3.0.

Vendor: Shahjada
Product: Download Manager Addons for Elementor
Published: Feb 20, 2026
Source: NVD