Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,745
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,741 - 2,760 of 3,469 CVEs
CVE-2026-24834 CRITICAL - 9.3

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM ...

Vendor: kata-containers
Product: kata-containers
Published: Feb 19, 2026
Source: NVD
CVE-2025-69674 CRITICAL - 9.8

Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute arbitrary code via the node_mac, node_opt, opt_param, and domainblk parameters of the mesh_node_config and domiainblk_config modules

Published: Feb 19, 2026
Source: NVD
CVE-2025-71243 CRITICAL - 9.8

The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. An attacker can exploit this vulnerability to execute arbitrary code on the server. Users should immediately update to version 5.11.1 or late...

Vendor: SPIP
Product: Saisies pour formulaire
Published: Feb 19, 2026
Source: NVD
CVE-2026-27112 CRITICAL - 9.9

Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the batch resource creation endpoints of both Kargo's legacy gRPC API and newer REST API accept multi-document YAML payloads. Specially crafted payloads can manifest a bug present ...

Vendor: go
Product: github.com/akuity/kargo
Published: Feb 19, 2026
Source: GitHub
CVE-2025-55853 CRITICAL - 9.1

SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to upload an XML or HTML...

Published: Feb 19, 2026
Source: NVD
CVE-2025-9953 CRITICAL - 9.8

Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection.This issue affects Databank Accreditation Software: through 19022026. NOTE: The vendor was contacted early about this disclos...

Published: Feb 19, 2026
Source: NVD
CVE-2025-8350 CRITICAL - 9.8

Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting.This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The vendor was contacted ea...

Published: Feb 19, 2026
Source: NVD
CVE-2025-15559 CRITICAL - 9.8

An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and download the WorkTime client from the WorkTime server is vulnerable in the β€œguid” parameter.Β This allows an attacker to execute arbitrary commands on the ...

Vendor: NesterSoft Inc.
Product: WorkTime (on-prem/cloud)
Published: Feb 19, 2026
Source: NVD
CVE-2025-13590 CRITICAL - 9.1

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by up...

Vendor: WSO2
Product: WSO2 API Manager, WSO2 API Control Plane, WSO2 Universal Gateway, WSO2 Traffic Manager, org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl
Published: Feb 19, 2026
Source: NVD
CVE-2025-12107 CRITICAL - 10.0

Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject and execute arbitrary template syntax within server-side templates. Successful exploitation of this vulnerability could allow a malicious actor with admin privilege to inject and...

Vendor: WSO2
Product: WSO2 Identity Server
Published: Feb 19, 2026
Source: NVD
CVE-2026-23549 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1.

Vendor: magepeopleteam
Product: WpEvently
Published: Feb 19, 2026
Source: NVD
CVE-2026-23542 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10.

Vendor: ThemeGoods
Product: Grand Restaurant
Published: Feb 19, 2026
Source: NVD
CVE-2026-1994 CRITICAL - 9.8

The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers t...

Published: Feb 19, 2026
Source: NVD
CVE-2026-1405 CRITICAL - 9.8

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to upload arbitrary files...

Published: Feb 19, 2026
Source: NVD
CVE-2026-0926 CRITICAL - 9.8

The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.9 via the 'parameters[template_name]' parameter. This makes it possible for unauthenticated attackers to include and read arbitrary files or execute arbitrary files on ...

Published: Feb 19, 2026
Source: NVD
CVE-2025-13851 CRITICAL - 9.8

The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.0.7. This is due to the plugin not validating or restricting the user role during registration via the REST API endpoint. This ma...

Vendor: scriptsbundle
Product: Buyent
Published: Feb 19, 2026
Source: NVD
CVE-2025-13563 CRITICAL - 9.8

The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_lms_pro_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated...

Vendor: BuddhaThemes
Product: Lizza LMS Pro
Published: Feb 19, 2026
Source: NVD
CVE-2025-12882 CRITICAL - 9.8

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set their own role by supplying the 'listing_user_role' parameter. This makes it possible for...

Vendor: SmartDataSoft
Product: Clasifico Listing
Published: Feb 19, 2026
Source: NVD
CVE-2026-2686 CRITICAL - 9.8

A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. The manipulation of the argument User leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed ...

Published: Feb 19, 2026
Source: NVD
CVE-2026-25548 CRITICAL - 9.1

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7.0 through a chained Local File Inclusion (LFI) and Log Poisoning attack. An authenticated administrator can execute arbi...

Vendor: InvoicePlane
Product: InvoicePlane
Published: Feb 18, 2026
Source: NVD