Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 581 - 600 of 897 CVEs
CVE-2026-3386 LOW - 3.3

A flaw has been found in wren-lang wren up to 0.4.0. Affected by this vulnerability is the function emitOp of the file src/vm/wren_compiler.c. This manipulation causes out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been published and may be used. The proje...

Vendor: wren
Product: wren
Published: Mar 01, 2026
Source: NVD
CVE-2026-3385 LOW - 3.3

A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recursion. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the pro...

Published: Mar 01, 2026
Source: NVD
CVE-2026-3384 LOW - 3.3

A security vulnerability has been detected in ChaiScript up to 6.1.0. This impacts the function chaiscript::eval::AST_Node_Impl::eval/chaiscript::eval::Function_Push_Pop of the file include/chaiscript/language/chaiscript_eval.hpp. The manipulation leads to uncontrolled recursion. An attack has to be...

Vendor: chaiscript
Product: chaiscript
Published: Mar 01, 2026
Source: NVD
CVE-2026-3383 LOW - 3.3

A weakness has been identified in ChaiScript up to 6.1.0. This affects the function chaiscript::Boxed_Number::go of the file include/chaiscript/dispatchkit/boxed_number.hpp. Executing a manipulation can lead to divide by zero. The attack requires local access. The exploit has been made available to ...

Vendor: chaiscript
Product: chaiscript
Published: Mar 01, 2026
Source: NVD
CVE-2026-3382 LOW - 3.3

A security flaw has been discovered in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::Boxed_Number::get_as of the file include/chaiscript/dispatchkit/boxed_number.hpp. Performing a manipulation results in memory corruption. The attack requires a local approach. The exploit ...

Vendor: chaiscript
Product: chaiscript
Published: Mar 01, 2026
Source: NVD

Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a very wide terminal. Version 9.2.0078 patches the issue.

Vendor: vim
Product: vim
Published: Feb 27, 2026
Source: NVD

Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.

Vendor: VMware
Product: Workstation
Published: Feb 27, 2026
Source: NVD

Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administrative privileges on a guest VM to obtain limited information disclosure from the machine where VMware Workstation is installed.

Vendor: VMware
Product: Workstation
Published: Feb 27, 2026
Source: NVD

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api modules), erlang rebar3 (r3_hex_api modules) allows Object Injection, Excessive Allocation. This vulnerability is associated with program files src/hex_api.e...

Vendor: hexpm, erlang
Product: hex_core, hex, rebar3
Published: Feb 27, 2026
Source: NVD

A flaw was found in Keycloakโ€™s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to r...

Vendor: Keycloak, Red Hat
Product: keycloak, Red Hat build of Keycloak 26.2, Red Hat build of Keycloak 26.2.11, Red Hat build of Keycloak 26.4, Red Hat build of Keycloak 26.4.4
Published: Feb 27, 2026
Source: NVD
CVE-2026-3293 LOW - 3.3

A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handler. Executing a manipulation of the argument nonProxyHosts can...

Vendor: maven
Product: net.snowflake:snowflake-jdbc
Published: Feb 27, 2026
Source: NVD
CVE-2026-3285 LOW - 3.3

A vulnerability was determined in berry-lang berry up to 1.1.0. The affected element is the function scan_string of the file src/be_lexer.c. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: 7149c59...

Vendor: berry-lang
Product: berry
Published: Feb 27, 2026
Source: NVD
CVE-2026-3284 LOW - 3.3

A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used....

Vendor: libvips
Product: libvips
Published: Feb 27, 2026
Source: NVD
CVE-2026-3283 LOW - 3.3

A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_band leads to out-of-bounds read. The attack needs to be performed locally. The exploit has been disclosed to t...

Vendor: libvips
Product: libvips
Published: Feb 27, 2026
Source: NVD
CVE-2026-3282 LOW - 3.3

A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alpha_band can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been ...

Vendor: libvips
Product: libvips
Published: Feb 27, 2026
Source: NVD

An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the system, and potentially causing a denial-of-service attack.

Vendor: Copeland
Product: Copeland XWEB 300D PRO, Copeland XWEB 500D PRO, Copeland XWEB 500B PRO
Published: Feb 27, 2026
Source: NVD

wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, ache keys are scoped only by `pk` โ€” no user ID is included. When a victim has previously accessed their routine via the...

Vendor: wger-project
Product: wger
Published: Feb 26, 2026
Source: NVD

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users can publish topics into staff-only categories via the `publish_to_category` topic timer, bypassing authorization checks. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No know...

Vendor: discourse
Product: discourse
Published: Feb 26, 2026
Source: NVD

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, moderators could export user Chat DMs via the CSV export endpoint by exploiting an overly permissive allowlist in `can_export_entity?`. The method allowed moderators to export any entity not explici...

Vendor: discourse
Product: discourse
Published: Feb 26, 2026
Source: NVD

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, DM communication-preference bypass when adding members via `Chat::AddUsersToChannel` โ€” a user could add targets who have blocked/ignored/muted them to an existing DM channel, bypassing per-recipient...

Vendor: discourse
Product: discourse
Published: Feb 26, 2026
Source: NVD