Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 601 - 620 of 897 CVEs

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, the `move_posts` action only checked `can_move_posts?` on the source topic but never validated write permissions on the destination topic. This allowed TL4 users and category group moderators to mov...

Vendor: discourse
Product: discourse
Published: Feb 26, 2026
Source: NVD

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, missing `validate_before_create` authorization in Data Explorer's `QueryGroupBookmarkable` allows any logged-in user to create bookmarks for query groups they don't have access to, enablin...

Vendor: discourse
Product: discourse
Published: Feb 26, 2026
Source: NVD

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, TL4 users are able to close, archive and pin topics in private categories they don't have access to. Versions 2025.12.2, 2026.1.1, and 2026.2.0 patch the issue. No known workarounds are availab...

Vendor: discourse
Product: discourse
Published: Feb 26, 2026
Source: NVD

VideoLAN VLC for Android prior to version 3.7.0 contains an authentication bypass in the Remote Access Server feature due to missing or insufficient rate limiting on one-time password (OTP) verification. The Remote Access Server uses a 4-digit OTP and does not enforce effective throttling or lockout...

Vendor: VideoLAN
Product: VLC for Android
Published: Feb 26, 2026
Source: NVD

Golioth Firmware SDK version 0.19.1 prior to 0.22.0, fixed in commit 0e788217, contain an out-of-bounds read due to improper null termination of a blockwise transfer path. blockwise_transfer_init() accepts a path whose length equals CONFIG_GOLIOTH_COAP_MAX_PATH_LEN and copies it using strncpy() with...

Vendor: Golioth
Product: Firmware SDK
Published: Feb 26, 2026
Source: NVD

Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit d7f55b38, contain an out-of-bounds read in LightDB State string parsing. When processing a string payload, a payload_size value less than 2 can cause a size_t underflow when computing the number of bytes to copy (nbytes). The subse...

Vendor: Golioth
Product: Firmware SDK
Published: Feb 26, 2026
Source: NVD

Golioth Firmware SDK version 0.10.0 prior to 0.22.0, fixed in commit 48f521b, contain a stack-based buffer overflow in Payload Utils. The golioth_payload_as_int() and golioth_payload_as_float() helpers copy network-supplied payload data into fixed-size stack buffers using memcpy() with a length deri...

Vendor: Golioth
Product: Firmware SDK
Published: Feb 26, 2026
Source: NVD

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. Prior to version 5.3.8, the application crashes with stack overflow when user use XML builder with `preserveOrder:true`. Version 5.3.8 fixes the issue. As ...

Vendor: NaturalIntelligence
Product: fast-xml-parser
Published: Feb 26, 2026
Source: NVD

ZITADEL is an open source identity management platform. Zitadel Action V2 (introduced as early preview in 2.59.0, beta in 3.0.0 and GA in 4.0.0) is a webhook based approach to allow developers act on API request to Zitadel and customize flows such the issue of a token. Zitadel's Action target U...

Vendor: zitadel
Product: zitadel
Published: Feb 26, 2026
Source: NVD
CVE-2026-3193 LOW - 3.1

A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. The manipulation results in cross-site request forgery. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered diff...

Published: Feb 25, 2026
Source: NVD
CVE-2026-3189 LOW - 3.1

A weakness has been identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This vulnerability affects unknown code of the file /api/admin/common/files/download. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be executed remotely. Attacks of ...

Published: Feb 25, 2026
Source: NVD

Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `RSASHA256Algorithm` and `RSASHA1Algorithm` contracts fail to validate PKCS#1 v1.5 padding structure when verifying RSA signatures. The contracts only c...

Vendor: ensdomains
Product: ens-contracts
Published: Feb 25, 2026
Source: NVD

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

Vendor: JetBrains
Product: TeamCity
Published: Feb 25, 2026
Source: NVD

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletio...

Vendor: Grafana
Product: Grafana
Published: Feb 25, 2026
Source: NVD
CVE-2026-3171 LOW - 3.5

A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /queue.php. This manipulation of the argument firstname/lastname causes cross site scripting. The attack is possible to be c...

Vendor: pamzey
Product: patients_waiting_area_queue_management_system
Published: Feb 25, 2026
Source: NVD
CVE-2026-3170 LOW - 2.4

A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected is an unknown function of the file /patient-search.php. The manipulation of the argument First Name/Last Name results in cross site scripting. The attack can be executed remotely....

Vendor: pamzey
Product: patients_waiting_area_queue_management_system
Published: Feb 25, 2026
Source: NVD
CVE-2026-3146 LOW - 3.3

A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The identifier of the patch is d4ce337c...

Vendor: libvips
Product: libvips
Published: Feb 25, 2026
Source: NVD

Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48, the Talishar application lacks Cross-Site Request Forgery (CSRF) protections on critical state-changing endpoints, specifically within `SubmitChat.php` and other game interaction handlers. By fa...

Vendor: Talishar
Product: Talishar
Published: Feb 25, 2026
Source: NVD

Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability to Protection mechanism bypass.

Vendor: Dell
Product: Wyse Management Suite
Published: Feb 24, 2026
Source: NVD
CVE-2026-1229 LOW - 9.8

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://github.com/cloudflar...

Vendor: go
Product: github.com/cloudflare/circl
Published: Feb 24, 2026
Source: NVD