Total CVEs

126,116

Critical Severity

2,290

High Severity

7,924

Last 7 Days

1,178
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 661 - 680 of 897 CVEs

Rejected reason: Further research determined the issue is an external dependency vulnerability.

Vendor: go
Product: github.com/refraction-networking/utls
Published: Feb 18, 2026
Source: GitHub

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH, related to cipher suite selection. When Chrome selects the preferred cip...

Vendor: go
Product: github.com/refraction-networking/utls
Published: Feb 18, 2026
Source: GitHub
CVE-2025-8860 LOW - 3.3

A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocation...

Published: Feb 18, 2026
Source: NVD

A flaw was found in FFmpegโ€™s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free cond...

Published: Feb 18, 2026
Source: NVD
CVE-2026-2662 LOW - 3.3

A weakness has been identified in FascinatedBox lily up to 2.3. This vulnerability affects the function count_transforms of the file src/lily_emitter.c. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could b...

Vendor: lily-lang
Product: lily
Published: Feb 18, 2026
Source: NVD
CVE-2026-2661 LOW - 3.3

A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be use...

Vendor: squirrel-lang
Product: squirrel
Published: Feb 18, 2026
Source: NVD
CVE-2026-2660 LOW - 3.3

A vulnerability was identified in FascinatedBox lily up to 2.3. Affected by this issue is the function shorthash_for_name of the file src/lily_symtab.c. The manipulation leads to use after free. Local access is required to approach this attack. The exploit is publicly available and might be used. Th...

Vendor: lily-lang
Product: lily
Published: Feb 18, 2026
Source: NVD
CVE-2026-2659 LOW - 3.3

A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation of the argument _target_stack can lead to out-of-bounds read. It is possible to launch the attack on...

Vendor: squirrel-lang
Product: squirrel
Published: Feb 18, 2026
Source: NVD

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user who does not hold the "admin" or "power" Splunk roles could bypass the SPL safegua...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Feb 18, 2026
Source: NVD
CVE-2026-2657 LOW - 3.3

A vulnerability has been found in wren-lang wren up to 0.4.0. This impacts the function printError of the file src/vm/wren_compiler.c of the component Error Message Handler. Such manipulation leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed...

Vendor: wren
Product: wren
Published: Feb 18, 2026
Source: NVD
CVE-2026-2656 LOW - 2.5

A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file include/chaiscript/dispatchkit/type_info.hpp. This manipulation causes use after free. The attack requires local access. The attack's complexity is rated as high. The exploit...

Vendor: chaiscript
Product: chaiscript
Published: Feb 18, 2026
Source: NVD
CVE-2026-2655 LOW - 2.5

A vulnerability was detected in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::str_less::operator of the file include/chaiscript/chaiscript_defines.hpp. The manipulation results in use after free. The attack requires a local approach. The attack requires a high level of com...

Vendor: chaiscript
Product: chaiscript
Published: Feb 18, 2026
Source: NVD
CVE-2026-1582 LOW - 3.7

The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.14 via the export download endpoint. This is due to a PHP type juggling vulnerability in the security token comparison which uses loose comparison (==) instead of strict c...

Published: Feb 18, 2026
Source: NVD
CVE-2026-2419 LOW - 2.7

The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal sequences to bypass ...

Published: Feb 18, 2026
Source: NVD
CVE-2026-1831 LOW - 2.7

The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and activation due to missing capability checks on the 'yaymail_install_yaysmtp' AJAX action and `/yaymail/v1/addons/activate` REST endpoint in all versions up to, and includin...

Published: Feb 18, 2026
Source: NVD
CVE-2026-2644 LOW - 3.3

A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the library core/SolverTypes.h of the component DIMACS File Parser. This manipulation of the argument variable index with the input 2147483648 causes out-of-bounds read. The attack needs ...

Vendor: minisat
Product: minisat
Published: Feb 18, 2026
Source: NVD
CVE-2026-2642 LOW - 3.3

A security vulnerability has been detected in ggreer the_silver_searcher up to 2.2.0. The impacted element is the function search_stream of the file src/search.c. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed publ...

Published: Feb 18, 2026
Source: NVD
CVE-2026-2641 LOW - 3.3

A weakness has been identified in universal-ctags ctags up to 6.2.1. The affected element is the function parseExpression/parseExprList of the file parsers/v.c of the component V Language Parser. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack on the ...

Published: Feb 18, 2026
Source: NVD

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

Vendor: zlib
Product: zlib
Published: Feb 18, 2026
Source: NVD

IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.

Vendor: IBM
Product: watsonx.data
Published: Feb 17, 2026
Source: NVD