Total CVEs

126,116

Critical Severity

2,290

High Severity

7,924

Last 7 Days

1,178
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 701 - 720 of 897 CVEs

An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access to an iOS device may be able to access photos from the lock screen.

Vendor: Apple
Product: iOS and iPadOS
Published: Feb 11, 2026
Source: NVD

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to monitor keystrokes without user permission.

Vendor: Apple
Product: macOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-2345 LOW - 3.6

Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based ...

Published: Feb 11, 2026
Source: NVD
CVE-2026-1282 LOW - 3.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.

Vendor: gitlab
Product: gitlab
Published: Feb 11, 2026
Source: NVD

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

Vendor: GitLab
Product: GitLab
Published: Feb 11, 2026
Source: NVD

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API en...

Vendor: GitLab
Product: GitLab
Published: Feb 11, 2026
Source: NVD

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side R...

Vendor: langchain-ai
Product: langchain
Published: Feb 10, 2026
Source: NVD
CVE-2026-1762 LOW - 2.9

A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.

Published: Feb 10, 2026
Source: NVD

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

Vendor: microsoft
Product: windows_10_1607
Published: Feb 10, 2026
Source: NVD

Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data corruption. This result may potentially occ...

Product: Intel(R) NPU Drivers
Published: Feb 10, 2026
Source: NVD

Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result...

Product: Intel(R) Graphics Drivers and Intel LTS kernels
Published: Feb 10, 2026
Source: NVD

Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local acce...

Published: Feb 10, 2026
Source: NVD

Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a l...

Product: Intel(R) Ethernet 800-Series
Published: Feb 10, 2026
Source: NVD

A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Unfortunately, the project has no active maintainer at t...

Vendor: wasm3_project
Product: wasm3
Published: Feb 10, 2026
Source: NVD

A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly ...

Vendor: ckolivas
Product: lrzip
Published: Feb 10, 2026
Source: NVD

Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue. Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough, t...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: Feb 10, 2026
Source: NVD
CVE-2026-2259 LOW - 3.3

A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsing. The manipulation leads to memory corruption. The attack can only be performed from a local envir...

Vendor: strlen
Product: lobster
Published: Feb 10, 2026
Source: NVD

Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory cor...

Vendor: SAP_SE
Product: SAP NetWeaver and ABAP Platform (Application Server ABAP)
Published: Feb 10, 2026
Source: NVD

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configur...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server Java
Published: Feb 10, 2026
Source: NVD
CVE-2026-2258 LOW - 3.3

A flaw has been found in aardappel lobster up to 2025.4. Affected by this vulnerability is the function WaveFunctionCollapse in the library dev/src/lobster/wfc.h. Executing a manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been published and may b...

Vendor: strlen
Product: lobster
Published: Feb 10, 2026
Source: NVD