Total CVEs

126,116

Critical Severity

2,290

High Severity

7,924

Last 7 Days

1,178
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 721 - 740 of 897 CVEs
CVE-2026-2246 LOW - 3.3

A security vulnerability has been detected in AprilRobotics apriltag up to 3.4.5. Affected by this vulnerability is the function apriltag_detector_detect of the file apriltag.c. The manipulation leads to memory corruption. The attack must be carried out locally. The exploit has been disclosed public...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2245 LOW - 3.3

A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is...

Published: Feb 09, 2026
Source: NVD

Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.

Vendor: craftcms
Product: cms
Published: Feb 09, 2026
Source: NVD
CVE-2026-2242 LOW - 3.3

A vulnerability was determined in janet-lang janet up to 1.40.1. This impacts the function janetc_if of the file src/core/specials.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This pa...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2241 LOW - 3.3

A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/os.c. Performing a manipulation results in out-of-bounds read. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is n...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2240 LOW - 3.3

A vulnerability has been found in janet-lang janet up to 1.40.1. The impacted element is the function janetc_pop_funcdef of the file src/core/compile.c. Such manipulation leads to out-of-bounds read. The attack must be carried out locally. The exploit has been disclosed to the public and may be used...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2224 LOW - 3.5

A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The explo...

Vendor: fabian
Product: online_reviewer_system
Published: Feb 09, 2026
Source: NVD
CVE-2026-2222 LOW - 2.4

A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting. The attack may...

Vendor: fabian
Product: online_reviewer_system
Published: Feb 09, 2026
Source: NVD
CVE-2026-2215 LOW - 3.7

A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the file core/auth.py of the component JWT Handler. Performing a manipulation of the argument SECRET_KEY results in use of default cryptographic key. The attack can be initiated remote...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2214 LOW - 2.4

A weakness has been identified in code-projects for Plugin 1.0. This affects an unknown part of the file /Administrator/PHP/AdminAddAlbum.php. This manipulation of the argument txtalbum causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available t...

Vendor: fabian
Product: online_music_site
Published: Feb 09, 2026
Source: NVD
CVE-2026-2201 LOW - 2.4

A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLeave of the file src/main/java/com/wdd/studentmanager/controller/LeaveController.java. The manipulation of the argument Reason for Leave leads to cross s...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2200 LOW - 2.4

A weakness has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/save of the component API Endpoint. Executing a manipulation can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public a...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2156 LOW - 2.4

A weakness has been identified in code-projects Online Student Management System 1.0. The impacted element is an unknown function of the file /admin/announcement/index.php?view=add of the component Announcement Management Module. This manipulation causes cross site scripting. The attack is possible ...

Vendor: fabian
Product: online_student_management_system
Published: Feb 08, 2026
Source: NVD
CVE-2026-2145 LOW - 3.5

A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the file /adminPage/conf/check of the component Web Management Interface. Such manipulation of the argument nginxDir leads to cross site scripting. The attack can be executed remotely. Th...

Published: Feb 08, 2026
Source: NVD

A vulnerability has been found in Mapnik up to 4.2.0. This vulnerability affects the function mapnik::detail::mod<...>::operator of the file src/value.cpp. The manipulation leads to divide by zero. The attack needs to be performed locally. The exploit has been disclosed to the public and may b...

Product: Mapnik
Published: Feb 07, 2026
Source: NVD
CVE-2026-2110 LOW - 3.7

A security flaw has been discovered in Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing a manipulation results in improper restriction of excessive authentication attempts. Remote exploita...

Published: Feb 07, 2026
Source: NVD
CVE-2026-2069 LOW - 3.3

A flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the function llama_grammar_advance_stack of the file llama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This manipulation causes stack-based buffer overflow. The attack needs to be launched locally. The exploi...

Published: Feb 06, 2026
Source: NVD

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an HTML injection vulnerability occurs in the time tracking function of OpenProject. The application does not escape HTML tags, an attacker with administrator privileges can create a work packa...

Vendor: opf
Product: openproject
Published: Feb 06, 2026
Source: NVD
CVE-2026-2064 LOW - 3.5

A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/meusdadod.php of the component User Data Page. Such manipulation of the argument File leads to cross site scripting. It is possible to launch the attack ...

Vendor: portabilis
Product: i-educar
Published: Feb 06, 2026
Source: NVD

Tanium addressed a denial of service vulnerability in Tanium Client.

Vendor: Tanium
Product: Tanium Client
Published: Feb 06, 2026
Source: NVD