Total CVEs

126,116

Critical Severity

2,290

High Severity

7,924

Last 7 Days

1,177
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 801 - 820 of 897 CVEs
CVE-2026-1485 LOW - 2.8

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exp...

Published: Jan 27, 2026
Source: NVD
CVE-2026-1444 LOW - 2.4

A vulnerability has been found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This affects an unknown part of the file controllers/books_center/add_book_check.php. Such manipulation of the argument mark leads to cross site scripting. The attack can be launched remotely. ...

Published: Jan 26, 2026
Source: NVD
CVE-2026-1190 LOW - 3.1

A flaw was found in Keycloak's SAML brokering functionality. When Keycloak is configured as a client in a Security Assertion Markup Language (SAML) setup, it fails to validate the `NotOnOrAfter` timestamp within the `SubjectConfirmationData`. This allows an attacker to delay the expiration of S...

Vendor: maven
Product: org.keycloak:keycloak-services
Published: Jan 26, 2026
Source: NVD
CVE-2025-9615 LOW - 3.3

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added...

Published: Jan 26, 2026
Source: NVD
CVE-2026-0925 LOW - 2.7

Tanium addressed an improper input validation vulnerability in Discover.

Published: Jan 26, 2026
Source: NVD

Deserialization of Untrusted Data vulnerability in Apache Karaf Decanter. The Decanter log socket collector exposes the port 4560, without authentication. If the collector exposes allowed classes property, this configuration can be bypassed. It means that the log socket collector is vulnerable to ...

Vendor: Apache Software Foundation
Product: Apache Karaf
Published: Jan 26, 2026
Source: NVD
CVE-2026-1421 LOW - 3.5

A vulnerability has been found in code-projects Online Examination System 1.0. Affected is an unknown function of the component Add Pages. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

Vendor: fabian
Product: online_examination_system
Published: Jan 26, 2026
Source: NVD
CVE-2026-1417 LOW - 3.3

A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could...

Vendor: gpac
Product: gpac
Published: Jan 26, 2026
Source: NVD
CVE-2026-1416 LOW - 3.3

A security flaw has been discovered in GPAC up to 2.4.0. Affected by this vulnerability is the function DumpMovieInfo of the file applications/mp4box/filedump.c. The manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to...

Vendor: gpac
Product: gpac
Published: Jan 26, 2026
Source: NVD
CVE-2026-1415 LOW - 3.3

A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file src/media_tools/media_export.c. The manipulation of the argument Name leads to null pointer dereference. The attack must be carried out locally. The exploit is publicly available ...

Vendor: gpac
Product: gpac
Published: Jan 26, 2026
Source: NVD
CVE-2026-1409 LOW - 2.0

A security vulnerability has been detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. This issue affects some unknown processing of the component UART Interface. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack on the physical...

Vendor: beetel
Product: 777vr1_firmware
Published: Jan 26, 2026
Source: NVD
CVE-2026-1408 LOW - 2.0

A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of the component UART Interface. Executing a manipulation can lead to weak password requirements. The physical device can be targeted for the attack. The attack requires a high level o...

Vendor: beetel
Product: 777vr1_firmware
Published: Jan 25, 2026
Source: NVD
CVE-2026-1407 LOW - 2.0

A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01.00.09_55. This affects an unknown part of the component UART Interface. Performing a manipulation results in information disclosure. The attack may be carried out on the physical device. The attack is considered to have high comp...

Vendor: beetel
Product: 777vr1_firmware
Published: Jan 25, 2026
Source: NVD
CVE-2026-1406 LOW - 3.5

A vulnerability was determined in lcg0124 BootDo up to 5ccd963c74058036b466e038cff37de4056c1600. Affected by this vulnerability is the function redirectToLogin of the file AccessControlFilter.java of the component Host Header Handler. This manipulation of the argument Hostname causes open redirect. ...

Published: Jan 25, 2026
Source: NVD
CVE-2026-0633 LOW - 3.7

The MetForm โ€“ Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.0. This is due to the use of a forgeable cookie value derived only from the entry ID and current user ID withou...

Published: Jan 24, 2026
Source: NVD

MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the settings management functionality due to insufficient input validation. The application's saveSettings() function accepts arbitrary key-value pairs wit...

Vendor: franklioxygen
Product: MyTube
Published: Jan 24, 2026
Source: NVD

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

Vendor: libexpat project
Product: libexpat
Published: Jan 23, 2026
Source: NVD
CVE-2026-0798 LOW - 3.5

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from public to private, users who previously watched the repository may continue to receive release notifications, potentially disclosing release titles, tags, and...

Vendor: go
Product: code.gitea.io/gitea
Published: Jan 23, 2026
Source: GitHub

Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.

Vendor: go
Product: github.com/go-gitea/gitea
Published: Jan 23, 2026
Source: GitHub

Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications.

Vendor: go
Product: github.com/go-gitea/gitea
Published: Jan 23, 2026
Source: GitHub