Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,653
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,261 - 10,280 of 13,241 CVEs
CVE-2019-25491 HIGH - 8.2

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the catid parameter. Attackers can send GET requests to the admin/cms_getpagetitle.php endpoint with malicious catid values to extract sensitive dat...

Vendor: Doditsolutions
Product: Homey BNB (Airbnb Clone Script)
Published: Feb 27, 2026
Source: NVD
CVE-2019-25490 HIGH - 8.2

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' parameter. Attackers can send GET requests to the admin/edit.php endpoint with time-based SQL injection payloads to extract sensit...

Vendor: Doditsolutions
Product: Homey BNB (Airbnb Clone Script)
Published: Feb 27, 2026
Source: NVD
CVE-2019-25489 HIGH - 8.2

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the hosting_id parameter. Attackers can send GET requests to the rooms/ajax_refresh_subtotal endpoint with malicious hosting_id values to extract sen...

Vendor: Doditsolutions
Product: Homey BNB (Airbnb Clone Script)
Published: Feb 27, 2026
Source: NVD

A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13.

Vendor: npm
Product: @nestjs/platform-fastify
Published: Feb 27, 2026
Source: NVD
CVE-2026-25147 HIGH - 7.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_payment.php`, the patient id used for the page is taken from the request (`$pid = $_REQUEST['pid'] ?? $pid` and `$pid = ($_REQUEST['hidden...

Vendor: openemr
Product: openemr
Published: Feb 27, 2026
Source: NVD
CVE-2025-69437 HIGH - 8.7

PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded JavaScript payload can be...

Vendor: publiccms
Product: publiccms
Published: Feb 27, 2026
Source: NVD

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch...

Vendor: npm
Product: multer
Published: Feb 27, 2026
Source: NVD

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to rec...

Vendor: npm
Product: multer
Published: Feb 27, 2026
Source: NVD
CVE-2026-2751 HIGH - 8.3

Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8, 24.10.20, 24.04.24.

Published: Feb 27, 2026
Source: NVD
CVE-2025-10990 HIGH - 7.5

A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Service (ReDoS), impacting the availability of the affected com...

Vendor: Red Hat
Product: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9, Red Hat Satellite 6.17 for RHEL 9, Satellite Client 6 for RHEL 8, Satellite Client 6 for RHEL 9
Published: Feb 27, 2026
Source: NVD
CVE-2026-2252 HIGH - 7.5

An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.ย  Please consider upgrading to FreeFlow Co...

Vendor: xerox
Product: freeflow_core
Published: Feb 27, 2026
Source: NVD
CVE-2026-27776 HIGH - 7.2

IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only when IM-LogicDesigner is deployed on the system. Arbitrary code may be executed when some crafted file is imported by a user with the administrative privilege.

Vendor: NTT DATA INTRAMART Corporation
Product: intra-mart Accel Platform
Published: Feb 27, 2026
Source: NVD
CVE-2026-0980 HIGH - 8.3

A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote ...

Vendor: rubygems
Product: rubyipmi
Published: Feb 27, 2026
Source: NVD
CVE-2026-28372 HIGH - 7.4

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and require...

Vendor: GNU
Product: inetutils
Published: Feb 27, 2026
Source: NVD
CVE-2026-1442 HIGH - 7.8

Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models. ...

Published: Feb 27, 2026
Source: NVD
CVE-2026-2428 HIGH - 7.5

The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.1.17. This is due to the PayPal IPN (Instant Payment Notification) verification being disabled by default (`disable_ipn_verification` defaults...

Published: Feb 27, 2026
Source: NVD
CVE-2026-28364 HIGH - 7.9

In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operat...

Vendor: OCaml
Product: OCaml
Published: Feb 27, 2026
Source: NVD
CVE-2026-3275 HIGH - 8.8

A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addressNat of the component httpd. Executing a manipulation of the argument entrys can lead to buffer overflow. The attack may be performed from remote. The exploit has been made availa...

Vendor: tenda
Product: f453_firmware
Published: Feb 27, 2026
Source: NVD
CVE-2026-3274 HIGH - 8.8

A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. The attack is possible to be carried out remotely. The exploit...

Vendor: tenda
Product: f453_firmware
Published: Feb 27, 2026
Source: NVD
CVE-2026-3037 HIGH - 8.0

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by modifying malicious input injected into the MBird SMS service URL and/or code via the utility route which is later processed dur...

Vendor: copeland
Product: xweb_300d_pro_firmware
Published: Feb 27, 2026
Source: NVD