Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,650
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,321 - 10,340 of 13,241 CVEs
CVE-2026-28211 HIGH - 7.8

The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions 2.0 through 8.0 in the Log Reader feature of this add-on. A maliciously crafted log file can lead to arbitrary code execution when a user reads it with log r...

Vendor: CyrilleB79
Product: NVDA-Dev-Test-Toolbox
Published: Feb 26, 2026
Source: NVD
CVE-2026-27638 HIGH - 7.1

Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoints (`/sync/*`) don't verify that the authenticated user owns or has access to the file being operated on. Any authenticated user can read, modify, and overwrite any other use...

Vendor: actualbudget
Product: actual
Published: Feb 26, 2026
Source: NVD
CVE-2026-3261 HIGH - 7.3

A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and m...

Vendor: itsourcecode
Product: school_management_system
Published: Feb 26, 2026
Source: NVD
CVE-2026-27449 HIGH - 7.5

Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed directly over the net...

Vendor: umbraco
Product: Umbraco.Engage.Forms
Published: Feb 26, 2026
Source: NVD
CVE-2026-25741 HIGH - 7.1

Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpoint for creating a card update session during an upgrade flow was accessible to users with only organization member privileges. When the associated Stripe Checkout session is compl...

Vendor: zulip
Product: zulip
Published: Feb 26, 2026
Source: NVD
CVE-2026-22206 HIGH - 8.8

SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code e...

Vendor: SPIP
Product: SPIP
Published: Feb 26, 2026
Source: NVD
CVE-2026-22205 HIGH - 7.5

SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows unauthenticated attackers to access protected information. Attackers can exploit loose type comparisons in authentication logic to bypass login verification and retrieve sensitive int...

Vendor: SPIP
Product: SPIP
Published: Feb 26, 2026
Source: NVD
CVE-2026-27509 HIGH - 8.0

Unitree Go2 firmware versions V1.1.7 through V1.1.9 and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join DDS domain 0 and publi...

Vendor: UnitreeRobotics
Product: Unitree Go2
Published: Feb 26, 2026
Source: NVD
CVE-2026-27141 HIGH - 7.5

Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic

Vendor: golang.org/x/net
Product: golang.org/x/net/http2
Published: Feb 26, 2026
Source: NVD
CVE-2026-1565 HIGH - 8.8

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admi...

Published: Feb 26, 2026
Source: NVD
CVE-2026-26938 HIGH - 8.6

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242). This requires an auth...

Vendor: Elastic
Product: Kibana
Published: Feb 26, 2026
Source: NVD
CVE-2026-26682 HIGH - 7.8

An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java component

Vendor: xjd2020
Product: fastcms
Published: Feb 26, 2026
Source: NVD
CVE-2026-23750 HIGH - 8.1

Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certificate handling. server_cert_write() allocates a heap buffer of size CONFIG_POUCH_SERVER_CERT_MAX_LEN when receiving the first fragment, then appends subsequent fragments using memcpy...

Vendor: Golioth
Product: Pouch
Published: Feb 26, 2026
Source: NVD
CVE-2026-26265 HIGH - 7.5

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerability in the directory items endpoint allows any user, including anonymous users, to retrieve private user field values for all users in the directory. The `user_field_ids` parameter...

Vendor: discourse
Product: discourse
Published: Feb 26, 2026
Source: NVD
CVE-2026-26078 HIGH - 7.5

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting is blank, an attacker can forge valid webhook signatures by computing an HMAC-MD5 with an empty string as the key. Since the request body is known to t...

Vendor: discourse
Product: discourse
Published: Feb 26, 2026
Source: NVD
CVE-2025-71057 HIGH - 8.2

Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.

Published: Feb 26, 2026
Source: NVD
CVE-2026-3071 HIGH - 8.4

Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to arbitrary code execution when loading a malicious model.

Published: Feb 26, 2026
Source: NVD
CVE-2025-14343 HIGH - 7.6

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd. E-Commerce Product allows Reflected XSS.This issue affects E-Commerce Product: through 10122025.

Vendor: Dokuzsoft Technology Ltd.
Product: E-Commerce Product
Published: Feb 26, 2026
Source: NVD
CVE-2026-28138 HIGH - 7.2

Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects uListing: from n/a through <= 2.2.0.

Vendor: Stylemix
Product: uListing
Published: Feb 26, 2026
Source: NVD
CVE-2026-28136 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS wp-sms allows SQL Injection.This issue affects WP SMS: from n/a through <= 6.9.12.

Vendor: VeronaLabs
Product: WP SMS
Published: Feb 26, 2026
Source: NVD