Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,649
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 10,341 - 10,360 of 13,241 CVEs
CVE-2026-25191 HIGH - 7.8

The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is directed to place a malicious DLL file and the installer to the same directory and execute the installer, arbitrary code may be executed with the installer's execution privil...

Vendor: Digital Arts Inc.
Product: FinalCode Ver.5 series, FinalCode Ver.6 series
Published: Feb 26, 2026
Source: NVD
CVE-2026-23703 HIGH - 7.8

The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability. A non-administrative user may execute arbitrary code with SYSTEM privilege.

Vendor: Digital Arts Inc.
Product: FinalCode Ver.5 series, FinalCode Ver.6 series
Published: Feb 26, 2026
Source: NVD
CVE-2026-1311 HIGH - 8.8

The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functionality. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload a malicious ZIP archive with path travers...

Published: Feb 26, 2026
Source: NVD
CVE-2026-27465 HIGH - 6.5

Fleet is open source device management software. In versions prior to 4.80.1, a vulnerability in Fleet’s configuration API could expose Google Calendar service account credentials to authenticated users with low-privilege roles. This may allow unauthorized access to Google Calendar resources associa...

Vendor: fleetdm
Product: fleet
Published: Feb 26, 2026
Source: NVD
CVE-2026-1779 HIGH - 8.1

The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly regi...

Published: Feb 26, 2026
Source: NVD
CVE-2026-27965 HIGH - 9.9

Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is later executed when that backup is restored. Th...

Vendor: vitessio
Product: vitess
Published: Feb 26, 2026
Source: NVD
CVE-2026-27961 HIGH - 8.8

Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed server-side within the API process when r...

Vendor: Agenta-AI
Product: agenta
Published: Feb 26, 2026
Source: NVD
CVE-2026-27959 HIGH - 7.5

Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API performs naive parsing of the HTTP Host header, extracting everything before the first colon without validating the input conforms to RFC 3986 hostname syntax. When a malform...

Vendor: koajs
Product: koa
Published: Feb 26, 2026
Source: NVD
CVE-2026-27952 HIGH - 8.8

Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a sandboxing mechanism for user-supplied evaluator code, but incorrectly whitelisted the `numpy` pack...

Vendor: Agenta-AI
Product: agenta-api
Published: Feb 26, 2026
Source: NVD
CVE-2026-27938 HIGH - 7.7

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command injection through direct use of `${{ github.event.pull_request.body }}` inside a `run:` shell block. When a...

Vendor: wp-graphql
Product: wp-graphql
Published: Feb 26, 2026
Source: NVD
CVE-2026-27904 HIGH - 7.5

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.4, nested `*()` extglobs produce regexps with nested unbounded quantifiers (e.g. `(?:(?:a|b)*)*`), which exhibit catastro...

Vendor: isaacs
Product: minimatch
Published: Feb 26, 2026
Source: NVD
CVE-2026-27903 HIGH - 7.5

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking when a glob pattern contains multiple non-adjacent `**` (GLOBST...

Vendor: isaacs
Product: minimatch
Published: Feb 26, 2026
Source: NVD
CVE-2026-27899 HIGH - 8.8

WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sending a single PUT request to their own user profile endpoint with `"IsAdmin": true` in the JSO...

Vendor: h44z
Product: wg-portal
Published: Feb 26, 2026
Source: NVD
CVE-2026-1557 HIGH - 7.5

The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 via the 'src' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive informati...

Published: Feb 26, 2026
Source: NVD
CVE-2026-27946 HIGH - 6.5

ZITADEL is an open source identity management platform. Prior to versions 4.11.1 and 3.4.7, a vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification process. The patch in versions 4.11.1 and 3.4....

Vendor: zitadel
Product: zitadel
Published: Feb 26, 2026
Source: NVD

The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prior to 1.3.1. Go's standard library performs case-insensitive matching of JSON keys to struct field tags β€” a field tagged json:"method" would also match "Met...

Vendor: modelcontextprotocol
Product: go-sdk
Published: Feb 26, 2026
Source: NVD
CVE-2026-27831 HIGH - 7.5

rldns is an open source DNS server. Version 2.3 has a heap-based out-of-bounds read that leads to denial of service. Version 1.4 contains a patch for the issue.

Vendor: bluedragonsecurity
Product: rldns
Published: Feb 26, 2026
Source: NVD
CVE-2026-27976 HIGH - 8.8

Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`async_tar::Archive::unpack`) creates symlinks from the archive without validation, and the path guard (`writeable_path_from_extension`) only performs lexical prefix checks without ...

Vendor: zed-industries
Product: zed
Published: Feb 26, 2026
Source: NVD
CVE-2026-27967 HIGH - 7.1

Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading and writing files **outside the project directory** when a project contains symbolic links pointing to external paths. This bypasses the intended work...

Vendor: zed-industries
Product: zed
Published: Feb 26, 2026
Source: NVD
CVE-2026-27818 HIGH - 7.5

TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration. Version 4.0.3 fixes the issue.

Vendor: TerriaJS
Product: terriajs-server
Published: Feb 26, 2026
Source: NVD