Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,649
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 10,381 - 10,400 of 13,241 CVEs
CVE-2026-1388 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service by sending specially crafted input to a merge request endpoint under ...

Vendor: gitlab
Product: gitlab
Published: Feb 25, 2026
Source: NVD
CVE-2026-0752 HIGH - 8.0

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.

Vendor: gitlab
Product: gitlab
Published: Feb 25, 2026
Source: NVD
CVE-2025-14511 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certa...

Vendor: GitLab
Product: GitLab
Published: Feb 25, 2026
Source: NVD
CVE-2026-22720 HIGH - 8.0

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.Β  To remediate CVE-2026-22720, apply the patches listed in the 'Fi...

Vendor: VMware
Product: VMware Aria Operations, VMware Cloud Foundation, VMware Telco Cloud Platform, VMware Telco Cloud Infrastructure
Published: Feb 25, 2026
Source: NVD
CVE-2026-22719 HIGH - 8.1

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.Β  To remediate CVE-2026...

Vendor: VMware
Product: Aria Operations, Cloud Foundationcust, Telco Cloud Platform, Telco Cloud Infrastructure
Published: Feb 25, 2026
Source: NVD
CVE-2026-25927 HIGH - 7.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the DICOM viewer state API (e.g. upload or state save/load) accepts a document ID (`doc_id`) without verifying that the document belongs to the current user’s authorized ...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD
CVE-2026-25746 HIGH - 8.8

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulnerability in prescription that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in th...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD
CVE-2026-25476 HIGH - 7.5

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the session expiration check in `library/auth.inc.php` runs only when `skip_timeout_reset` is not present in the request. When `skip_timeout_reset=1` is sent, the entire b...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD
CVE-2026-25164 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the REST API route table in `apis/routes/_rest_routes_standard.inc.php` does not call `RestConfig::request_authorization_check()` for the document and insurance routes. Ot...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD
CVE-2026-24890 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization bypass vulnerability in the patient portal signature endpoint allows authenticated portal users to upload and overwrite provider signatures by setting `ty...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD
CVE-2026-23627 HIGH - 8.8

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Immunization module allows any authenticated user to execute arbitrary SQL queries, leading to complete database compromise, PHI exfi...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD
CVE-2026-25733 HIGH - 7.3

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the Custom Rules function of the WebUI where ...

Vendor: pip
Product: rucio-webui
Published: Feb 25, 2026
Source: GitHub
CVE-2026-25136 HIGH - 8.1

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. A reflected Cross-site Scripting vulnerability was located in versions prior to 35.8.3, 38.5.4, and 39.3.1 in the rendering of the ExceptionMessage ...

Vendor: pip
Product: rucio-webui
Published: Feb 25, 2026
Source: GitHub

c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map<Stri...

Vendor: maven
Product: com.mchange:c3p0
Published: Feb 25, 2026
Source: GitHub
CVE-2026-27850 HIGH - 7.5

Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source port 5222, exposing all services which are normally only accessible through the local network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

Vendor: Linksys
Product: MR9600, MX4200
Published: Feb 25, 2026
Source: NVD

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an ap...

Vendor: swaldman
Product: mchange-commons-java
Published: Feb 25, 2026
Source: NVD
CVE-2026-27706 HIGH - 7.7

Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated attacker with general user privileges to send arbitrary GET requests to ...

Vendor: makeplane
Product: plane
Published: Feb 25, 2026
Source: NVD
CVE-2026-20128 HIGH - 7.5

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges on an affected system. To exploit this vulnerability, the attacker must have valid&nbsp;vmanage credentials on the affected system....

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: Feb 25, 2026
Source: NVD
CVE-2026-20126 HIGH - 8.8

A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gain root privileges on the underlying operating system. This vulnerability is due to an insufficient user authentication mechanism in the REST API. An attacker could exploit this ...

Vendor: Cisco
Product: Cisco Catalyst SD-WAN Manager
Published: Feb 25, 2026
Source: NVD
CVE-2026-20051 HIGH - 7.4

A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop. This vulnerability is due to a logic error wh...

Vendor: Cisco
Product: Cisco NX-OS Software
Published: Feb 25, 2026
Source: NVD