Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,649
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,401 - 10,420 of 13,241 CVEs
CVE-2026-20048 HIGH - 7.7

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper processing when...

Vendor: Cisco
Product: Cisco NX-OS System Software in ACI Mode
Published: Feb 25, 2026
Source: NVD
CVE-2026-20033 HIGH - 7.4

A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker c...

Vendor: Cisco
Product: Cisco NX-OS System Software in ACI Mode
Published: Feb 25, 2026
Source: NVD
CVE-2026-20010 HIGH - 7.4

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of specif...

Vendor: Cisco
Product: Cisco NX-OS Software, Cisco NX-OS System Software in ACI Mode, Cisco Unified Computing System (Managed)
Published: Feb 25, 2026
Source: NVD
CVE-2026-27730 HIGH - 8.6

esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF vulnerability (CWE-918) in esm.shโ€™s `/http(s)` fetch route. The service tries to block localhost/internal targets, but the validation is based on hostname string checks and can be b...

Vendor: esm-dev
Product: esm.sh
Published: Feb 25, 2026
Source: NVD
CVE-2026-27700 HIGH - 8.2

Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an Application Load Balancer (ALB), the `getConnInfo()` function incorrectly selected the first value from the `X-Forwarde...

Vendor: honojs
Product: hono
Published: Feb 25, 2026
Source: NVD
CVE-2026-27692 HIGH - 7.1

iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and including 2.3.1.4, heap-buffer-overflow read occurs during CIccTagTextDescription::Release() when strlen() reads past a heap buffer while parsing ICC profile XML text description tags, ...

Vendor: InternationalColorConsortium
Product: iccDEV
Published: Feb 25, 2026
Source: NVD
CVE-2025-50180 HIGH - 7.5

esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information from internal websites through the vulnerability. Version 137 fixes the vulnerability.

Vendor: go
Product: github.com/esm-dev/esm.sh
Published: Feb 25, 2026
Source: GitHub
CVE-2026-28193 HIGH - 8.8

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

Vendor: JetBrains
Product: YouTrack
Published: Feb 25, 2026
Source: NVD
CVE-2026-26103 HIGH - 7.1

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block device...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Feb 25, 2026
Source: NVD
CVE-2026-2416 HIGH - 7.5

The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibl...

Published: Feb 25, 2026
Source: NVD
CVE-2026-1929 HIGH - 8.8

The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.37. This is due to the use of `call_user_func_array()` with user-controlled callback and parameters in the `get_select_option_values()` AJAX handler without an allowlist of per...

Published: Feb 25, 2026
Source: NVD
CVE-2026-1916 HIGH - 7.5

The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks and an insecure authentication mechanism on the `wpgsi_callBackFuncAccept` and `wpgsi_callBackFuncUpdate` REST API functions in all versions up to, and...

Published: Feb 25, 2026
Source: NVD
CVE-2026-3169 HIGH - 8.8

A security vulnerability has been detected in Tenda F453 1.0.0.3. This impacts the function fromSafeEmailFilter of the file /goform/SafeEmailFilter of the component httpd. The manipulation of the argument page leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has b...

Vendor: tenda
Product: f453_firmware
Published: Feb 25, 2026
Source: NVD
CVE-2026-3168 HIGH - 8.8

A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform/NatStaticSetting of the component httpd. Executing a manipulation of the argument page can lead to buffer overflow. The attack may be launched remotely. The exploit has been made ...

Vendor: tenda
Product: f453_firmware
Published: Feb 25, 2026
Source: NVD
CVE-2026-3167 HIGH - 8.8

A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component httpd. Performing a manipulation of the argument webSiteId results in buffer overflow. The attack may be initiated remotely. The expl...

Vendor: tenda
Product: f453_firmware
Published: Feb 25, 2026
Source: NVD
CVE-2026-3166 HIGH - 8.8

A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /goform/RouteStatic of the component httpd. Such manipulation of the argument page leads to buffer overflow. The attack can be launched remotely. The exploit is publicly available a...

Vendor: tenda
Product: f453_firmware
Published: Feb 25, 2026
Source: NVD
CVE-2026-3179 HIGH - 8.1

The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MITM attacker can craft filenames containing path traversal sequences, causing the client to write files outside the intended backup directory. A path tr...

Vendor: asustor
Product: data_master
Published: Feb 25, 2026
Source: NVD
CVE-2026-3165 HIGH - 8.8

A vulnerability was determined in Tenda F453 1.0.0.3. Impacted is the function fromSetWifiGusetBasic of the file /goform/AdvSetWrlsafeset of the component httpd. This manipulation of the argument mit_ssid causes buffer overflow. The attack can be initiated remotely. The exploit has been publicly dis...

Vendor: tenda
Product: f453_firmware
Published: Feb 25, 2026
Source: NVD
CVE-2026-3164 HIGH - 7.3

A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The manipulation of the argument pagetitle results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and coul...

Vendor: clive_21
Product: news_portal_project
Published: Feb 25, 2026
Source: NVD
CVE-2026-3153 HIGH - 7.3

A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and ...

Vendor: admerc
Product: document_management_system
Published: Feb 25, 2026
Source: NVD