Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,646
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 10,421 - 10,440 of 13,241 CVEs
CVE-2026-3152 HIGH - 7.3

A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/teacher-salary.php. This manipulation of the argument teacher_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and...

Vendor: angeljudesuarez
Product: college_management_system
Published: Feb 25, 2026
Source: NVD
CVE-2026-3151 HIGH - 7.3

A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

Vendor: angeljudesuarez
Product: college_management_system
Published: Feb 25, 2026
Source: NVD
CVE-2026-3148 HIGH - 7.3

A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may ...

Vendor: haben-cs9
Product: simple_and_nice_shopping_cart_script
Published: Feb 25, 2026
Source: NVD
CVE-2026-27696 HIGH - 8.6

changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io is vulnerable to Server-Side Request Forgery (SSRF) because the URL validation function `is_safe_valid_url()` does not validate the resolved IP address of watch URLs against priva...

Vendor: dgtlmoon
Product: changedetection.io
Published: Feb 25, 2026
Source: NVD
CVE-2026-27624 HIGH - 7.2

Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and internal ranges using "denied-peer-ip" and/or default loopback restrictions. CVE-2020-26262 addressed bypasses involving "0.0.0.0", "[::1]" and "...

Vendor: coturn
Product: coturn
Published: Feb 25, 2026
Source: NVD
CVE-2026-27745 HIGH - 8.8

The SPIP interface_traduction_objets plugin versions prior toΒ 4.3.3 contain an authenticated remote code execution vulnerability in the translation interface workflow. The plugin incorporates untrusted request data into a hidden form field that is rendered without SPIP output filtering. Because fiel...

Vendor: SPIP
Product: interface_traduction_objets
Published: Feb 25, 2026
Source: NVD
CVE-2026-27640 HIGH - 7.5

tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context variables, and hierarchica...

Vendor: oocx
Product: tfplan2md
Published: Feb 25, 2026
Source: NVD
CVE-2026-27636 HIGH - 8.8

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/Misc/Helper.php` does not include `.htaccess` or `.user.ini` files. On Apache servers with `AllowOverride All` (a common configurati...

Vendor: freescout-help-desk
Product: freescout
Published: Feb 25, 2026
Source: NVD
CVE-2026-27627 HIGH - 8.2

Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `readableContentHtml`, the HTML parsing subprocess uses it directly without running it through DOMPurify. Every other content source in the crawler goes through Readability + DOMPurify, ...

Vendor: karakeep-app
Product: karakeep
Published: Feb 25, 2026
Source: NVD
CVE-2026-27628 HIGH - 7.5

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires reading the file. This has been fixed in pypdf 6.7.2. As a workaround, one may apply the patch manually.

Vendor: py-pdf
Product: pypdf
Published: Feb 25, 2026
Source: NVD
CVE-2026-27615 HIGH - 7.8

ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbPath` settings variable, which determines the path of the ADB binary to be executed, to be set to a Universal Naming Convention (UNC) path in the application's settings file. T...

Vendor: Alex4SSB
Product: ADB-Explorer
Published: Feb 25, 2026
Source: NVD
CVE-2026-27611 HIGH - 6.5

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the password and still download the file. This happens because the API returns a direct download link in t...

Vendor: gtsteffaniak
Product: filebrowser
Published: Feb 25, 2026
Source: NVD
CVE-2026-27610 HIGH - 5.3

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the `ConfigKeyCache` uses the same cache key for both master key and read-only master key when resolving function-typed keys. Under specific timing conditions, a read-only user...

Vendor: parse-community
Product: parse-dashboard
Published: Feb 25, 2026
Source: NVD
CVE-2026-27609 HIGH - 6.5

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint (`POST /apps/:appId/agent`) lacks CSRF protection. An attacker can craft a malicious page that, when visited by an authenticated dashboard user, submi...

Vendor: parse-community
Product: parse-dashboard
Published: Feb 25, 2026
Source: NVD
CVE-2026-27607 HIGH - 8.1

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads (PostObject), allowing attackers to bypass content-length-range, starts-with, and Content-Type constraints. This enable...

Vendor: rustfs
Product: rustfs
Published: Feb 25, 2026
Source: NVD
CVE-2026-2914 HIGH - 7.8

CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs

Vendor: cyberark
Product: endpoint_privilege_manager
Published: Feb 25, 2026
Source: NVD
CVE-2026-25131 HIGH - 8.8

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in the OpenEMR order types management system, allowing low-privilege users (such as Receptionist) to add and modify procedure ...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD
CVE-2025-69231 HIGH - 8.7

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site scripting vulnerability in the GAD-7 anxiety assessment form allows authenticated users with clinician privileges to inject malicious JavaScript that e...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD
CVE-2025-67752 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: false`), making all external HTTPS connections...

Vendor: openemr
Product: openemr
Published: Feb 25, 2026
Source: NVD
CVE-2026-3135 HIGH - 7.3

A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been made availabl...

Vendor: clive_21
Product: news_portal_project
Published: Feb 25, 2026
Source: NVD