Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 10,461 - 10,480 of 13,241 CVEs
CVE-2025-13776 HIGH - 7.1

Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A malicious attacker in local network who knows default credentials is able to read and edit database content. This vulnerability has been fixed in version: Finka-FK 18.5, Finka-KPR ...

Vendor: TIK-SOFT
Product: Finka-FK, Finka-KPR, Finka-Płace, Finka-Faktura, Finka-Magazyn, Finka-STW
Published: Feb 24, 2026
Source: NVD
CVE-2024-48928 HIGH - 7.5

Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration parameter is set to MD5(RAND()) in MySQL. However, RAND() only has 30 bits of randomness, making it feasible to brute-force the secret key. The CSRF token is ...

Vendor: Piwigo
Product: Piwigo
Published: Feb 24, 2026
Source: NVD
CVE-2026-27520 HIGH - 7.5

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side cookie as a Base64-encoded value accessible via the web interface. Because Base64 is reversible and provides no confidentiality, an attacker who can access the cookie value can reco...

Vendor: Binardat Ltd.
Product: 10G08-0800GSM Network Switch
Published: Feb 24, 2026
Source: NVD
CVE-2026-27519 HIGH - 7.5

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded in client-side JavaScript. Because the key is static and exposed, an attacker can decrypt protected values and defeat confidentiality protections.

Vendor: Binardat Ltd.
Product: 10G08-0800GSM Network Switch
Published: Feb 24, 2026
Source: NVD
CVE-2026-27516 HIGH - 8.1

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext within the administrative interface and HTTP responses, allowing recovery of valid credentials.

Vendor: Binardat Ltd.
Product: 10G08-0800GSM Network Switch
Published: Feb 24, 2026
Source: NVD
CVE-2026-23678 HIGH - 8.8

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management interface. By injecting the %1a character into the hostname parameter, an authenticated attacker with ...

Vendor: Binardat Ltd.
Product: 10G08-0800GSM Network Switch
Published: Feb 24, 2026
Source: NVD
CVE-2025-63409 HIGH - 8.8

Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.

Vendor: gcomtw
Product: gcom_epon_1ge_firmware
Published: Feb 24, 2026
Source: NVD
CVE-2026-27732 HIGH - 8.1

WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a `downloadURL` parameter and fetches the referenced resource server-side without proper validation or an allow-list. This allows authenticated users to trigger server-side requests...

Vendor: WWBN
Product: AVideo
Published: Feb 24, 2026
Source: NVD
CVE-2026-27483 HIGH - 8.8

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution. The vulnerability exists in the...

Vendor: mindsdb
Product: mindsdb
Published: Feb 24, 2026
Source: NVD
CVE-2025-67445 HIGH - 7.5

TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (CONTENT_LENGTH + 1) without sufficient bounds checking. When lighttpd s request size limit is not enfor...

Vendor: totolink
Product: x5000r_firmware
Published: Feb 24, 2026
Source: NVD
CVE-2026-2803 HIGH - 7.5

Information disclosure, mitigation bypass in the Settings UI component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2801 HIGH - 7.5

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2798 HIGH - 8.8

Use-after-free in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thunderbird < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2794 HIGH - 7.5

Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability affects Firefox < 148.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2783 HIGH - 7.5

Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2769 HIGH - 8.8

Use-after-free in the Storage: IndexedDB component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.

Vendor: mozilla
Product: firefox
Published: Feb 24, 2026
Source: NVD
CVE-2026-2460 HIGH - 8.1

A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so.

Vendor: hitachienergy
Product: reb500_firmware
Published: Feb 24, 2026
Source: NVD
CVE-2026-2459 HIGH - 8.1

A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.

Vendor: hitachienergy
Product: reb500_firmware
Published: Feb 24, 2026
Source: NVD
CVE-2026-1773 HIGH - 7.5

IEC 60870-5-104: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. Enabling secure communication following IEC 62351-3 does not remediate the vulnerability but mitigates the risk of explo...

Vendor: hitachienergy
Product: rtu540_firmware
Published: Feb 24, 2026
Source: NVD
CVE-2026-2664 HIGH - 7.8

An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an unspecified impact by writing to /proc/docker entries. The issue has been fixed in Docker Desktop 4.6...

Vendor: docker
Product: desktop
Published: Feb 24, 2026
Source: NVD