Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,501 - 10,520 of 13,241 CVEs
CVE-2026-24481 HIGH - 7.5

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted PSD file conta...

Vendor: ImageMagick
Product: ImageMagick
Published: Feb 24, 2026
Source: NVD
CVE-2026-3044 HIGH - 8.8

A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-bin/UploadCfg of the component Httpd Service. The manipulation of the argument boundary leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The ex...

Vendor: tenda
Product: ac8_firmware
Published: Feb 24, 2026
Source: NVD
CVE-2026-3042 HIGH - 7.3

A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and ...

Vendor: admerc
Product: event_management_system
Published: Feb 24, 2026
Source: NVD
CVE-2025-69252 HIGH - 7.5

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 have a NULL Pointer Dereference vulnerability. Remote unauthenticated attackers can trigger a service panic (Denial of Service) by s...

Vendor: free5gc
Product: udm
Published: Feb 24, 2026
Source: NVD
CVE-2025-69250 HIGH - 7.5

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. In versions up to and including 1.4.1, the service reliably leaks detailed internal error messages (e.g., strconv.ParseInt parsing errors) to remote clients when proce...

Vendor: free5gc
Product: udm
Published: Feb 24, 2026
Source: NVD
CVE-2026-25649 HIGH - 7.3

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect vulnerability in two OIDC-related endpoints. The `redirect_uri` parameter is not validated against a...

Vendor: traccar
Product: traccar
Published: Feb 23, 2026
Source: NVD
CVE-2025-69248 HIGH - 7.5

free5GC is an an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of free5GC's AMF service have a Buffer Overflow vulnerability leading to Denial of Service. Remote unauthenticated attackers can crash the AMF service by sending a specially cra...

Vendor: free5gc
Product: amf
Published: Feb 23, 2026
Source: NVD
CVE-2025-69247 HIGH - 7.5

free5GC go-upf is the User Plane Function (UPF) implementation for 5G networks that is part of the free5GC project. Versions prior to 1.2.8 have a Heap-based Buffer Overflow (CWE-122) vulnerability leading to Denial of Service. Remote attackers can crash the UPF network element by sending a speciall...

Vendor: free5gc
Product: go-upf
Published: Feb 23, 2026
Source: NVD
CVE-2025-69232 HIGH - 7.5

free5GC is an an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to free5gc smf up to and including 1.4.0, have an Improper Input Validation and Protocol Compliance vulnerability leading to Denial of Service. Remote a...

Vendor: free5gc
Product: go-upf, smf
Published: Feb 23, 2026
Source: NVD
CVE-2026-27127 HIGH - 6.3

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMSโ€™s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time-of-Check-Time-of-Use (TOCTOU) vulnerability enables DNS rebind...

Vendor: composer
Product: craftcms/cms
Published: Feb 23, 2026
Source: GitHub
CVE-2026-26331 HIGH - 8.8

yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt-dlp's `--netrc-cmd` command-line option (or `netrc_cmd` Python API parameter) is used, an attacker could achieve arbitrary command injection on the user's system with a ...

Vendor: pip
Product: yt-dlp
Published: Feb 23, 2026
Source: GitHub
CVE-2026-25802 HIGH - 7.6

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `<scrip...

Vendor: go
Product: github.com/QuantumNous/new-api
Published: Feb 23, 2026
Source: GitHub
CVE-2026-25591 HIGH - 6.5

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustion...

Vendor: go
Product: github.com/QuantumNous/new-api
Published: Feb 23, 2026
Source: GitHub
CVE-2026-3026 HIGH - 7.3

A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the file /plug-in/ueditor/jsp/getRemoteImage.jsp of the component UEditor. The manipulation of the argument upfile leads to server-side request forgery. The attack can be initiated remote...

Vendor: jeewms
Product: jeewms
Published: Feb 23, 2026
Source: NVD
CVE-2026-3025 HIGH - 7.3

A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of the file /MP/Service/Webservice/ExampleNodeService.asmx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to...

Published: Feb 23, 2026
Source: NVD
CVE-2026-25648 HIGH - 8.7

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device images. The application accepts SVG file uploads without...

Vendor: traccar
Product: traccar
Published: Feb 23, 2026
Source: NVD
CVE-2025-70328 HIGH - 8.8

TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_40C404 and passed to a date -s shell command through CsteSystem. While the first two tokens of the in...

Vendor: totolink
Product: x6000r_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2025-68930 HIGH - 7.1

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocket handshake. This allows a remote attacker to bypa...

Vendor: traccar
Product: traccar
Published: Feb 23, 2026
Source: NVD
CVE-2026-27623 HIGH - 7.5

Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can cause the system to abort by triggering an assertion. When processing incoming requests, the Valkey system does not properly reset the networking stat...

Vendor: valkey-io
Product: valkey
Published: Feb 23, 2026
Source: NVD
CVE-2026-21863 HIGH - 7.5

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing c...

Vendor: valkey-io
Product: valkey
Published: Feb 23, 2026
Source: NVD