Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,521 - 10,540 of 13,241 CVEs
CVE-2025-70329 HIGH - 8.0

TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the /usr/sbin/lighttpd executable. The vlanVidLan1 (and other vlanVidLanX) parameters are retrieved via Uci_Get_Str and passed to the CsteSystem function without adequate validation or...

Vendor: totolink
Product: x5000r_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2025-67733 HIGH - 8.5

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject arbitrary information into the response stream for the given client, potentially corrupting or returning tampered data to other users on the same conne...

Vendor: valkey-io
Product: valkey
Published: Feb 23, 2026
Source: NVD
CVE-2025-63946 HIGH - 7.4

A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

Vendor: tencent
Product: pcmanager
Published: Feb 23, 2026
Source: NVD
CVE-2025-63945 HIGH - 7.4

A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

Vendor: tencent
Product: ioa
Published: Feb 23, 2026
Source: NVD
CVE-2025-61144 HIGH - 7.3

libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.

Vendor: libtiff
Product: libtiff
Published: Feb 23, 2026
Source: NVD
CVE-2026-22567 HIGH - 7.6

Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.

Vendor: Zscaler
Product: ZIA Admin UI
Published: Feb 23, 2026
Source: NVD
CVE-2026-3016 HIGH - 8.8

A vulnerability was identified in UTT HiPER 810G up to 1.7.7-171114. The affected element is the function strcpy of the file /goform/formP2PLimitConfig. The manipulation of the argument except leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available ...

Vendor: utt
Product: 810g_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2026-3015 HIGH - 8.8

A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/formPolicyRouteConf. Executing a manipulation of the argument GroupName can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed a...

Vendor: utt
Product: 810g_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2025-70058 HIGH - 7.4

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests

Vendor: ymfe
Product: yapi
Published: Feb 23, 2026
Source: NVD
CVE-2025-70045 HIGH - 7.4

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in jxcore jxm master. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTPS request options when 'jx_obj.IsSecure' is true

Vendor: jxcore
Product: jxm
Published: Feb 23, 2026
Source: NVD
CVE-2025-14905 HIGH - 7.2

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional format...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Feb 23, 2026
Source: NVD
CVE-2026-21420 HIGH - 7.3

Dell Repository Manager (DRM), versions prior to 3.4.8, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution and escalation of privileges.

Vendor: Dell
Product: Repository Manager
Published: Feb 23, 2026
Source: NVD
CVE-2025-69700 HIGH - 7.5

Tenda FH1203 V2.0.1.6 contains a stack-based buffer overflow vulnerability in the modify_add_client_prio function, which is reachable via the formSetClientPrio CGI handler.

Vendor: tenda
Product: fh1203_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2026-2983 HIGH - 7.3

A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin/core/import_users.php of the component Bulk Import. This manipulation of the argument File causes improper access controls. Remote exploitation of the...

Vendor: munyweki
Product: student_result_management_system
Published: Feb 23, 2026
Source: NVD
CVE-2026-2981 HIGH - 8.8

A vulnerability was found in UTT HiPER 810G up to 1.7.7-1711. The affected element is the function strcpy of the file /goform/formTaskEdit_ap. The manipulation of the argument txtMin2 results in buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.

Vendor: utt
Product: 810g_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2026-2980 HIGH - 7.2

A vulnerability has been found in UTT HiPER 810G up to 1.7.7-1711. Impacted is the function strcpy of the file /goform/setSysAdm. The manipulation of the argument passwd1 leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Vendor: utt
Product: 810g_firmware
Published: Feb 23, 2026
Source: NVD
CVE-2026-25747 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. An...

Vendor: Apache Software Foundation
Product: Apache Camel
Published: Feb 23, 2026
Source: NVD
CVE-2026-1367 HIGH - 8.3

Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.

Published: Feb 23, 2026
Source: NVD
CVE-2026-2998 HIGH - 7.8

ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code.

Published: Feb 23, 2026
Source: NVD
CVE-2026-2962 HIGH - 8.8

A vulnerability was found in D-Link DWR-M960 1.01.07. This vulnerability affects the function sub_460F30 of the file /boafrm/formDateReboot of the component Scheduled Reboot Configuration Endpoint. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack may be ...

Vendor: dlink
Product: dwr-m960_firmware
Published: Feb 23, 2026
Source: NVD