Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,621 - 10,640 of 13,241 CVEs
CVE-2026-2038 HIGH - 7.3

GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configur...

Vendor: gfi
Product: archiver
Published: Feb 20, 2026
Source: NVD
CVE-2026-2037 HIGH - 8.8

GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although authentication is required to exploit this vulnerability, the existing authentication...

Vendor: gfi
Product: archiver
Published: Feb 20, 2026
Source: NVD
CVE-2026-2036 HIGH - 8.8

GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although authentication is required to exploit this vulnerability, the existing authenticatio...

Vendor: gfi
Product: archiver
Published: Feb 20, 2026
Source: NVD
CVE-2026-2034 HIGH - 7.8

Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must vi...

Vendor: santesoft
Product: dicom_viewer_pro
Published: Feb 20, 2026
Source: NVD
CVE-2026-2033 HIGH - 8.1

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. The specific flaw ...

Published: Feb 20, 2026
Source: NVD
CVE-2019-25454 HIGH - 7.2

phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation...

Vendor: Phpmoadmin
Product: phpMoAdmin
Published: Feb 20, 2026
Source: NVD
CVE-2019-25438 HIGH - 8.2

LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the login parameter of login.php or the user_name parameter of r...

Vendor: Labcollector
Product: LabCollector
Published: Feb 20, 2026
Source: NVD
CVE-2019-25435 HIGH - 7.8

Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the Username field in User Manag...

Vendor: Sricam
Product: Sricam DeviceViewer
Published: Feb 20, 2026
Source: NVD
CVE-2019-25434 HIGH - 7.5

SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field during registration to tr...

Vendor: Nsasoft
Product: Nsauditor SpotAuditor
Published: Feb 20, 2026
Source: NVD
CVE-2019-25432 HIGH - 7.5

Part-DB 0.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to login by injecting SQL syntax into authentication parameters. Attackers can submit a single quote followed by 'or' in the login form to bypass credential validation and gain unauthorized ac...

Vendor: Part-DB
Product: Part-DB
Published: Feb 20, 2026
Source: NVD
CVE-2019-25431 HIGH - 8.2

delpino73 Blue-Smiley-Organizer 1.32 contains an SQL injection vulnerability in the datetime parameter that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL code through POST requests to extract sensitive data using boolean-based blind and time-based blind te...

Vendor: delpino73
Product: Blue-Smiley-Organizer
Published: Feb 20, 2026
Source: NVD
CVE-2018-25158 HIGH - 8.8

Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrar...

Vendor: Chamilo
Product: Chamillo LMS
Published: Feb 20, 2026
Source: NVD
CVE-2026-0797 HIGH - 7.8

GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or o...

Vendor: gimp
Product: gimp
Published: Feb 20, 2026
Source: NVD
CVE-2026-0777 HIGH - 7.8

Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xmind. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a m...

Published: Feb 20, 2026
Source: NVD
CVE-2026-2857 HIGH - 8.8

A vulnerability was determined in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_423E00 of the file /boafrm/formPortFw of the component Port Forwarding Configuration Endpoint. This manipulation of the argument submit-url causes stack-based buffer overflow. Remote exploitation of...

Vendor: dlink
Product: dwr-m960_firmware
Published: Feb 20, 2026
Source: NVD
CVE-2026-2856 HIGH - 8.8

A vulnerability was found in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub_424AFC of the file /boafrm/formFilter of the component Filter Configuration Endpoint. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack may be launche...

Vendor: dlink
Product: dwr-m960_firmware
Published: Feb 20, 2026
Source: NVD
CVE-2026-24892 HIGH - 7.5

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized changelog data derived from a...

Vendor: openITCOCKPIT
Product: openITCOCKPIT
Published: Feb 20, 2026
Source: NVD
CVE-2026-2855 HIGH - 8.8

A vulnerability has been found in D-Link DWR-M960 1.01.07. Affected is the function sub_4648F0 of the file /boafrm/formDdns of the component DDNS Settings Handler. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has ...

Vendor: dlink
Product: dwr-m960_firmware
Published: Feb 20, 2026
Source: NVD
CVE-2026-2854 HIGH - 8.8

A flaw has been found in D-Link DWR-M960 1.01.07. This impacts the function sub_4611CC of the file /boafrm/formNtp of the component NTP Configuration Endpoint. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. The attack can be launched remotely. The exploi...

Vendor: dlink
Product: dwr-m960_firmware
Published: Feb 20, 2026
Source: NVD
CVE-2026-2853 HIGH - 8.8

A vulnerability was detected in D-Link DWR-M960 1.01.07. This affects the function sub_462E14 of the file /boafrm/formSysLog of the component System Log Configuration Endpoint. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be initiated re...

Vendor: dlink
Product: dwr-m960_firmware
Published: Feb 20, 2026
Source: NVD