Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,637
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 10,641 - 10,660 of 13,241 CVEs

Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up toΒ (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via pre-creating predictably...

Vendor: pip
Product: google-cloud-aiplatform
Published: Feb 20, 2026
Source: NVD

Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's Jupyter or Colab ...

Vendor: pip
Product: google-cloud-aiplatform
Published: Feb 20, 2026
Source: NVD
CVE-2019-25444 HIGH - 8.2

Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can supply malicious SQL syntax in the page parameter to extract sensitive database information or modify...

Vendor: Phpscriptsmall
Product: Fiverr Clone Script
Published: Feb 20, 2026
Source: NVD
CVE-2026-27115 HIGH - 7.1

ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigger recursive deletion of arbitrary directories on the Windows filesystem. ADB Explorer accepts an optional path argument to set a custom data directory,...

Vendor: Alex4SSB
Product: ADB-Explorer
Published: Feb 20, 2026
Source: NVD
CVE-2026-24891 HIGH - 7.5

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls PHP's unserialize...

Vendor: openITCOCKPIT
Product: openITCOCKPIT
Published: Feb 20, 2026
Source: NVD
CVE-2026-2818 HIGH - 8.2

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

Published: Feb 20, 2026
Source: NVD
CVE-2026-26746 HIGH - 8.8

OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code ...

Vendor: opensourcepos
Product: open_source_point_of_sale
Published: Feb 20, 2026
Source: NVD
CVE-2026-26724 HIGH - 7.6

Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the selectgroup and gn parameters on the /?Function=Groups endpoint.

Vendor: keystorage
Product: global_facilities_management_software
Published: Feb 20, 2026
Source: NVD
CVE-2026-26723 HIGH - 8.2

Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the function parameter.

Vendor: keystorage
Product: global_facilities_management_software
Published: Feb 20, 2026
Source: NVD
CVE-2026-26721 HIGH - 7.1

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensitive information via the sid query parameter.

Vendor: keystorage
Product: global_facilities_management_software
Published: Feb 20, 2026
Source: NVD
CVE-2026-26102 HIGH - 7.8

Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.

Vendor: Owl
Product: opds
Published: Feb 20, 2026
Source: NVD
CVE-2026-26101 HIGH - 7.8

Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.

Vendor: Owl
Product: opds
Published: Feb 20, 2026
Source: NVD
CVE-2026-26048 HIGH - 7.5

The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of management frame protection, allowing forged deauthentication and disassociation frames to be broadcast without authentication or encryption. An attacker can use this to cause unauthorized disruptions and create a ...

Vendor: Jinan USR IOT Technology Limited (PUSR)
Product: USR-W610
Published: Feb 20, 2026
Source: NVD
CVE-2026-24790 HIGH - 8.2

The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.

Vendor: Welker
Product: OdorEyes EcoSystem Pulse Bypass System with XL4 Controller
Published: Feb 20, 2026
Source: NVD
CVE-2026-24455 HIGH - 7.5

The embedded web interface of the device does not support HTTPS/TLS for authentication and uses HTTP Basic Authentication. Traffic is encoded but not encrypted, exposing user credentials to passive interception by attackers on the same network.

Vendor: Jinan USR IOT Technology Limited (PUSR)
Product: USR-W610
Published: Feb 20, 2026
Source: NVD
CVE-2026-2847 HIGH - 7.2

A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/formReleaseConnect of the component Web Management Interface. The manipulation of the argument Isp_Name results in os command injection. The attack can be launched remotely. The exploi...

Vendor: utt
Product: 520_firmware
Published: Feb 20, 2026
Source: NVD
CVE-2026-2846 HIGH - 7.2

A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of the component Web Management Interface. The manipulation of the argument policyNames leads to os command injection. The attack can be initiated remote...

Vendor: utt
Product: 520_firmware
Published: Feb 20, 2026
Source: NVD
CVE-2026-27072 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PixelYourSite PixelYourSite – Your smart PIXEL (TAG) Manager pixelyoursite allows Stored XSS.This issue affects PixelYourSite – Your smart PIXEL (TAG) Manager: from n/a through <= 11.2....

Vendor: PixelYourSite
Product: PixelYourSite – Your smart PIXEL (TAG) Manager
Published: Feb 20, 2026
Source: NVD
CVE-2026-24959 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.1.

Vendor: JoomSky
Product: JS Help Desk
Published: Feb 20, 2026
Source: NVD
CVE-2026-24955 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Whizz Plugins whizz-plugins allows Reflected XSS.This issue affects Whizz Plugins: from n/a through <= 1.9.

Vendor: fox-themes
Product: Whizz Plugins
Published: Feb 20, 2026
Source: NVD