Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,604
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,801 - 10,820 of 13,241 CVEs
CVE-2026-21535 HIGH - 8.2

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

Vendor: microsoft
Product: teams
Published: Feb 19, 2026
Source: NVD
CVE-2026-27206 HIGH - 8.1

Zumba Json Serializer is a library to serialize PHP variables in JSON format. In versions 3.2.2 and below, the library allows deserialization of PHP objects from JSON using a special @type field. The deserializer instantiates any class specified in the @type field without restriction. When processin...

Vendor: composer
Product: zumba/json-serializer
Published: Feb 19, 2026
Source: GitHub
CVE-2026-27343 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VanKarWai Airtifact airtifact allows PHP Local File Inclusion.This issue affects Airtifact: from n/a through <= 1.2.91.

Vendor: VanKarWai
Product: Airtifact
Published: Feb 19, 2026
Source: NVD
CVE-2026-27114 HIGH - 7.5

NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.

Vendor: M2Team
Product: NanaZip
Published: Feb 19, 2026
Source: NVD
CVE-2026-26286 HIGH - 8.5

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions prior to 1.16.0, a Server-Side Request Forgery (SSRF) vulnerability in the asset download endpoint allows...

Vendor: SillyTavern
Product: SillyTavern
Published: Feb 19, 2026
Source: NVD
CVE-2026-27193 HIGH - 5.3

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, all HTTP request headers are stored in the session cookie, which is signed but not encrypted, exposing internal proxy/gateway headers to clients. The OAuth service ...

Vendor: npm
Product: @feathersjs/authentication-oauth
Published: Feb 19, 2026
Source: GitHub
CVE-2026-27192 HIGH - 8.1

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, origin validation uses startsWith() for comparison, allowing attackers to bypass the check by registering a domain that shares a common prefix with an allowed origi...

Vendor: npm
Product: @feathersjs/authentication-oauth
Published: Feb 19, 2026
Source: GitHub
CVE-2026-27191 HIGH - 6.1

Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.39 and below the redirect query parameter is appended to the base origin without validation, allowing attackers to steal access tokens via URL authority injection. This leads to ful...

Vendor: npm
Product: @feathersjs/authentication-oauth
Published: Feb 19, 2026
Source: GitHub
CVE-2026-27190 HIGH - 8.1

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process implementation. This vulnerability is fixed in 2.6.8.

Vendor: rust
Product: deno
Published: Feb 19, 2026
Source: GitHub
CVE-2026-27198 HIGH - 8.8

Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based authorization during account creation. Although the system validates that the specified role exists, it does not verify whether the current user has su...

Vendor: composer
Product: getformwork/formwork
Published: Feb 19, 2026
Source: GitHub
CVE-2026-27196 HIGH - 8.1

Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which allows authenticated users with field management permissions to inject malicious JavaScript that execu...

Vendor: composer
Product: statamic/cms
Published: Feb 19, 2026
Source: GitHub
CVE-2026-27194 HIGH - 9.8

D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. This issue ha...

Vendor: pip
Product: dtale
Published: Feb 19, 2026
Source: GitHub
CVE-2026-27203 HIGH - 8.3

eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell APIs. All versions are vulnerable to Environment Variable Injection through the updateEnvFile function. The ebay_set_user_tokens tool allows updating the .env file with new to...

Vendor: npm
Product: ebay-mcp
Published: Feb 19, 2026
Source: GitHub
CVE-2026-26202 HIGH - 7.5

Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a font data chunk in the `create-font-variant` RPC endpoint, resulting in the file co...

Vendor: penpot
Product: penpot
Published: Feb 19, 2026
Source: NVD
CVE-2026-26200 HIGH - 7.8

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on t...

Vendor: HDFGroup
Product: hdf5
Published: Feb 19, 2026
Source: NVD
CVE-2026-26193 HIGH - 7.3

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.44, aanually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded into an iFrame with a sandbox that has `allow-scripts...

Vendor: open-webui
Product: open-webui
Published: Feb 19, 2026
Source: NVD
CVE-2026-26192 HIGH - 7.3

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.7.0, aanually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter a code path that treats document contents as HTML,...

Vendor: open-webui
Product: open-webui
Published: Feb 19, 2026
Source: NVD
CVE-2026-27475 HIGH - 8.1

SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterator, which accept serialized data. An attacker who can place malicious serialized content (a pre-condition requiring prior access or another vulnerability) can trigger arbitrary obj...

Vendor: SPIP
Product: SPIP
Published: Feb 19, 2026
Source: NVD
CVE-2026-26337 HIGH - 8.2

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.

Vendor: Hyland
Product: Alfresco Transformation Service (Enterprise), Alfresco Community (Transform Core)
Published: Feb 19, 2026
Source: NVD
CVE-2026-2232 HIGH - 7.5

The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 4.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on th...

Published: Feb 19, 2026
Source: NVD