Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,599
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 10,821 - 10,840 of 13,241 CVEs
CVE-2026-26336 HIGH - 7.5

Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via the "/share/page/resource/" endpoint, thus leading to the disclosure of sensitive configuration files.

Vendor: Hyland
Product: Alfresco Enterprise, Alfresco Community
Published: Feb 19, 2026
Source: NVD
CVE-2026-25998 HIGH - 7.5

strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the database (private keys, EAP secrets), strongMan encrypts the corresponding database fields. So far it used AES in CTR mode with a global database key. Together with an initialization ve...

Vendor: strongswan
Product: strongMan
Published: Feb 19, 2026
Source: NVD
CVE-2026-1581 HIGH - 7.5

The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all versions up to, and including, 2.4.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

Published: Feb 19, 2026
Source: NVD
CVE-2026-25940 HIGH - 8.1

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following property, a user can i...

Vendor: parallax
Product: jsPDF
Published: Feb 19, 2026
Source: NVD
CVE-2026-25755 HIGH - 8.1

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the JavaScript string delimiter, an attacker can execute malicious ...

Vendor: parallax
Product: jsPDF
Published: Feb 19, 2026
Source: NVD
CVE-2026-25535 HIGH - 7.5

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of service. If given the possibility to pass unsanitized image data or URLs to the `addImage` method, a user can provide a harmful GIF file that results in...

Vendor: parallax
Product: jsPDF
Published: Feb 19, 2026
Source: NVD
CVE-2019-25422 HIGH - 7.2

Comodo Dome Firewall 2.7.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through the vpnfw endpoint. Attackers can submit POST requests with script payloads in the target parameter for reflected XSS or the remark parameter for stored XSS to execute ar...

Vendor: Cdome
Product: Comodo Dome Firewall
Published: Feb 19, 2026
Source: NVD
CVE-2019-25419 HIGH - 7.2

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the schedule endpoint. Attackers can submit POST requests with JavaScript payloads in the SCHNAME parameter to execute arbitrary code in ad...

Vendor: Cdome
Product: Comodo Dome Firewall
Published: Feb 19, 2026
Source: NVD
CVE-2019-25405 HIGH - 7.2

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the newLicense parameter. Attackers can send POST requests to the license activation endpoint with script payloads in the newLicense field ...

Vendor: Cdome
Product: Comodo Dome Firewall
Published: Feb 19, 2026
Source: NVD
CVE-2025-9062 HIGH - 7.3

Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection.This issue affects Envanty: before 1.0.6.Β Β  NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerabi...

Published: Feb 19, 2026
Source: NVD
CVE-2025-15561 HIGH - 7.8

An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be namedΒ  WTWatch.exe and dropped in the C:\ProgramData\wta\ClientExe directory, which is writable by "Everyone". The ...

Vendor: NesterSoft Inc.
Product: WorkTime (on-prem/cloud)
Published: Feb 19, 2026
Source: NVD
CVE-2025-15560 HIGH - 8.8

An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, attackers are able to retrieve all data from the database backend. If the MSSQL backend is used the attacker c...

Vendor: NesterSoft Inc.
Product: WorkTime (on-prem/cloud)
Published: Feb 19, 2026
Source: NVD
CVE-2026-22267 HIGH - 8.1

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vendor: Dell
Product: PowerProtect Data Manager
Published: Feb 19, 2026
Source: NVD
CVE-2026-27052 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in villatheme Sales Countdown Timer for WooCommerce and WordPress sctv-sales-countdown-timer allows PHP Local File Inclusion.This issue affects Sales Countdown Timer for Wo...

Vendor: villatheme
Product: Sales Countdown Timer for WooCommerce and WordPress
Published: Feb 19, 2026
Source: NVD
CVE-2026-26362 HIGH - 8.1

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized modification of critical system files.

Vendor: Dell
Product: Unisphere for PowerMax, PowerMax
Published: Feb 19, 2026
Source: NVD
CVE-2026-26360 HIGH - 8.1

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to delete arbitrary files.

Vendor: Dell
Product: Unisphere for PowerMax, PowerMax
Published: Feb 19, 2026
Source: NVD
CVE-2026-26359 HIGH - 8.8

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files.

Vendor: Dell
Product: Unisphere for PowerMax, PowerMax
Published: Feb 19, 2026
Source: NVD
CVE-2026-26358 HIGH - 8.8

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Vendor: Dell
Product: Unisphere for PowerMax, PowerMax
Published: Feb 19, 2026
Source: NVD
CVE-2026-25418 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bitpressadmin Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.21.10.

Vendor: bitpressadmin
Product: Bit Form
Published: Feb 19, 2026
Source: NVD
CVE-2026-25378 HIGH - 7.6

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Blind SQL Injection.This issue affects Nelio AB Testing: from n/a through <= 8.2.4.

Vendor: Nelio Software
Product: Nelio AB Testing
Published: Feb 19, 2026
Source: NVD