Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,518
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 10,901 - 10,920 of 13,241 CVEs
CVE-2026-24708 HIGH - 8.2

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in...

Vendor: OpenStack
Product: Nova
Published: Feb 18, 2026
Source: NVD
CVE-2025-70151 HIGH - 8.8

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied fil...

Vendor: fabian
Product: scholars_tracking_system
Published: Feb 18, 2026
Source: NVD
CVE-2025-70148 HIGH - 7.5

Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (I...

Vendor: codeastro
Product: membership_management_system
Published: Feb 18, 2026
Source: NVD
CVE-2026-27487 HIGH - 7.6

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below, when using macOS, the Claude CLI keychain credential refresh path constructed a shell command to write the updated JSON blob into Keychain via security add-generic-password -w .... Because OAuth tokens are user-controlled data, th...

Vendor: npm
Product: openclaw
Published: Feb 18, 2026
Source: GitHub
CVE-2026-2507 HIGH - 7.5

When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Published: Feb 18, 2026
Source: NVD
CVE-2025-70147 HIGH - 7.5

Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session.

Vendor: projectworlds
Product: online_time_table_generator
Published: Feb 18, 2026
Source: NVD

opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) ...

Vendor: go
Product: github.com/open-policy-agent/opa-envoy-plugin
Published: Feb 18, 2026
Source: GitHub
CVE-2026-27099 HIGH - 8.0

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Confi...

Vendor: Jenkins Project
Product: Jenkins
Published: Feb 18, 2026
Source: NVD
CVE-2026-1426 HIGH - 8.8

The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrusted input in the shortcode_check function within the Live Composer compatibility layer. This makes it possible for authenticated att...

Published: Feb 18, 2026
Source: NVD
CVE-2025-61982 HIGH - 7.8

An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A specially crafted OpenFOAM simulation file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

Vendor: OpenCFD
Product: OpenFOAM
Published: Feb 18, 2026
Source: NVD
CVE-2025-60038 HIGH - 7.8

A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which...

Vendor: Bosch Rexroth
Product: IndraWorks
Published: Feb 18, 2026
Source: NVD
CVE-2025-60037 HIGH - 7.8

A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Exploitation requires user interaction, specifically opening a specially crafted file, which...

Vendor: Bosch Rexroth
Product: IndraWorks
Published: Feb 18, 2026
Source: NVD
CVE-2025-60036 HIGH - 7.8

A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. Ex...

Vendor: Bosch Rexroth
Product: IndraWorks, UA.Testclient
Published: Feb 18, 2026
Source: NVD
CVE-2025-60035 HIGH - 7.8

A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions prior to 15V24 are affected. This flaw allows an attacker to execute arbitrary code on the user's system by parsing a manipulated file containing malicious serialized data. E...

Vendor: Bosch Rexroth
Product: IndraWorks
Published: Feb 18, 2026
Source: NVD
CVE-2025-33253 HIGH - 7.8

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: NeMo Framework
Published: Feb 18, 2026
Source: NVD
CVE-2025-33252 HIGH - 7.8

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: NeMo Framework
Published: Feb 18, 2026
Source: NVD
CVE-2025-33251 HIGH - 7.8

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: NeMo Framework
Published: Feb 18, 2026
Source: NVD
CVE-2025-33250 HIGH - 7.8

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Vendor: NVIDIA
Product: NeMo Framework
Published: Feb 18, 2026
Source: NVD
CVE-2025-33249 HIGH - 7.8

NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and ...

Vendor: NVIDIA
Product: NeMo Framework
Published: Feb 18, 2026
Source: NVD
CVE-2025-33246 HIGH - 7.8

NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection by supplying crafted input to a configuration parameter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data...

Vendor: NVIDIA
Product: NeMo Framework
Published: Feb 18, 2026
Source: NVD