Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,517
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,921 - 10,940 of 13,241 CVEs
CVE-2025-33245 HIGH - 8.0

NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: NeMo Framework
Published: Feb 18, 2026
Source: NVD
CVE-2025-33243 HIGH - 7.8

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: NeMo Framework
Published: Feb 18, 2026
Source: NVD
CVE-2025-33241 HIGH - 7.8

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: NeMo Framework
Published: Feb 18, 2026
Source: NVD
CVE-2025-33240 HIGH - 7.8

NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: Megatron-Bridge
Published: Feb 18, 2026
Source: NVD
CVE-2025-33239 HIGH - 7.8

NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: Megatron-Bridge
Published: Feb 18, 2026
Source: NVD
CVE-2025-33236 HIGH - 7.8

NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: NeMo Framework
Published: Feb 18, 2026
Source: NVD
CVE-2026-2495 HIGH - 7.5

The WPNakama โ€“ Team and multi-Client Collaboration, Editorial and Project Management plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the '/wp-json/WPNakama/v1/boards' REST API endpoint in all versions up to, and including, 0.6.5. This is due to in...

Published: Feb 18, 2026
Source: NVD
CVE-2026-2296 HIGH - 7.2

The Product Addons for Woocommerce โ€“ Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 3.1.0. This is due to insufficient input validation of the 'operator' field in conditional logic rules within the evalCondition...

Published: Feb 18, 2026
Source: NVD
CVE-2026-2019 HIGH - 7.2

The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.1.21. This is due to insufficient input validation on the 'Assign page' field which is passed directly to the eval() function. This makes it possible for authent...

Published: Feb 18, 2026
Source: NVD
CVE-2026-1368 HIGH - 7.5

The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.

Published: Feb 18, 2026
Source: NVD
CVE-2026-2576 HIGH - 7.5

The Business Directory Plugin โ€“ Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'payment' parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient p...

Published: Feb 18, 2026
Source: NVD
CVE-2026-1931 HIGH - 7.2

The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all versions up to, and including, 0.32.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for unauthenticated attac...

Published: Feb 18, 2026
Source: NVD
CVE-2026-1714 HIGH - 8.6

The ShopLentor โ€“ WooCommerce Builder for Elementor & Gutenberg +21 Modules โ€“ All in One Solution plugin for WordPress is vulnerable to Email Relay Abuse in all versions up to, and including, 3.3.2. This is due to the lack of validation on the 'send_to', 'product_title', '...

Published: Feb 18, 2026
Source: NVD
CVE-2026-26960 HIGH - 7.1

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. ...

Vendor: npm
Product: tar
Published: Feb 18, 2026
Source: GitHub
CVE-2026-26317 HIGH - 7.1

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding reduces remote exposure but does not prevent browser-initiated requests from malicious origins. A mali...

Vendor: npm
Product: openclaw
Published: Feb 18, 2026
Source: GitHub
CVE-2026-26323 HIGH - 8.8

OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts`. The issue affects contributors/maintainers (or CI) who run `bun scripts/update-clawtributors.ts` in a source checkout that contains a mali...

Vendor: npm
Product: openclaw
Published: Feb 18, 2026
Source: GitHub
CVE-2026-26329 HIGH - 6.5

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, authenticated attackers can read arbitrary files from the Gateway host by supplying absolute paths or path traversal sequences to the browser tool's `upload` action. The server passed these paths to Playwright's `setInputFile...

Vendor: npm
Product: openclaw
Published: Feb 18, 2026
Source: GitHub
CVE-2026-26327 HIGH - 6.5

OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`, `tailnetDns`, `gatewayPort`, and `gatewayTlsSha256`. TXT records are unauthenticated. Prior to version 2026.2.14, some clients treated TXT values as authoritative routing/pinning i...

Vendor: npm
Product: openclaw
Published: Feb 18, 2026
Source: GitHub
CVE-2026-23599 HIGH - 7.8

A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges.

Vendor: Hewlett Packard Enterprise (HPE)
Product: HPE Aruba Networking ClearPass Policy Manager
Published: Feb 18, 2026
Source: NVD
CVE-2026-22048 HIGH - 7.1

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptible to a Server-Side Request Forgery (SSRF) vulnerability. Successful exploit could allow an authenticat...

Vendor: NETAPP
Product: StorageGRID (formerly StorageGRID Webscale)
Published: Feb 18, 2026
Source: NVD