Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,514
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 10,941 - 10,960 of 13,241 CVEs
CVE-2026-26119 HIGH - 8.8

Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Vendor: microsoft
Product: windows_admin_center
Published: Feb 17, 2026
Source: NVD
CVE-2025-13689 HIGH - 8.8

IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to sensitive information due to unrestricted file uploads.

Vendor: IBM
Product: DataStage on Cloud Pak
Published: Feb 17, 2026
Source: NVD
CVE-2026-2629 HIGH - 7.3

A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is the function Promise of the file lib/tts-providers/mac-os.js of the component TTS Provider. This manipulation of the argument phrase causes os command injection. It is possible to ...

Published: Feb 17, 2026
Source: NVD
CVE-2026-2627 HIGH - 7.8

A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Program Files\Common Files\microsoft shared\ink\HID.dll of the component Backup/Restore. The manipulation results in link following. The attack needs to be approached locally. The ex...

Published: Feb 17, 2026
Source: NVD
CVE-2025-33088 HIGH - 7.4

IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to escalate their privileges due to incorrect file permissions for critical resources.

Vendor: IBM
Product: Concert
Published: Feb 17, 2026
Source: NVD
CVE-2026-26325 HIGH - 7.2

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `system.run` handler could cause allowlist/approval evaluation to be performed on one command while executing a different argv. This only impacts deployments that use the...

Vendor: npm
Product: openclaw
Published: Feb 17, 2026
Source: GitHub
CVE-2026-26324 HIGH - 7.5

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full-form IPv4-mapped IPv6 literals such as `0:0:0:0:0:ffff:7f00:1` (which is `127.0.0.1`). This could allow requests that should be blocked (loopback / private network / link-loc...

Vendor: npm
Product: openclaw
Published: Feb 17, 2026
Source: GitHub
CVE-2026-26322 HIGH - 7.6

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient restrictions, which could cause the OpenClaw host to attempt outbound WebSocket connections to user-specified targets. This requires the ability to invo...

Vendor: npm
Product: openclaw
Published: Feb 17, 2026
Source: GitHub
CVE-2026-26321 HIGH - 7.5

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendMediaFeishu` to treat attacker-controlled `mediaUrl` values as local filesystem paths and read them directly. If an attacker can influence tool calls (directly or via prompt injecti...

Vendor: npm
Product: openclaw
Published: Feb 17, 2026
Source: GitHub
CVE-2026-26320 HIGH - 6.5

OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw://agent` deep links without an unattended `key`, the app shows a confirmation dialog that previously displayed only the first 240 characters of the message, but executed the full ...

Vendor: npm
Product: openclaw
Published: Feb 17, 2026
Source: GitHub
CVE-2026-26319 HIGH - 7.5

OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept unsigned inbound webhook requests when telnyx.publicKey is not configured, enabling unauthenticated callers to forge Telnyx events. Telnyx webhooks are ex...

Vendor: npm
Product: openclaw
Published: Feb 17, 2026
Source: GitHub
CVE-2026-26316 HIGH - 7.5

OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authenticated based only on the TCP peer address being loopback (`127.0.0.1`, `::1`, `::ffff:127.0.0.1`) even when the configured webhook secret was missing or i...

Vendor: npm
Product: openclaw
Published: Feb 17, 2026
Source: GitHub
CVE-2026-26278 HIGH - 7.5

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to ...

Vendor: npm
Product: fast-xml-parser
Published: Feb 17, 2026
Source: GitHub
CVE-2026-26275 HIGH - 7.5

httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to version 0.0.23 where Digest header verification could incorrectly succeed due to misuse of Rust's `matches!` macro. Specifically, the comparison `if matches!(digest, _expected_dig...

Vendor: rust
Product: httpsig-hyper
Published: Feb 17, 2026
Source: GitHub
CVE-2026-26267 HIGH - 7.5

soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` macro contains a bug in how it wires up function calls. `#[contractimpl]` generates code that uses `MyContract::value()` style calls even when it's processing the trait version....

Vendor: rust
Product: soroban-sdk-macros
Published: Feb 17, 2026
Source: GitHub
CVE-2026-26201 HIGH - 7.5

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are accessed without consistent synchronization across goroutines. Under concurrent activity, Go runtime can trigger `fatal error: concurrent map read and map write`, causing C2 process cras...

Vendor: go
Product: github.com/jm33-m0/emp3r0r/core
Published: Feb 17, 2026
Source: GitHub
CVE-2026-2621 HIGH - 7.3

A security vulnerability has been detected in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0. This affects an unknown part of the file /SISReport/WebReport20/Proxy/AsyncTreeProxy.aspx. The manipulation of the argument PGUID leads to sql injection. The attack can be initiated remo...

Published: Feb 17, 2026
Source: NVD
CVE-2026-23595 HIGH - 8.8

An authentication bypass in the application API allows an unauthorized administrative account to be created. A remote attacker could exploit this vulnerability to create privileged user accounts. Successful exploitation could allow an attacker to gain administrative access, modify system configurati...

Vendor: Hewlett Packard Enterprise (HPE)
Product: HPE Aruba Networking Private 5G Core
Published: Feb 17, 2026
Source: NVD
CVE-2025-13691 HIGH - 8.1

IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be used to impersonate other users in the system.

Vendor: IBM
Product: DataStage on Cloud Pak for Data
Published: Feb 17, 2026
Source: NVD
CVE-2026-2620 HIGH - 7.3

A weakness has been identified in Huace Monitoring and Early Warning System 2.2. Affected by this issue is some unknown functionality of the file /Web/SysManage/ProjectRole.aspx. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The ...

Published: Feb 17, 2026
Source: NVD