Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,507
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 11,021 - 11,040 of 13,246 CVEs
CVE-2026-0692 HIGH - 7.5

The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-contro...

Published: Feb 14, 2026
Source: NVD
CVE-2026-24853 HIGH - 8.1

Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the 8080 port, and shows Host/IP is not allowed to connect to Caido on all endpoints. But this is bypassable by injecting a X-Forwarded-Host: 127.0.0.1:8080 header. This vulnerability...

Vendor: caido
Product: caido
Published: Feb 13, 2026
Source: NVD
CVE-2026-1844 HIGH - 7.2

The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 12.4.0.2 due to insufficient input sanitization and output escaping. This makes ...

Published: Feb 13, 2026
Source: NVD
CVE-2026-1841 HIGH - 7.2

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' parameter and the 'pys_landing_page' parameter in all versions up to, and including, 11.2.0 due to insufficient input sanitiza...

Published: Feb 13, 2026
Source: NVD
CVE-2025-70957 HIGH - 7.5

A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises from the handling of external arguments passed to locally executed "get methods." An attacker can inject a constructed Continuation object (an internal TVM type) that is ...

Published: Feb 13, 2026
Source: NVD
CVE-2025-70956 HIGH - 7.5

A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the RUNVM instruction logic (VmState::run_child_vm), which is responsible for initializing child virtual machines. The operation moves critical resources (specifically libraries and l...

Published: Feb 13, 2026
Source: NVD
CVE-2025-70955 HIGH - 7.5

A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems from the improper handling of vmstate and continuation jump instructions, which allow for continuous dynamic tail calls. An attacker can exploit this by crafting a smart contract w...

Published: Feb 13, 2026
Source: NVD
CVE-2025-70954 HIGH - 7.5

A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.06. The issue is located in the execution logic of the INMSGPARAM instruction, where the program fails to validate if a specific pointer is null before accessing it. By sending a m...

Published: Feb 13, 2026
Source: NVD
CVE-2025-70866 HIGH - 8.8

LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider ...

Vendor: lavalite
Product: lavalite
Published: Feb 13, 2026
Source: NVD
CVE-2025-15157 HIGH - 8.8

The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'srm_restore_options_defaults' function in all versions up to, and including, ...

Vendor: starfishwp
Product: Starfish Review Generation & Marketing for WordPress
Published: Feb 13, 2026
Source: NVD
CVE-2026-2441 HIGH - 8.8

Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Vendor: google
Product: chrome
Published: Feb 13, 2026
Source: NVD
CVE-2026-26264 HIGH - 8.1

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a malformed WriteProperty request can trigger a length underflow in the BACnet stack, leading to an out‑of‑bounds read and a crash (DoS). The issue is in wp.c within wp_decode_service_...

Vendor: bacnet-stack
Product: bacnet-stack
Published: Feb 13, 2026
Source: NVD
CVE-2026-26208 HIGH - 7.8

ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. This allows ...

Vendor: Alex4SSB
Product: ADB-Explorer
Published: Feb 13, 2026
Source: NVD
CVE-2026-26187 HIGH - 8.1

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allows authenticated users to read and write files outside their designated storage boundaries. The verifyRelPath function used strings.Has...

Vendor: treeverse
Product: lakeFS
Published: Feb 13, 2026
Source: NVD
CVE-2026-25991 HIGH - 7.7

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerability in the Cookmate recipe import feature of Tandoor Recipes. The application fails to validate the destination URL after...

Vendor: TandoorRecipes
Product: recipes
Published: Feb 13, 2026
Source: NVD
CVE-2026-21878 HIGH - 7.5

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability has been discovered in BACnet Stack's file writing functionality where there is no validation of user-provided file paths, allowing attackers to write files to arbitrary direc...

Vendor: bacnet-stack
Product: bacnet-stack
Published: Feb 13, 2026
Source: NVD
CVE-2026-26268 HIGH - 8.0

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicious agent (ie prompt injection) could write to improperly protected .git settings, including git hooks, which may cause out-of-sandbox RCE next time the...

Vendor: cursor
Product: cursor
Published: Feb 13, 2026
Source: NVD
CVE-2025-70123 HIGH - 7.5

An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Setup Request, violating 3GPP TS 29.244. This places the UPF in an inconsistent state where a subsequent...

Vendor: free5gc
Product: free5gc
Published: Feb 13, 2026
Source: NVD
CVE-2025-70122 HIGH - 7.5

A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in the SDFFilterFields.UnmarshalBinary function (sdf-filter.go) when processing a declared length that ex...

Vendor: free5gc
Product: free5gc
Published: Feb 13, 2026
Source: NVD
CVE-2025-70121 HIGH - 7.5

An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS Registration Request message. The issue occurs in the GetSUCI method (NAS_MobileIdentity5GS.go) when accessing index 5 of ...

Vendor: free5gc
Product: free5gc
Published: Feb 13, 2026
Source: NVD