Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,501
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 11,081 - 11,100 of 13,246 CVEs
CVE-2025-61879 HIGH - 7.7

In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.

Vendor: infoblox
Product: nios
Published: Feb 12, 2026
Source: NVD
CVE-2025-54756 HIGH - 8.4

BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest release fixes this issue for new installations; users of old installations are encouraged to change all...

Vendor: BrightSign
Product: BrightSign OS series 4 players, BrightSign OS series 5 players
Published: Feb 12, 2026
Source: NVD

CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validation in the transaction API. The issue has been fixed in version 1.2.3. If upgrading is not immediately possible, restrict API access to trusted networks ...

Vendor: npm
Product: cedipay-core
Published: Feb 12, 2026
Source: GitHub
CVE-2026-26217 HIGH - 8.6

Crawl4AI versions prior to 0.8.0 contain a local file inclusion vulnerability in the Docker API deployment. The /execute_js, /screenshot, /pdf, and /html endpoints accept file:// URLs, allowing unauthenticated remote attackers to read arbitrary files from the server filesystem. An attacker can acces...

Vendor: unclecode
Product: Crawl4AI
Published: Feb 12, 2026
Source: NVD
CVE-2026-26214 HIGH - 7.4

Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which...

Vendor: Xiaomi Technology Co., Ltd.
Product: Galaxy FDS Android SDK
Published: Feb 12, 2026
Source: NVD
CVE-2025-70886 HIGH - 7.5

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

Vendor: halo
Product: halo
Published: Feb 12, 2026
Source: NVD
CVE-2026-25949 HIGH - 7.5

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then s...

Vendor: go
Product: github.com/traefik/traefik/v3
Published: Feb 12, 2026
Source: GitHub

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split index (for finding .php) on a lowercased copy of the request path but applies that byte index to the or...

Vendor: go
Product: github.com/dunglas/frankenphp
Published: Feb 12, 2026
Source: GitHub

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potential...

Vendor: go
Product: github.com/dunglas/frankenphp
Published: Feb 12, 2026
Source: GitHub
CVE-2026-1104 HIGH - 8.8

The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to unauthorized backup creation and download due to a missing capability check on REST API endpoints in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Con...

Published: Feb 12, 2026
Source: NVD
CVE-2023-31313 HIGH - 7.2

An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.

Vendor: AMD
Product: AMD Instinct™ MI210, AMD Instinct™ MI250
Published: Feb 12, 2026
Source: NVD
CVE-2026-2007 HIGH - 8.2

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and ...

Published: Feb 12, 2026
Source: NVD
CVE-2026-2006 HIGH - 8.8

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 1...

Published: Feb 12, 2026
Source: NVD
CVE-2026-2005 HIGH - 8.8

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Published: Feb 12, 2026
Source: NVD
CVE-2026-2004 HIGH - 8.8

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Published: Feb 12, 2026
Source: NVD
CVE-2026-1320 HIGH - 7.2

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' HTTP header in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for ...

Published: Feb 12, 2026
Source: NVD
CVE-2025-13002 HIGH - 8.2

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Cross-Site Scripting (XSS).This issue affects E-Commerce Package: through 27112025.

Vendor: Farktor Software E-Commerce Services Inc.
Product: E-Commerce Package
Published: Feb 12, 2026
Source: NVD
CVE-2026-1316 HIGH - 7.2

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].href' parameter in all versions up to, and including, 5.97.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attack...

Published: Feb 12, 2026
Source: NVD
CVE-2026-25676 HIGH - 7.8

The installer of M-Track Duo HD version 1.0.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrator privileges.

Vendor: M-Audio
Product: M-Track Duo HD
Published: Feb 12, 2026
Source: NVD
CVE-2026-26235 HIGH - 7.5

JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the server. Attackers can send a single POST request to trigger the server reboot without requiring any authentication.

Vendor: ALBRECHT JUNG GMBH & CO. KG
Product: JUNG Smart Visu Server
Published: Feb 12, 2026
Source: NVD