Total CVEs

140,426

Critical Severity

3,747

High Severity

13,550

Last 7 Days

1,491
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 11,121 - 11,140 of 13,246 CVEs
CVE-2026-20606 HIGH - 7.1

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to bypass certain Privacy preferences.

Vendor: Apple
Product: macOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-1669 HIGH - 7.1

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references.

Vendor: pip
Product: keras
Published: Feb 11, 2026
Source: NVD
CVE-2025-46290 HIGH - 7.5

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4. A remote attacker may be able to cause a denial-of-service.

Vendor: Apple
Product: macOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-26029 HIGH - 7.5

sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability exists in sf-mcp-server due to unsafe use of child_process.exec when constructing Salesforce CLI commands with user-controlled input. Successful exploitation allows attackers to exec...

Vendor: akutishevsky
Product: sf-mcp-server
Published: Feb 11, 2026
Source: NVD
CVE-2024-50619 HIGH - 8.8

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account ...

Vendor: cipplanner
Product: cipace
Published: Feb 11, 2026
Source: NVD
CVE-2024-50617 HIGH - 7.5

Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieval...

Vendor: cipplanner
Product: cipace
Published: Feb 11, 2026
Source: NVD
CVE-2026-26158 HIGH - 7.0

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to priv...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6
Published: Feb 11, 2026
Source: NVD
CVE-2026-26157 HIGH - 7.0

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially e...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 6
Published: Feb 11, 2026
Source: NVD
CVE-2026-25999 HIGH - 7.1

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or deletion of metadata for any tenant. By sending a crafted request to the /resetMemoryCache endpoint, an...

Vendor: Aiven-Open
Product: klaw
Published: Feb 11, 2026
Source: NVD
CVE-2026-25924 HIGH - 8.4

Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application correctly hides the plugin installation interface wh...

Vendor: kanboard
Product: kanboard
Published: Feb 11, 2026
Source: NVD
CVE-2025-64487 HIGH - 7.6

Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between user and group membership management endpoints. This vulnerability is fixed in 1.1....

Vendor: outline
Product: outline
Published: Feb 11, 2026
Source: NVD
CVE-2024-50620 HIGH - 8.8

Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce before 9.17. An authorized user can upload executable files when inserting images in the rich text editor, and upload executable files when uploading file...

Published: Feb 11, 2026
Source: NVD
CVE-2020-37215 HIGH - 7.5

MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the 'User Name and Regi...

Vendor: Top Password Software
Product: MSN Password Recovery
Published: Feb 11, 2026
Source: NVD
CVE-2020-37214 HIGH - 7.5

Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path parameter. Attackers can exploit the path parameter in /admin/voyager-assets to read arbitrary files like /etc/passwd and .env configuration files.

Vendor: The Control Group
Product: Voyager
Published: Feb 11, 2026
Source: NVD
CVE-2020-37213 HIGH - 7.5

TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized buffer in the license key field. Attackers can generate a 6000-byte payload and paste it into the activation field to trigger an application crash.

Vendor: DigitalVolcano Software
Product: TextCrawler Pro
Published: Feb 11, 2026
Source: NVD
CVE-2020-37212 HIGH - 7.5

SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

Vendor: Nsasoft
Product: Nsauditor SpotMSN
Published: Feb 11, 2026
Source: NVD
CVE-2020-37211 HIGH - 7.5

SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

Vendor: Nsasoft
Product: Nsauditor SpotIM
Published: Feb 11, 2026
Source: NVD
CVE-2020-37210 HIGH - 7.5

SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

Vendor: Nsasoft
Product: Nsauditor SpotIE
Published: Feb 11, 2026
Source: NVD
CVE-2020-37209 HIGH - 7.5

SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

Vendor: Nsasoft
Product: Nsauditor SpotFTP FTP Password Recovery
Published: Feb 11, 2026
Source: NVD
CVE-2020-37208 HIGH - 7.5

SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash and denial of service.

Vendor: Nsasoft
Product: Nsauditor SpotFTP FTP Password Recovery
Published: Feb 11, 2026
Source: NVD