Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,788
Quick preset (or use dates below)
Clear Filters
Showing 1,161 - 1,180 of 1,477 CVEs
CVE-2026-3193 LOW - 3.1

A vulnerability was detected in Chia Blockchain 2.1.0. Impacted is an unknown function of the file /send_transaction. The manipulation results in cross-site request forgery. The attack may be performed from remote. The attack requires a high level of complexity. The exploitability is considered diff...

Published: Feb 25, 2026
Source: NVD
CVE-2026-3189 LOW - 3.1

A weakness has been identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This vulnerability affects unknown code of the file /api/admin/common/files/download. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be executed remotely. Attacks of ...

Published: Feb 25, 2026
Source: NVD

Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `RSASHA256Algorithm` and `RSASHA1Algorithm` contracts fail to validate PKCS#1 v1.5 padding structure when verifying RSA signatures. The contracts only c...

Vendor: ensdomains
Product: ens-contracts
Published: Feb 25, 2026
Source: NVD

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

Vendor: JetBrains
Product: TeamCity
Published: Feb 25, 2026
Source: NVD

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletio...

Vendor: Grafana
Product: Grafana
Published: Feb 25, 2026
Source: NVD
CVE-2026-3171 LOW - 3.5

A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /queue.php. This manipulation of the argument firstname/lastname causes cross site scripting. The attack is possible to be c...

Vendor: pamzey
Product: patients_waiting_area_queue_management_system
Published: Feb 25, 2026
Source: NVD
CVE-2026-3170 LOW - 2.4

A vulnerability was detected in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected is an unknown function of the file /patient-search.php. The manipulation of the argument First Name/Last Name results in cross site scripting. The attack can be executed remotely....

Vendor: pamzey
Product: patients_waiting_area_queue_management_system
Published: Feb 25, 2026
Source: NVD
CVE-2026-3146 LOW - 3.3

A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The identifier of the patch is d4ce337c...

Vendor: libvips
Product: libvips
Published: Feb 25, 2026
Source: NVD

Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871a14c192d1fb8146cdbc76f29f27c1cf48, the Talishar application lacks Cross-Site Request Forgery (CSRF) protections on critical state-changing endpoints, specifically within `SubmitChat.php` and other game interaction handlers. By fa...

Vendor: Talishar
Product: Talishar
Published: Feb 25, 2026
Source: NVD

Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability to Protection mechanism bypass.

Vendor: Dell
Product: Wyse Management Suite
Published: Feb 24, 2026
Source: NVD
CVE-2026-1229 LOW - 9.8

The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas. ECDH and ECDSA signing relying on this curve are not affected. The bug was fixed in v1.6.3 https://github.com/cloudflar...

Vendor: go
Product: github.com/cloudflare/circl
Published: Feb 24, 2026
Source: NVD

A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Management Page. This manipulation of the argument temn/tp causes path traversal. It is possible to initiate the attack remotely. Th...

Vendor: muyucms
Product: MuYuCMS
Published: Feb 24, 2026
Source: NVD
CVE-2026-3050 LOW - 3.5

A flaw has been found in horilla-opensource horilla up to 1.0.2. Impacted is an unknown function of the file static/assets/js/global.js of the component Leads Module. This manipulation of the argument Notes causes cross site scripting. The attack is possible to be carried out remotely. The exploit h...

Vendor: horilla
Product: horilla
Published: Feb 24, 2026
Source: NVD
CVE-2026-3041 LOW - 2.4

A security vulnerability has been detected in xingfuggz BaykeShop up to 1.3.20. Impacted is an unknown function of the file src/baykeshop/contrib/article/templates/baykeshop/sidebar/custom.html of the component Article Sidebar Module. Such manipulation of the argument sidebar.content leads to cross ...

Published: Feb 23, 2026
Source: NVD

ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds

Vendor: nuget
Product: Magick.NET-Q16-AnyCPU
Published: Feb 23, 2026
Source: NVD
CVE-2026-2974 LOW - 2.5

A vulnerability was identified in AliasVault App up to 0.25.3 on Android/iOS. This vulnerability affects unknown code of the file shared_prefs/aliasvault.xml of the component Backup Handler. The manipulation of the argument accessToken/refreshToken/metadata/key_derivation_params/auth_methods leads t...

Published: Feb 23, 2026
Source: NVD
CVE-2026-2972 LOW - 2.4

A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso-server/src/main/java/openjoe/smart/sso/server/controller/admin/UserController.java of the component Role Edit Page. Executing a manipulation can lead to cross site scripting. The ...

Vendor: a466350665
Product: smart-sso
Published: Feb 23, 2026
Source: NVD
CVE-2026-2968 LOW - 3.7

A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of cryptographic signature. The attack may be la...

Vendor: cesanta
Product: mongoose
Published: Feb 23, 2026
Source: NVD
CVE-2026-2967 LOW - 3.7

A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to improper verification of source of a communication channel. The attack may be initiated ...

Vendor: cesanta
Product: mongoose
Published: Feb 23, 2026
Source: NVD
CVE-2026-2966 LOW - 3.7

A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently random values. The attack can be launched re...

Vendor: cesanta
Product: mongoose
Published: Feb 23, 2026
Source: NVD