Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
Showing 1,201 - 1,220 of 1,477 CVEs
CVE-2026-2825 LOW - 3.5

A vulnerability has been found in rachelos WeRSS we-mp-rss up to 1.4.8. This impacts the function fix_html of the file tools/fix.py of the component Article Module. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the p...

Published: Feb 20, 2026
Source: NVD

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.634.6 and below allow non-admin users to obtain Slack OAuth client secrets, which should only be accessible to workspace administrators. The GET /api/w/{workspace}/workspaces/get_se...

Vendor: windmill-labs
Product: windmill
Published: Feb 20, 2026
Source: NVD

Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be considered valid during verification even if the provided timestamp would mean the issuing certificate shoul...

Vendor: sigstore
Product: cosign
Published: Feb 19, 2026
Source: NVD

Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache Containing Sensitive Information vulnerability. The logic instructs caches not to cache t...

Vendor: pip
Product: flask
Published: Feb 19, 2026
Source: GitHub

Missing Authorization vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real 3D FlipBook: from n/a through <= 4.16.4.

Vendor: creativeinteractivemedia
Product: Real 3D FlipBook
Published: Feb 19, 2026
Source: NVD
CVE-2026-2733 LOW - 3.8

A flaw was identified in the Docker v2 authentication endpoint of Keycloak, where tokens continue to be issued even after a Docker registry client has been administratively disabled. This means that turning the client “Enabled” setting to OFF does not fully prevent access. As a result, previously va...

Vendor: maven
Product: org.keycloak:keycloak-services
Published: Feb 19, 2026
Source: NVD
CVE-2026-2709 LOW - 3.5

A flaw has been found in busy up to 2.5.5. The affected element is an unknown function of the file source-code/busy-master/src/server/app.js of the component Callback Handler. Executing a manipulation of the argument state can lead to open redirect. It is possible to launch the attack remotely. The ...

Published: Feb 19, 2026
Source: NVD
CVE-2026-2703 LOW - 3.3

A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::decode_base64 of the file source/detail/cryptography/base64.cpp of the component Encrypted XLSX File Parser. Executing a manipulation can lead to off-by-one. The attack requires local access. Th...

Published: Feb 19, 2026
Source: NVD
CVE-2026-2702 LOW - 3.1

A security flaw has been discovered in Beetel 777VR1 up to 01.00.09. This issue affects some unknown processing of the component WPA2 PSK. Performing a manipulation results in hard-coded credentials. The attacker must have access to the local network to execute the attack. The complexity of an attac...

Published: Feb 19, 2026
Source: NVD

The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action in the wa_order_number_save_number_field function. This makes it possible for...

Vendor: walterpinem
Product: OneClick Chat to Order
Published: Feb 19, 2026
Source: NVD

filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographic primitives. In versions 1.1.0 and earlier, MultiScalarMult produces invalid results or undefined behavior if the receiver is not the identity point. If (*Point).MultiScalarMult i...

Vendor: go
Product: filippo.io/edwards25519
Published: Feb 18, 2026
Source: GitHub

Rejected reason: Further research determined the issue is an external dependency vulnerability.

Vendor: go
Product: github.com/refraction-networking/utls
Published: Feb 18, 2026
Source: GitHub

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for the handshake. Versions 1.6.0 through 1.8.0 contain a fingerprint mismatch with Chrome when using GREASE ECH, related to cipher suite selection. When Chrome selects the preferred cip...

Vendor: go
Product: github.com/refraction-networking/utls
Published: Feb 18, 2026
Source: GitHub
CVE-2025-8860 LOW - 3.3

A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocation...

Published: Feb 18, 2026
Source: NVD

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free cond...

Published: Feb 18, 2026
Source: NVD
CVE-2026-2662 LOW - 3.3

A weakness has been identified in FascinatedBox lily up to 2.3. This vulnerability affects the function count_transforms of the file src/lily_emitter.c. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could b...

Vendor: lily-lang
Product: lily
Published: Feb 18, 2026
Source: NVD
CVE-2026-2661 LOW - 3.3

A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be use...

Vendor: squirrel-lang
Product: squirrel
Published: Feb 18, 2026
Source: NVD
CVE-2026-2660 LOW - 3.3

A vulnerability was identified in FascinatedBox lily up to 2.3. Affected by this issue is the function shorthash_for_name of the file src/lily_symtab.c. The manipulation leads to use after free. Local access is required to approach this attack. The exploit is publicly available and might be used. Th...

Vendor: lily-lang
Product: lily
Published: Feb 18, 2026
Source: NVD
CVE-2026-2659 LOW - 3.3

A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation of the argument _target_stack can lead to out-of-bounds read. It is possible to launch the attack on...

Vendor: squirrel-lang
Product: squirrel
Published: Feb 18, 2026
Source: NVD

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.5, 9.3.7, and 9.2.9, and Splunk Cloud Platform versions below 10.1.2507.0, 10.0.2503.9, 9.3.2411.112, and 9.3.2408.122, a low-privileged user who does not hold the "admin" or "power" Splunk roles could bypass the SPL safegua...

Vendor: Splunk
Product: Splunk Enterprise, Splunk Cloud Platform
Published: Feb 18, 2026
Source: NVD