Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
Showing 1,221 - 1,240 of 1,477 CVEs
CVE-2026-2657 LOW - 3.3

A vulnerability has been found in wren-lang wren up to 0.4.0. This impacts the function printError of the file src/vm/wren_compiler.c of the component Error Message Handler. Such manipulation leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed...

Vendor: wren
Product: wren
Published: Feb 18, 2026
Source: NVD
CVE-2026-2656 LOW - 2.5

A flaw has been found in ChaiScript up to 6.1.0. This affects the function chaiscript::Type_Info::bare_equal of the file include/chaiscript/dispatchkit/type_info.hpp. This manipulation causes use after free. The attack requires local access. The attack's complexity is rated as high. The exploit...

Vendor: chaiscript
Product: chaiscript
Published: Feb 18, 2026
Source: NVD
CVE-2026-2655 LOW - 2.5

A vulnerability was detected in ChaiScript up to 6.1.0. The impacted element is the function chaiscript::str_less::operator of the file include/chaiscript/chaiscript_defines.hpp. The manipulation results in use after free. The attack requires a local approach. The attack requires a high level of com...

Vendor: chaiscript
Product: chaiscript
Published: Feb 18, 2026
Source: NVD
CVE-2026-1582 LOW - 3.7

The WP All Export plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.14 via the export download endpoint. This is due to a PHP type juggling vulnerability in the security token comparison which uses loose comparison (==) instead of strict c...

Published: Feb 18, 2026
Source: NVD
CVE-2026-2419 LOW - 2.7

The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal sequences to bypass ...

Published: Feb 18, 2026
Source: NVD
CVE-2026-1831 LOW - 2.7

The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and activation due to missing capability checks on the 'yaymail_install_yaysmtp' AJAX action and `/yaymail/v1/addons/activate` REST endpoint in all versions up to, and includin...

Published: Feb 18, 2026
Source: NVD
CVE-2026-2644 LOW - 3.3

A weakness has been identified in niklasso minisat up to 2.2.0. This issue affects the function Solver::value in the library core/SolverTypes.h of the component DIMACS File Parser. This manipulation of the argument variable index with the input 2147483648 causes out-of-bounds read. The attack needs ...

Vendor: minisat
Product: minisat
Published: Feb 18, 2026
Source: NVD
CVE-2026-2642 LOW - 3.3

A security vulnerability has been detected in ggreer the_silver_searcher up to 2.2.0. The impacted element is the function search_stream of the file src/search.c. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed publ...

Published: Feb 18, 2026
Source: NVD
CVE-2026-2641 LOW - 3.3

A weakness has been identified in universal-ctags ctags up to 6.2.1. The affected element is the function parseExpression/parseExprList of the file parsers/v.c of the component V Language Parser. Executing a manipulation can lead to uncontrolled recursion. It is possible to launch the attack on the ...

Published: Feb 18, 2026
Source: NVD

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

Vendor: zlib
Product: zlib
Published: Feb 18, 2026
Source: NVD

IBM watsonx.data 2.2 through 2.2.1 IBM Lakehouse could allow a privileged user to upload malicious files that could be executed server to modify limited files or data.

Vendor: IBM
Product: watsonx.data
Published: Feb 17, 2026
Source: NVD
CVE-2026-2622 LOW - 3.5

A vulnerability was detected in Blossom up to 1.17.1. This vulnerability affects the function content of the file blossom-backend/backend/src/main/java/com/blossom/backend/server/article/draft/ArticleController.java of the component Article Title Handler. The manipulation results in cross site scrip...

Vendor: wangyunf
Product: blossom
Published: Feb 17, 2026
Source: NVD
CVE-2026-0102 LOW - 3.1

Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.

Vendor: microsoft
Product: edge_chromium
Published: Feb 17, 2026
Source: NVD

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification in...

Vendor: Apache Software Foundation
Product: Apache Tomcat
Published: Feb 17, 2026
Source: NVD

OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, when the Slack integration is enabled, channel metadata (topic/description) can be incorporated into the model's system prompt. Prompt injection is a documented risk for LLM-d...

Vendor: npm
Product: openclaw
Published: Feb 17, 2026
Source: GitHub
CVE-2026-2618 LOW - 3.7

A vulnerability was determined in Beetel 777VR1 up to 01.00.09. This impacts an unknown function of the component SSH Service. This manipulation causes risky cryptographic algorithm. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitabili...

Vendor: beetel
Product: 777vr1_firmware
Published: Feb 17, 2026
Source: NVD

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the User Panel, specifically the /profile.php endpoint.

Vendor: phpgurukul
Product: gym_management_system
Published: Feb 17, 2026
Source: NVD
CVE-2026-2557 LOW - 3.5

A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller/resource/MediaController.java of the component File Upload. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and ma...

Vendor: cskefu
Product: cskefu
Published: Feb 16, 2026
Source: NVD

Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561

Vendor: Mattermost
Product: Mattermost
Published: Feb 16, 2026
Source: NVD
CVE-2026-2547 LOW - 3.5

A vulnerability was detected in LigeroSmart up to 6.1.26. The impacted element is the function AgentDashboard of the file /otrs/index.pl. Performing a manipulation of the argument Subaction results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and ...

Vendor: ligerosmart
Product: ligerosmart
Published: Feb 16, 2026
Source: NVD