Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
Showing 1,261 - 1,280 of 1,477 CVEs

Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data corruption. This result may potentially occ...

Product: Intel(R) NPU Drivers
Published: Feb 10, 2026
Source: NVD

Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result...

Product: Intel(R) Graphics Drivers and Intel LTS kernels
Published: Feb 10, 2026
Source: NVD

Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local acce...

Published: Feb 10, 2026
Source: NVD

Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a l...

Product: Intel(R) Ethernet 800-Series
Published: Feb 10, 2026
Source: NVD

A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Unfortunately, the project has no active maintainer at t...

Vendor: wasm3_project
Product: wasm3
Published: Feb 10, 2026
Source: NVD

A security vulnerability has been detected in ckolivas lrzip up to 0.651. This vulnerability affects the function ucompthread of the file stream.c. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly ...

Vendor: ckolivas
Product: lrzip
Published: Feb 10, 2026
Source: NVD

Observable Timing Discrepancy vulnerability in Apache Shiro. This issue affects Apache Shiro: from 1.*, 2.* before 2.0.7. Users are recommended to upgrade to version 2.0.7 or later, which fixes the issue. Prior to Shiro 2.0.7, code paths for non-existent vs. existing users are different enough, t...

Vendor: Apache Software Foundation
Product: Apache Shiro
Published: Feb 10, 2026
Source: NVD
CVE-2026-2259 LOW - 3.3

A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsing. The manipulation leads to memory corruption. The attack can only be performed from a local envir...

Vendor: strlen
Product: lobster
Published: Feb 10, 2026
Source: NVD

Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory cor...

Vendor: SAP_SE
Product: SAP NetWeaver and ABAP Platform (Application Server ABAP)
Published: Feb 10, 2026
Source: NVD

Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administrative access could submit specially crafted content to the application. If processed by the application, this content enables injection of untrusted entries into generated configur...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server Java
Published: Feb 10, 2026
Source: NVD
CVE-2026-2258 LOW - 3.3

A flaw has been found in aardappel lobster up to 2025.4. Affected by this vulnerability is the function WaveFunctionCollapse in the library dev/src/lobster/wfc.h. Executing a manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been published and may b...

Vendor: strlen
Product: lobster
Published: Feb 10, 2026
Source: NVD
CVE-2026-2246 LOW - 3.3

A security vulnerability has been detected in AprilRobotics apriltag up to 3.4.5. Affected by this vulnerability is the function apriltag_detector_detect of the file apriltag.c. The manipulation leads to memory corruption. The attack must be carried out locally. The exploit has been disclosed public...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2245 LOW - 3.3

A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is...

Published: Feb 09, 2026
Source: NVD

Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.

Vendor: craftcms
Product: cms
Published: Feb 09, 2026
Source: NVD
CVE-2026-2242 LOW - 3.3

A vulnerability was determined in janet-lang janet up to 1.40.1. This impacts the function janetc_if of the file src/core/specials.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This pa...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2241 LOW - 3.3

A vulnerability was found in janet-lang janet up to 1.40.1. This affects the function os_strftime of the file src/core/os.c. Performing a manipulation results in out-of-bounds read. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is n...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2240 LOW - 3.3

A vulnerability has been found in janet-lang janet up to 1.40.1. The impacted element is the function janetc_pop_funcdef of the file src/core/compile.c. Such manipulation leads to out-of-bounds read. The attack must be carried out locally. The exploit has been disclosed to the public and may be used...

Published: Feb 09, 2026
Source: NVD
CVE-2026-2224 LOW - 3.5

A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The explo...

Vendor: fabian
Product: online_reviewer_system
Published: Feb 09, 2026
Source: NVD
CVE-2026-2222 LOW - 2.4

A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting. The attack may...

Vendor: fabian
Product: online_reviewer_system
Published: Feb 09, 2026
Source: NVD
CVE-2026-2215 LOW - 3.7

A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the file core/auth.py of the component JWT Handler. Performing a manipulation of the argument SECRET_KEY results in use of default cryptographic key. The attack can be initiated remote...

Published: Feb 09, 2026
Source: NVD