Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,806
Quick preset (or use dates below)
Clear Filters
Showing 1,301 - 1,320 of 1,478 CVEs

Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device configuration files, as exploited in the wild from 2025-12-16 through 2026 (by default, the encryption key is the same across all customers' installations). NOTE: the Supplier's position is that th...

Vendor: Fortinet
Product: FortiOS
Published: Feb 05, 2026
Source: NVD
CVE-2026-1970 LOW - 3.5

A flaw has been found in Edimax BR-6258n up to 1.18. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup. This manipulation of the argument submit-url causes open redirect. The attack can be initiated remotely. The exploit has been published and may be used. The vendo...

Published: Feb 05, 2026
Source: NVD

Tanium addressed an improper certificate validation vulnerability in Tanium Appliance.

Vendor: Tanium
Product: Tanium Appliance
Published: Feb 05, 2026
Source: NVD

Tanium addressed an improper input validation vulnerability in Tanium Appliance.

Vendor: Tanium
Product: Tanium Appliance
Published: Feb 05, 2026
Source: NVD

Tanium addressed an improper access controls vulnerability in Interact.

Vendor: Tanium
Product: Interact
Published: Feb 05, 2026
Source: NVD

Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris...

Vendor: npm
Product: webpack
Published: Feb 05, 2026
Source: GitHub

Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that ap...

Vendor: npm
Product: webpack
Published: Feb 05, 2026
Source: GitHub

P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from a stored cross-site scripting vulnerability. Input passed to several GET/POST parameters is not properly sanitized before being returned to the user, allowing attackers to execute arbitrary HTML and script code in a user's browser s...

Vendor: P5
Product: FNIP-8x16A
Published: Feb 05, 2026
Source: NVD

P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user interaction. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authenti...

Vendor: P5
Product: FNIP-8x16A
Published: Feb 05, 2026
Source: NVD

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or f...

Vendor: Go standard library
Product: os
Published: Feb 04, 2026
Source: NVD

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Manager were able to upload SVGs without automatic sanitization. To actively exploit this security issue, an attacker would ...

Vendor: composer
Product: winter/wn-cms-module
Published: Feb 04, 2026
Source: GitHub
CVE-2025-2134 LOW - 3.5

IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to insufficient resource pooling.

Published: Feb 04, 2026
Source: NVD

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside on the server.

Vendor: IBM
Product: Jazz Reporting Service
Published: Feb 04, 2026
Source: NVD
CVE-2025-1823 LOW - 3.5

IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query that consumes excess memory resources.

Published: Feb 04, 2026
Source: NVD

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Vendor: F5
Product: BIG-IP
Published: Feb 04, 2026
Source: NVD

A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

Vendor: F5
Product: BIG-IP Edge Client
Published: Feb 04, 2026
Source: NVD
CVE-2026-1791 LOW - 2.7

Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security Gateway on Linux allows Upload a Web Shell to a Web Server.This issue affects Operation and Maintenance Security Gateway: V5.5ST00001B113.

Published: Feb 04, 2026
Source: NVD

A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration. If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errors...

Vendor: Kubernetes
Product: ingress-nginx
Published: Feb 03, 2026
Source: NVD

Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler middleware allows a remote attacker to redirect users to arbitrary protocol-relative URLs. Successful exploitation permits attackers to craft convin...

Vendor: QwikDev
Product: qwik
Published: Feb 03, 2026
Source: NVD

HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk of unauthorized access if the cookies are intercepted or compromised. This issue affects AION: 2.0.

Vendor: HCL
Product: AION
Published: Feb 03, 2026
Source: NVD