Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,806
Quick preset (or use dates below)
Clear Filters
Showing 1,321 - 1,340 of 1,478 CVEs

HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potentially exposing the application to man-in-the-middle and protocol downgrade attacks.. This issue affects AION: 2.0.

Vendor: HCL
Product: AION
Published: Feb 03, 2026
Source: NVD

HCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerability. This can allow autocomplete on password fields may lead to unintended storage or disclosure of sensitive credentials, potentially increasing the risk of unauthorized access. This issue affects AION...

Vendor: HCL
Product: AION
Published: Feb 03, 2026
Source: NVD

Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uploaded content without a restrictive Content-Security-Policy (CSP) or adequate Content-Type validation, leading to Stored ...

Vendor: go
Product: github.com/stefanprodan/podinfo
Published: Feb 03, 2026
Source: NVD

HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cross-site scripting and other content injection attacks by allowing unsafe scripts or resources to execute..This issue affects AION: 2.0.

Vendor: HCL
Product: AION
Published: Feb 03, 2026
Source: NVD

A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attac...

Vendor: composer
Product: moodle/moodle
Published: Feb 03, 2026
Source: NVD

A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different directories.

Vendor: Brocade
Product: Fabric OS
Published: Feb 03, 2026
Source: NVD

A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories.

Vendor: Brocade
Product: Fabric OS
Published: Feb 03, 2026
Source: NVD

IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific shared processor configurations during certain operations.

Vendor: IBM
Product: PowerVM Hypervisor
Published: Feb 02, 2026
Source: NVD

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applications that return a ReadableStream (or Response with a Web Stream body) via r...

Vendor: npm
Product: fastify
Published: Feb 02, 2026
Source: GitHub

When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

Vendor: pip
Product: pip
Published: Feb 02, 2026
Source: NVD
CVE-2026-1751 LOW - 3.1

A vulnerability has been discovered in GitLab CE/EE affecting all versions starting with 16.8 before 18.5.0 that could have allowed unauthorized edits to merge request approval rules under certain conditions.

Vendor: gitlab
Product: gitlab
Published: Feb 02, 2026
Source: NVD
CVE-2026-1518 LOW - 2.7

A flaw was found in Keycloak’s CIBA feature where insufficient validation of client-configured backchannel notification endpoints could allow blind server-side requests to internal services.

Vendor: maven
Product: org.keycloak:keycloak-parent
Published: Feb 02, 2026
Source: NVD

A flaw was found in Keycloak Admin API. This vulnerability allows an administrator with limited privileges to retrieve sensitive custom attributes via the /unmanagedAttributes endpoint, bypassing User Profile visibility settings.

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: Feb 02, 2026
Source: NVD
CVE-2026-1744 LOW - 2.4

A vulnerability was found in D-Link DSL-6641K N8.TR069.20131126. Affected by this issue is the function doSubmitPPP of the file sp_pppoe_user.js. The manipulation of the argument Username results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could...

Published: Feb 02, 2026
Source: NVD
CVE-2026-1743 LOW - 3.1

A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerability is an unknown functionality of the component Enhanced Wi-Fi Pairing. The manipulation leads to authentication bypass by capture-replay. The attack must be carried out from within...

Published: Feb 02, 2026
Source: NVD
CVE-2026-1705 LOW - 2.4

A vulnerability was detected in D-Link DSL-6641K N8.TR069.20131126. Affected by this issue is the function ad_virtual_server_vdsl of the component Web Interface. Performing a manipulation of the argument Name results in cross site scripting. It is possible to initiate the attack remotely. The exploi...

Published: Jan 30, 2026
Source: NVD
CVE-2026-1700 LOW - 3.5

A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknown code of the file /app/sms.php. This manipulation of the argument Message causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made av...

Published: Jan 30, 2026
Source: NVD

Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenticate()` method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses). In `packages/core/src/config/auth/native-authentication-strate...

Vendor: vendurehq
Product: vendure
Published: Jan 30, 2026
Source: NVD
CVE-2026-1685 LOW - 3.7

A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the component Login. Such manipulation leads to improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high com...

Published: Jan 30, 2026
Source: NVD

Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.

Vendor: llamastack
Product: Llama Stack
Published: Jan 30, 2026
Source: NVD