Total CVEs

125,574

Critical Severity

2,253

High Severity

7,771

Last 7 Days

1,121
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 161 - 180 of 250 CVEs
CVE-2026-28193 HIGH - 8.8

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

Vendor: JetBrains
Product: YouTrack
Published: Feb 25, 2026
Source: NVD
CVE-2026-27614 CRITICAL - 9.3

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the affected Stacktrace in the web UI. When Pygments retu...

Vendor: bugsink
Product: bugsink
Published: Feb 25, 2026
Source: NVD
CVE-2026-25649 HIGH - 7.3

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect vulnerability in two OIDC-related endpoints. The `redirect_uri` parameter is not validated against a...

Vendor: traccar
Product: traccar
Published: Feb 23, 2026
Source: NVD
CVE-2026-25648 HIGH - 8.7

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device images. The application accepts SVG file uploads without...

Vendor: traccar
Product: traccar
Published: Feb 23, 2026
Source: NVD
CVE-2026-23521 MEDIUM - 6.5

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absolute path. When uploading a device image, Traccar uses that `uniqueId` to build the filesystem path wi...

Vendor: traccar
Product: traccar
Published: Feb 23, 2026
Source: NVD
CVE-2025-68930 HIGH - 7.1

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocket handshake. This allows a remote attacker to bypa...

Vendor: traccar
Product: traccar
Published: Feb 23, 2026
Source: NVD

Reflected Cross-Site Scripting vulnerability in SOTESHOP, version 8.3.4. THis vulnerability allows an attacker execute JavaScript code in the victim's browser when a malicious URL with the 'id' parameter in '/adsTracker/checkAds' is sent to the victim. The vulnerability can ...

Vendor: SOTE
Product: SOTESHOP
Published: Feb 23, 2026
Source: NVD
CVE-2026-27479 HIGH - 7.7

Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the subscription and payment logo/icon upload functionality. The application validates the IP address of the provided URL before making the re...

Vendor: ellite
Product: Wallos
Published: Feb 21, 2026
Source: NVD
CVE-2026-27197 CRITICAL - 9.1

Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the...

Vendor: getsentry
Product: sentry
Published: Feb 21, 2026
Source: NVD
CVE-2026-2040 HIGH - 7.3

PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of PDF-XChange Editor. An attacker must first obtain the ability to execute low-privileged code on th...

Published: Feb 20, 2026
Source: NVD
CVE-2026-2033 HIGH - 8.1

MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this vulnerability. The specific flaw ...

Published: Feb 20, 2026
Source: NVD
CVE-2026-26953 MEDIUM - 5.4

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and above have a Stored HTML Injection vulnerability in the active sessions table located on the API settings page, allowing an attacker with valid credentials...

Vendor: pi-hole
Product: web
Published: Feb 19, 2026
Source: NVD
CVE-2026-26952 MEDIUM - 5.4

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below are vulnerable to stored HTML injection through the local DNS records configuration page, which allows an authenticated administrator to inject code t...

Vendor: pi-hole
Product: web
Published: Feb 19, 2026
Source: NVD
CVE-2026-1219 MEDIUM - 5.3

The MP3 Audio Player โ€“ Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0 to 5.10 via the 'load_track_note_ajax' due to missing validation on a user controlled key. This makes it possible for unauthentic...

Published: Feb 19, 2026
Source: NVD
CVE-2026-26996 HIGH - 7.5

minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal character that doesn't...

Vendor: npm
Product: minimatch
Published: Feb 18, 2026
Source: GitHub
CVE-2025-70152 CRITICAL - 9.8

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, ...

Vendor: fabian
Product: scholars_tracking_system
Published: Feb 18, 2026
Source: NVD
CVE-2025-70151 HIGH - 8.8

code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied fil...

Vendor: fabian
Product: scholars_tracking_system
Published: Feb 18, 2026
Source: NVD
CVE-2026-25500 MEDIUM - 5.4

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory` generates an HTML directory index where each file entry is rendered as a clickable link. If a file exists on disk whose basename starts with the `javascript:` scheme (e.g. `javascript:alert(1)...

Vendor: rubygems
Product: rack
Published: Feb 17, 2026
Source: GitHub
CVE-2026-22860 HIGH - 7.5

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`โ€™s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directo...

Vendor: rubygems
Product: rack
Published: Feb 17, 2026
Source: GitHub

In the Linux kernel, the following vulnerability has been resolved: KVM: Don't clobber irqfd routing type when deassigning irqfd When deassigning a KVM_IRQFD, don't clobber the irqfd's copy of the IRQ's routing entry as doing so breaks kvm_arch_irq_bypass_del_producer() on x86 ...

Vendor: Linux
Product: Linux
Published: Feb 14, 2026
Source: NVD