Total CVEs

111,140

Critical Severity

796

High Severity

2,523

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 204 CVEs

Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID: MMSA-2025-00549

Vendor: Mattermost
Product: Mattermost
Published: Feb 13, 2026
Source: NVD

NeuVector scanner insecurely handles passwords as command arguments

Vendor: go
Product: github.com/neuvector/scanner
Published: Feb 12, 2026
Source: GitHub
CVE-2026-2391 LOW - 3.7

### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit enforcement, similar to the bracket notation bypass addressed in GHSA-6...

Vendor: npm
Product: qs
Published: Feb 12, 2026
Source: NVD

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26.3. An app may be able to access information about a user's contacts.

Vendor: Apple
Product: macOS
Published: Feb 11, 2026
Source: NVD

A logic issue was addressed with improved checks. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker in a privileged network position may be able to intercept ...

Vendor: Apple
Product: macOS, watchOS, visionOS, iOS and iPadOS, tvOS
Published: Feb 11, 2026
Source: NVD

The issue was resolved by sanitizing logging. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An app may be able to enumerate a user's installed apps.

Vendor: Apple
Product: iOS and iPadOS
Published: Feb 11, 2026
Source: NVD

A logic issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, Safari 26.3, macOS Tahoe 26.3. An app may be able to access a user's Safari history.

Vendor: Apple
Product: Safari, macOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read sensitive location information.

Vendor: Apple
Product: macOS
Published: Feb 11, 2026
Source: NVD

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to monitor keystrokes without user permission.

Vendor: Apple
Product: macOS
Published: Feb 11, 2026
Source: NVD
CVE-2026-2345 LOW - 3.6

Proctorio Chrome Extension is a browser extension used for online proctoring. The extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based ...

Published: Feb 11, 2026
Source: NVD
CVE-2026-1282 LOW - 3.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.

Vendor: gitlab
Product: gitlab
Published: Feb 11, 2026
Source: NVD

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

Vendor: GitLab
Product: GitLab
Published: Feb 11, 2026
Source: NVD

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API en...

Vendor: GitLab
Product: GitLab
Published: Feb 11, 2026
Source: NVD

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side R...

Vendor: langchain-ai
Product: langchain
Published: Feb 10, 2026
Source: NVD
CVE-2026-1762 LOW - 2.9

A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.

Published: Feb 10, 2026
Source: NVD

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

Vendor: microsoft
Product: windows_10_1607
Published: Feb 10, 2026
Source: NVD

Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data corruption. This result may potentially occ...

Product: Intel(R) NPU Drivers
Published: Feb 10, 2026
Source: NVD

Improper conditions check in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result...

Product: Intel(R) Graphics Drivers and Intel LTS kernels
Published: Feb 10, 2026
Source: NVD

Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local acce...

Published: Feb 10, 2026
Source: NVD

Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) &amp; 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a l...

Product: Intel(R) Ethernet 800-Series
Published: Feb 10, 2026
Source: NVD