CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2025-6830 SQLi in Xpoda Türkiye Information Technology's Xpoda Studio 09.02.2026 9.8
CVE-2026-25848 09.02.2026 9.1
CVE-2026-22903 Stack Overflow via SESSIONID Cookie in lighttpd 09.02.2026 9.8
CVE-2026-22904 Stack Overflow via Oversized Cookie Fields in lighttpd 09.02.2026 9.8
CVE-2026-22906 Hardcoded Key Allows Credential Disclosure 09.02.2026 9.8
CVE-2026-2234 HGiga|C&Cm@il - Missing Authentication 09.02.2026 9.3
CVE-2026-1868 Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway 09.02.2026 9.9
CVE-2026-1615 09.02.2026 9.2
CVE-2025-15027 JAY Login & Register <= 2.6.03 - Unauthenticated Privilege Escalation via jay_login_register_ajax_create_final_user 09.02.2026 9.8
CVE-2026-25858 macrozheng mall <= 1.0.3 Unauthenticated Password Reset via OTP Disclosure 07.02.2026 9.3
CVE-2020-37135 AMSS++ 4.7 - Backdoor Admin Account 06.02.2026 9.3
CVE-2026-25803 3DP-MANAGER Uses Hard-coded Credentials 09.02.2026 9.8
CVE-2026-25763 Command Injection on OpenProject repositories leads to Remote Code Execution 09.02.2026 9.4
CVE-2026-1731 Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) 09.02.2026 9.9
CVE-2026-1727 Information Disclosure via Bucket Squatting in Google Cloud Agentspace. 09.02.2026 9.1
CVE-2026-25544 Payload has an SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters 09.02.2026 9.8
CVE-2026-25592 Semantic Kernel has an Arbitrary File Write via AI Agent Function Calling in .NET SDK 09.02.2026 10
CVE-2026-25632 EPyT-Flow has unsafe JSON deserialization (__type__) 06.02.2026 10
CVE-2026-25520 SandboxJS has a Sandbox Escape 06.02.2026 10
CVE-2026-25586 SandboxJS has a Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution 06.02.2026 10
CVE-2026-25587 SandboxJS has a Sandbox Escape 06.02.2026 10
CVE-2026-25641 SandboxJS has a sandbox escape via TOCTOU bug on keys in property accesses 06.02.2026 10
CVE-2026-1709 Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication 09.02.2026 9.4
CVE-2026-25643 Frigate Affected by Authenticated Remote Command Execution (RCE) and Container Escape 06.02.2026 9.1
CVE-2026-25751 FUXA Unauthenticated Exposure of Plaintext Database Credentials 09.02.2026 9.1
CVE-2026-25752 FUXA Unauthenticated Remote Arbitrary Device Tag Write 09.02.2026 9.3
CVE-2026-25753 PlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover) 09.02.2026 9.3
CVE-2025-69212 OpenSTAManager has an OS Command Injection in P7M File Processing 09.02.2026 9.4
CVE-2025-64111 Gogs's update .git/config file allows remote command execution 07.02.2026 9.3
CVE-2026-2017 IP-COM W30AP POST Request wx3auth R7WebsSecurityHandler stack-based overflow 06.02.2026 9.3
CVE-2026-1499 WP Duplicate <= 1.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via 'process_add_site' AJAX Action 06.02.2026 9.8
CVE-2026-21643 07.02.2026 9.1
CVE-2026-21626 Extension - stackideas.com - Information disclosure in post custom fields in EasyDiscuss 1.0.0-5.0.15 for Joomla 06.02.2026 9.2
CVE-2026-24300 Azure Front Door Elevation of Privilege Vulnerability 07.02.2026 9.8
CVE-2020-37123 Pinger 1.0 - Remote Code Execution 06.02.2026 9.3
CVE-2020-37125 Edimax Technology EW-7438RPn-v3 Mini 1.27 - Remote Code Execution 05.02.2026 9.3
CVE-2025-62615 AutoGPT has SSRF vulnerability in ReadRSSFeedBlock 05.02.2026 9.3
CVE-2025-62616 AutoGPT has SSRF vulnerability in SendDiscordFileBlock 05.02.2026 9.3
CVE-2026-25579 Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints 05.02.2026 9.2
CVE-2026-25539 SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE 05.02.2026 9.1
CVE-2026-25547 Uncontrolled Resource Consumption in @isaacs/brace-expansion 05.02.2026 9.2
CVE-2026-25526 JinJava Bypass through ForTag leads to Arbitrary Java Execution 05.02.2026 9.8
CVE-2026-25521 Locutus is vulnerable to Prototype Pollution 05.02.2026 9.4
CVE-2025-13375 IBM Common Cryptographic Architecture Arbitrary Command Execution 06.02.2026 9.8
CVE-2026-25512 Group-Office is vulnerable to RCE due to Command Injection via TNEF Attachment Handler 05.02.2026 9.4
CVE-2026-25481 Langroid has WAF Bypass Leading to RCE in TableChatAgent 04.02.2026 9.4
CVE-2026-25505 Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication 06.02.2026 9.8
CVE-2026-25160 Alist has Insecure TLS Config 05.02.2026 9.1
CVE-2025-64712 Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write 04.02.2026 9.8
CVE-2026-21893 n8n Vulnerable to Command Injection in Community Package Installation 04.02.2026 9.4
CVE-2026-25049 n8n Has an Expression Escape Vulnerability Leading to RCE 05.02.2026 9.4
CVE-2026-25052 n8n Improper File Access Controls Allow Arbitrary File Read by Authenticated Users 05.02.2026 9.4
CVE-2026-25053 n8n is Vulnerable to OS Command Injection in Git Node 05.02.2026 9.4
CVE-2026-25056 n8n Arbitrary File Write leading to RCE in n8n Merge Node 05.02.2026 9.4
CVE-2026-25115 n8n is vulnerable to Python sandbox escape 05.02.2026 9.4
CVE-2025-5329 SQLi in Martcode Software's Delta Course Automation 04.02.2026 9.8
CVE-2025-59818 Authenticated Remote Code Execution via the file name of an uploaded file 04.02.2026 10
CVE-2026-1633 Synectix LAN 232 TRIO Missing Authentication for Critical Function 04.02.2026 10
CVE-2026-1632 RISS SRL MOMA Seismic Station Missing Authentication for Critical Function 04.02.2026 9.3
CVE-2020-37071 CraftCMS 3 vCard Plugin 1.0.0 - Remote Code Execution 04.02.2026 9.3
CVE-2020-37092 Netis E1+ 1.2.32533 - Backdoor Account (root) 04.02.2026 9.3
CVE-2026-1341 Missing Authentication for Critical Function in Avation Light Engine Pro 04.02.2026 9.3
CVE-2026-25150 Prototype Pollution via FormData Processing in Qwik City 04.02.2026 9.3
CVE-2026-25510 CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor 04.02.2026 10
CVE-2025-65078 Untrusted search path vulnerability in Embedded Solutions Framework 06.02.2026 9.3
CVE-2026-1803 Ziroom ZHOME A0101 Dropbear SSH Service default credentials 03.02.2026 9.2
CVE-2025-10878 04.02.2026 10
CVE-2026-25237 PEAR is Vulnerable to PHP Code Execution via preg_replace /e in Bug Update Emails 04.02.2026 9.2
CVE-2026-25238 PEAR is Vulnerable to SQL Injection in Bug Subscription Deletion via Weak Email Validation 04.02.2026 9.2
CVE-2026-25241 PEAR is Vulnerable to SQL Injection in /get/<package>/<version> Endpoint 04.02.2026 9.3
CVE-2025-70841 04.02.2026 10
CVE-2026-1568 Rapid7 InsightVM Signature Validation Vulnerability 04.02.2026 9.6
CVE-2025-5319 SQLi in Emit Informatics' DIGITA Efficiency Management System 04.02.2026 9.8
CVE-2026-1432 SQL injection (SQLi) on the Buroweb platform 03.02.2026 9.3
CVE-2026-24465 03.02.2026 9.3
CVE-2026-24936 An improper input validation vulnerability was found in ADM while joining a AD Domain. 04.02.2026 9.5
CVE-2025-66480 Wildfire has Arbitrary File Upload via Directory Traversal in UploadFileAction 03.02.2026 9.8
CVE-2026-22778 vLLM leaks a heap address when PIL throws an error 03.02.2026 9.8
CVE-2026-25134 Group-Office Argument Injection in MaintenanceController::actionZipLanguage 04.02.2026 9.4
CVE-2026-25137 NixOs Odoo database and filestore publicly accessible with default odoo configuration 04.02.2026 9.1
CVE-2026-25142 SandboxJS Prototype Pollution -> Sandbox Escape -> RCE 04.02.2026 10

Latest Updates

CVE Title Updated Score
CVE-2026-2240 janet-lang janet compile.c janetc_pop_funcdef out-of-bounds 09.02.2026
CVE-2026-24095 Missing Permission Check on Analyze Configuration Page 09.02.2026
CVE-2025-14831 Gnutls: gnutls: denial of service via excessive resource consumption during certificate verification 09.02.2026
CVE-2025-59023 Crafted delegations or IP fragments can poison cached delegations in Recursor 09.02.2026 8.2
CVE-2025-59024 Crafted delegations or IP fragments can poison cached delegations in Recursor 09.02.2026 6.5
CVE-2025-63354 09.02.2026
CVE-2026-24027 Crafted zones can lead to increased incoming network traffic 09.02.2026 5.3
CVE-2026-0398 Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor 09.02.2026 5.3
CVE-2025-10465 Unrestricted File Upload in Birtech Information Technologies' Sensaway 09.02.2026 8.8
CVE-2025-10464 Cleartext password storage in Birtech Information Technologies' Sensaway 09.02.2026 6.5
CVE-2025-10463 Improper Authentication in Birtech Information Technologies' Sensaway 09.02.2026 7.3
CVE-2025-7708 Sensitive Data Exposure in Atlas Software's k12net 09.02.2026 6.8
CVE-2026-1959 Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes 09.02.2026
CVE-2026-1960 Stored Cross-Site Scripting (XSS) vulnerability in Loggro Pymes 09.02.2026
CVE-2025-6830 SQLi in Xpoda Türkiye Information Technology's Xpoda Studio 09.02.2026 9.8
CVE-2026-0632 Fluent Forms Pro Add On Pack <= 6.1.12 - Authenticated (Subscriber+) Server-Side Request Forgery via 'saveDataSource' 09.02.2026 5.4
CVE-2026-22922 Apache Airflow: Airflow externalLogUrl Permission Bypass 09.02.2026
CVE-2026-24098 Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors 09.02.2026
CVE-2026-25846 09.02.2026 6.5
CVE-2026-25847 09.02.2026 8.2
CVE-2026-25848 09.02.2026 9.1
CVE-2026-2227 D-Link DCS-931L setSystemAdmin doSystem command injection 09.02.2026
CVE-2026-23903 Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems 09.02.2026
CVE-2026-2226 DouPHP ZIP File file.php unrestricted upload 09.02.2026
CVE-2026-25905 Lack of isolation in mcp-run-python leads to MCP server takeover 09.02.2026 5.8
CVE-2026-2225 itsourcecode News Portal Project Administrator Login index.php sql injection 09.02.2026
CVE-2026-25904 Overly permissive Deno configuration in mcp-run-python leads to SSRF 09.02.2026 5.8
CVE-2026-2224 code-projects Online Reviewer System btn_functions.php cross site scripting 09.02.2026
CVE-2025-7799 Reflected XSS in Zirve Information Technologies' e-Taxpayer Accounting Website 09.02.2026 8.6
CVE-2026-25916 09.02.2026 4.3
CVE-2026-2223 code-projects Online Reviewer System index.php sql injection 09.02.2026
CVE-2026-22903 Stack Overflow via SESSIONID Cookie in lighttpd 09.02.2026 9.8
CVE-2026-22904 Stack Overflow via Oversized Cookie Fields in lighttpd 09.02.2026 9.8
CVE-2026-22905 Authentication Bypass via URI Traversal 09.02.2026 7.5
CVE-2026-22906 Hardcoded Key Allows Credential Disclosure 09.02.2026 9.8
CVE-2026-2222 code-projects Online Reviewer System btn_functions.php cross site scripting 09.02.2026
CVE-2026-2234 HGiga|C&Cm@il - Missing Authentication 09.02.2026
CVE-2026-2235 HGiga|C&Cm@il - SQL Injection 09.02.2026
CVE-2026-2236 HGiga|C&Cm@il - SQL Injection 09.02.2026
CVE-2026-24466 09.02.2026
CVE-2026-2221 code-projects Online Reviewer System Login index.php sql injection 09.02.2026
CVE-2026-0870 GIGABYTE|MacroHub - Local Privilege Escalation 09.02.2026
CVE-2026-1868 Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway 09.02.2026 9.9
CVE-2026-2220 code-projects Online Reviewer System btn_functions.php sql injection 09.02.2026
CVE-2026-22613 09.02.2026 5.7
CVE-2026-2218 D-Link DCS-933L alphapd setSystemAdmin command injection 09.02.2026
CVE-2026-2216 rachelos WeRSS we-mp-rss tools.py download_export_file path traversal 09.02.2026
CVE-2026-2217 itsourcecode Event Management System manage_user.php sql injection 09.02.2026
CVE-2026-1615 09.02.2026 9.8
CVE-2026-2215 rachelos WeRSS we-mp-rss JWT auth.py default key 09.02.2026
CVE-2025-66594 09.02.2026
CVE-2025-66595 09.02.2026
CVE-2025-66596 09.02.2026
CVE-2025-66597 09.02.2026
CVE-2025-66598 09.02.2026
CVE-2026-2213 code-projects Online Music Site AdminAddAlbum.php unrestricted upload 09.02.2026
CVE-2026-2214 code-projects for Plugin AdminAddAlbum.php cross site scripting 09.02.2026
CVE-2025-66599 09.02.2026
CVE-2025-66600 09.02.2026
CVE-2025-66601 09.02.2026
CVE-2025-66602 09.02.2026
CVE-2025-66603 09.02.2026
CVE-2025-66604 09.02.2026
CVE-2025-66605 09.02.2026
CVE-2025-66606 09.02.2026
CVE-2025-66607 09.02.2026
CVE-2025-66608 09.02.2026
CVE-2026-2211 code-projects Online Music Site AdminDeleteCategory.php sql injection 09.02.2026
CVE-2026-2212 code-projects Online Music Site AdminEditCategory.php sql injection 09.02.2026
CVE-2026-2202 Tenda AC8 httpd WifiGuestSet fromSetWifiGusetBasic buffer overflow 09.02.2026
CVE-2026-2203 Tenda AC8 Embedded Httpd Service fast_setting_wifi_set buffer overflow 09.02.2026
CVE-2026-2210 D-Link DIR-823X set_filtering sub_4211C8 os command injection 09.02.2026
CVE-2026-2200 heyewei JFinalCMS API Endpoint save cross site scripting 09.02.2026
CVE-2026-2201 ZeroWdd studentmanager LeaveController.java addLeave cross site scripting 09.02.2026
CVE-2026-2198 code-projects Online Reviewer System loaddata.php sql injection 09.02.2026
CVE-2026-2199 code-projects Online Reviewer System user-delete.php sql injection 09.02.2026
CVE-2026-2196 code-projects Online Reviewer System exam-update.php sql injection 09.02.2026
CVE-2026-2197 code-projects Online Reviewer System exam-delete.php sql injection 09.02.2026
CVE-2026-2194 D-Link DI-7100G C1 start_proxy_client_email command injection 08.02.2026
CVE-2026-2195 code-projects Online Reviewer System questions-view.php sql injection 08.02.2026
CVE-2026-2192 Tenda AC9 formGetRebootTimer stack-based overflow 08.02.2026
CVE-2026-2193 D-Link DI-7100G C1 set_jhttpd_info command injection 08.02.2026
CVE-2026-2190 itsourcecode School Management System controller.php sql injection 08.02.2026
CVE-2026-2191 Tenda AC9 formGetDdosDefenceList stack-based overflow 08.02.2026
CVE-2026-2189 itsourcecode School Management System index.php sql injection 08.02.2026
CVE-2026-2188 UTT 进取 521G formPdbUpConfig sub_446B18 os command injection 08.02.2026