| CVE-2025-1242 |
Administrative Credentials Can Be Extracted Through Gardyn API Responses |
25.02.2026 |
|
| CVE-2026-27700 |
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo |
25.02.2026 |
8.2 |
| CVE-2026-27701 |
LiveCodes vulnerable to JavaScript Injection via untrusted PR title in i18n-update-pull workflow |
25.02.2026 |
|
| CVE-2026-27702 |
Budibase Vulnerable to Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud) |
25.02.2026 |
9.9 |
| CVE-2026-27704 |
Dart SDK and Flutter SDK have Zip slip in Dart Pub package extraction |
25.02.2026 |
|
| CVE-2026-27846 |
Missing authentication in Linksys MR9600, Linksys MX4200 |
25.02.2026 |
|
| CVE-2026-27847 |
Missing authentication in Linksys MR9600, Linksys MX4200 |
25.02.2026 |
|
| CVE-2026-27848 |
Missing neutralization in Linksys MR9600, Linksys MX4200 |
25.02.2026 |
|
| CVE-2026-3206 |
Improper management of context cancelations |
25.02.2026 |
|
| CVE-2026-27692 |
iccDEV has HBO in CIccTagTextDescription::Release() |
25.02.2026 |
7.1 |
| CVE-2026-27695 |
zae-limiter: DynamoDB hot partition throttling enables per-entity Denial of Service |
25.02.2026 |
4.3 |
| CVE-2026-27699 |
Basic FTP has Path Traversal Vulnerability in its downloadToDir() method |
25.02.2026 |
9.1 |
| CVE-2026-2878 |
Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX |
25.02.2026 |
5.3 |
| CVE-2026-27691 |
iccDEV has SIO in parse3DTable() at iccFromCube.cpp Line 218 |
25.02.2026 |
6.2 |
| CVE-2026-3187 |
feiyuchuixue sz-boot-parent API Endpoint upload unrestricted upload |
25.02.2026 |
|
| CVE-2026-3201 |
Improperly Controlled Sequential Memory Allocation in Wireshark |
25.02.2026 |
4.7 |
| CVE-2026-3202 |
NULL Pointer Dereference in Wireshark |
25.02.2026 |
4.7 |
| CVE-2026-3203 |
Buffer Over-read in Wireshark |
25.02.2026 |
5.5 |
| CVE-2026-3197 |
|
25.02.2026 |
|
| CVE-2026-3185 |
feiyuchuixue sz-boot-parent API Endpoint sys-message authorization |
25.02.2026 |
|
| CVE-2026-3186 |
feiyuchuixue sz-boot-parent Password Reset password default password |
25.02.2026 |
|
| CVE-2026-28193 |
|
25.02.2026 |
8.8 |
| CVE-2026-28194 |
|
25.02.2026 |
4.3 |
| CVE-2026-28195 |
|
25.02.2026 |
4.3 |
| CVE-2026-28196 |
|
25.02.2026 |
2.3 |
| CVE-2026-21725 |
Authorization Bypass via TOCTOU in Grafana Datasource Deletion by Name |
25.02.2026 |
2.6 |
| CVE-2026-2624 |
Authentication Bypass in ePati's Antikor NGFW |
25.02.2026 |
9.8 |
| CVE-2026-0704 |
|
25.02.2026 |
|
| CVE-2026-3118 |
Rhdh: graphql injection leading to platform-wide denial of service (dos) in rh developer hub orchestrator plugin |
25.02.2026 |
|
| CVE-2026-25701 |
|
25.02.2026 |
|
| CVE-2025-62878 |
Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern |
25.02.2026 |
9.9 |
| CVE-2025-67601 |
Rancher CLI skips TLS verification on Rancher CLI login command |
25.02.2026 |
8.3 |
| CVE-2026-26104 |
Udisks: missing authorization check allows unprivileged users to back up luks headers via udisks d-bus api |
25.02.2026 |
|
| CVE-2025-67860 |
NeuVector scanner insecurely handles passwords as command arguments |
25.02.2026 |
3.8 |
| CVE-2026-26103 |
Udisks: missing authorization check allows unprivileged users to restore luks headers via udisks d-bus api |
25.02.2026 |
|
| CVE-2025-14742 |
WP Recipe Maker <= 10.2.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure |
25.02.2026 |
4.3 |
| CVE-2026-2301 |
Post Duplicator <= 3.0.8 - Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter |
25.02.2026 |
4.3 |
| CVE-2026-2367 |
Secure Copy Content Protection and Content Locking <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute |
25.02.2026 |
6.4 |
| CVE-2026-2410 |
Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update |
25.02.2026 |
4.3 |
| CVE-2026-3171 |
SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System queue.php cross site scripting |
25.02.2026 |
|
| CVE-2026-1916 |
WPGSI: Spreadsheet Integration <= 3.8.3 - Missing Authorization to Unauthenticated Arbitrary Post Creation and Deletion via Forged Base64 Token |
25.02.2026 |
7.5 |
| CVE-2026-1929 |
Advanced Woo Labels <= 2.37 - Authenticated (Contributor+) Remote Code Execution via 'callback' Parameter |
25.02.2026 |
8.8 |
| CVE-2026-2416 |
Geo Mashup <= 1.13.17 - Unauthenticated SQL Injection via 'sort' Parameter |
25.02.2026 |
7.5 |
| CVE-2026-2479 |
Responsive Lightbox & Gallery <= 2.7.1 - Authenticated (Author+) Server-Side Request Forgery via Remote Library Image Upload |
25.02.2026 |
5 |
| CVE-2026-3170 |
SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System patient-search.php cross site scripting |
25.02.2026 |
|
| CVE-2026-3169 |
Tenda F453 httpd SafeEmailFilter fromSafeEmailFilter buffer overflow |
25.02.2026 |
|
| CVE-2025-11563 |
wcurl path traversal with percent-encoded slashes |
25.02.2026 |
|
| CVE-2026-1614 |
Rise Blocks – A Complete Gutenberg Page Builder <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Identity Block Attributes |
25.02.2026 |
6.4 |
| CVE-2026-3167 |
Tenda F453 httpd webtypelibrary formWebTypeLibrary buffer overflow |
25.02.2026 |
|
| CVE-2026-3168 |
Tenda F453 httpd NatStaticSetting fromNatStaticSetting buffer overflow |
25.02.2026 |
|
| CVE-2026-3166 |
Tenda F453 httpd RouteStatic fromRouteStatic buffer overflow |
25.02.2026 |
|
| CVE-2026-25785 |
|
25.02.2026 |
|
| CVE-2026-3100 |
An improper certificate validation vulnerability was found in the FTP Backup on the ADM. |
25.02.2026 |
|
| CVE-2026-3164 |
itsourcecode News Portal Project contactus.php sql injection |
25.02.2026 |
|
| CVE-2026-3165 |
Tenda F453 httpd AdvSetWrlsafeset fromSetWifiGusetBasic buffer overflow |
25.02.2026 |
|
| CVE-2026-3179 |
A path traversal vulnerability was found in the FTP Backup on the ADM. |
25.02.2026 |
|
| CVE-2026-3153 |
itsourcecode Document Management System register.php sql injection |
25.02.2026 |
|
| CVE-2026-3163 |
SourceCodester Website Link Extractor URL file_get_contents server-side request forgery |
25.02.2026 |
|
| CVE-2026-3151 |
itsourcecode College Management System login.php sql injection |
25.02.2026 |
|
| CVE-2026-3152 |
itsourcecode College Management System teacher-salary.php sql injection |
25.02.2026 |
|
| CVE-2025-0976 |
Information Exposure Vulnerability in Hitachi Configuration Manager, Hitachi Ops Center API Configuration Manager |
25.02.2026 |
4.7 |
| CVE-2026-27624 |
Coturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACL |
25.02.2026 |
7.2 |
| CVE-2026-27645 |
changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response |
25.02.2026 |
6.1 |
| CVE-2026-27696 |
changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs |
25.02.2026 |
8.6 |
| CVE-2026-3148 |
SourceCodester Simple and Nice Shopping Cart Script signup.php sql injection |
25.02.2026 |
|
| CVE-2026-3149 |
itsourcecode College Management System asign-single-student-subjects.php sql injection |
25.02.2026 |
|
| CVE-2026-3150 |
itsourcecode College Management System display-teacher.php sql injection |
25.02.2026 |
|
| CVE-2026-27597 |
@enclave-vm/core is vulnerable to Sandbox Escape |
25.02.2026 |
10 |
| CVE-2026-27627 |
Karakeep's Reddit plugin content bypasses DOMPurify sanitization, enabling stored XSS |
25.02.2026 |
8.2 |
| CVE-2026-27636 |
FreeScout: Missing .htaccess in Restricted File Extensions Allows Remote Code Execution on Apache |
25.02.2026 |
8.8 |
| CVE-2026-27637 |
FreeScout's Predictable Authentication Token Enables Account Takeover |
25.02.2026 |
9.8 |
| CVE-2026-27639 |
Mercator vulnerable to stored XSS via unescaped Blade directives in display templates |
25.02.2026 |
|
| CVE-2026-27640 |
tfplan2md has Sensitive Value Exposure in Generated Reports |
25.02.2026 |
|
| CVE-2026-27641 |
Flask-Reuploaded vulnerable to Remote Code Execution via Server-Side Template Injection |
25.02.2026 |
9.8 |
| CVE-2026-27743 |
SPIP referer_spam <= 1.2.1 Unauthenticated SQL Injection |
25.02.2026 |
|
| CVE-2026-27744 |
SPIP tickets < 4.3.3 Unauthenticated RCE |
25.02.2026 |
|
| CVE-2026-27745 |
SPIP interface_traduction_objets < 2.2.2 Authenticated RCE |
25.02.2026 |
|
| CVE-2026-27746 |
SPIP jeux < 4.1.1 Reflected XSS via index Parameters |
25.02.2026 |
|
| CVE-2026-27747 |
SPIP interface_traduction_objets < 2.2.2 Authenticated SQL Injection |
25.02.2026 |
|
| CVE-2026-3147 |
libvips csvload.c vips_foreign_load_csv_build heap-based overflow |
25.02.2026 |
|
| CVE-2025-5781 |
Information Exposure Vulnerability in Hitachi Configuration Manager, Hitachi Ops Center API Configuration Manager |
25.02.2026 |
5.2 |
| CVE-2026-25135 |
OpenEMR's location resource for Group.$export operation returns entire patient/user population contact information |
25.02.2026 |
4.5 |
| CVE-2026-27595 |
Parse Dashboard has incomplete authentication on AI Agent endpoint |
25.02.2026 |
|
| CVE-2026-27606 |
Rollup 4 has Arbitrary File Write via Path Traversal |
25.02.2026 |
|
| CVE-2026-27607 |
RustFS's Missing Post Policy Validation leads to Arbitrary Object Write |
25.02.2026 |
8.1 |
| CVE-2026-27608 |
Parse Dashboard Missing Authorization on Agent Endpoint |
25.02.2026 |
|
| CVE-2026-27609 |
Parse Dashboard Missing CSRF Protection on Agent Endpoint |
25.02.2026 |
|
| CVE-2026-27610 |
Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions |
25.02.2026 |
|
| CVE-2026-27611 |
FileBrowser Quantum: Password Protection Not Enforced on Shared File Links |
25.02.2026 |
|
| CVE-2026-27612 |
Repostat Vulnerable to Reflected Cross-Site Scripting (XSS) via repo prop in RepoCard |
25.02.2026 |
6.1 |
| CVE-2026-27614 |
Bugsink is vulnerable to Stored XSS via Pygments fallback in stacktrace rendering |
25.02.2026 |
9.3 |
| CVE-2026-27615 |
ADB-Explorer: UNC Path Support in ManualAdbPath Leads to Remote Code Execution (RCE) |
25.02.2026 |
|
| CVE-2026-27621 |
TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload |
25.02.2026 |
|
| CVE-2026-27626 |
OliveTin vulnerable to OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell safety checks |
25.02.2026 |
10 |
| CVE-2026-27628 |
pypdf has a possible infinite loop when loading circular /Prev entries in cross-reference streams |
25.02.2026 |
|
| CVE-2026-27629 |
InvenTree Vulnerable to Server Side Template Injection (SSTI) |
25.02.2026 |
5.9 |
| CVE-2026-27632 |
Talishar Vulnerable to Cross-Site Request Forgery (CSRF) |
25.02.2026 |
2.6 |
| CVE-2026-27822 |
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover |
25.02.2026 |
9.1 |
| CVE-2026-3145 |
libvips matrixload.c vips_foreign_load_matrix_header memory corruption |
25.02.2026 |
|
| CVE-2026-3146 |
libvips matrixload.c vips_foreign_load_matrix_header null pointer dereference |
25.02.2026 |
|
| CVE-2025-69231 |
OpenEMR has a Stored XSS in GAD-7 Form that Enables Session Hijacking and Privilege Escalation |
25.02.2026 |
8.7 |
| CVE-2026-21443 |
OpenEMR allows inconsistent escaping of translation function output |
25.02.2026 |
|
| CVE-2026-24847 |
OpenEMR has Open Redirect in Eye Exam Form |
25.02.2026 |
6.1 |
| CVE-2026-24849 |
OpenEMR Arbitrary File Read Vulnerability |
25.02.2026 |
10 |
| CVE-2026-24896 |
OpenEMR has Broken Access Control that allows unauthorized access to EDI Logs |
25.02.2026 |
6.5 |
| CVE-2026-25124 |
OpenEMR has Broken Access Control in Report/Clients/Message List CSV Export |
25.02.2026 |
6.5 |
| CVE-2026-25127 |
OpenEMR has Broken Access Control on Care Coordination Module |
25.02.2026 |
|
| CVE-2026-25131 |
OpenEMR has Broken Access Control in Procedures Configuration |
25.02.2026 |
8.8 |
| CVE-2026-2914 |
|
25.02.2026 |
|
| CVE-2025-67752 |
OpenEMR Has Disabled SSL Certificate Verification in HTTP Client |
25.02.2026 |
8.1 |
| CVE-2025-68277 |
OpenEMR allows links sent via Secure Messaging to be opened in OpenEMR and Portal |
25.02.2026 |
|
| CVE-2025-67491 |
OpenEMR has Stored XSS in ub04 helper |
25.02.2026 |
|
| CVE-2026-27598 |
Dagu: Path traversal in DAG creation allows arbitrary YAML file write outside DAGs directory |
25.02.2026 |
|
| CVE-2026-3135 |
itsourcecode News Portal Project add-category.php sql injection |
25.02.2026 |
|
| CVE-2026-3137 |
CodeAstro Food Ordering System food_ordering.exe stack-based overflow |
25.02.2026 |
|
| CVE-2026-3133 |
itsourcecode Document Management System Login loging.php sql injection |
24.02.2026 |
|
| CVE-2026-3134 |
itsourcecode News Portal Project edit-category.php sql injection |
24.02.2026 |
|
| CVE-2026-26351 |
GetSimpleCMS-CE < 3.3.22 Stored XSS via components.php |
24.02.2026 |
|
| CVE-2026-27117 |
bit7z has a path traversal vulnerability |
24.02.2026 |
5.5 |
| CVE-2026-27593 |
Statamic is vulnerable to account takeover via password reset link injection |
24.02.2026 |
9.3 |
| CVE-2026-27204 |
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion |
24.02.2026 |
|
| CVE-2026-27572 |
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance |
24.02.2026 |
|
| CVE-2026-25891 |
Fiber has an Arbitrary File Read in Static Middleware on Windows |
24.02.2026 |
|
| CVE-2026-25899 |
Fiber is Vulnerable to Denial of Service via Flash Cookie Unbounded Allocation |
24.02.2026 |
7.5 |
| CVE-2026-27195 |
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future |
24.02.2026 |
|
| CVE-2026-21410 |
InSAT MasterSCADA BUK-TS SQL Injection |
24.02.2026 |
9.8 |
| CVE-2026-22553 |
InSAT MasterSCADA BUK-TS OS Command Injection |
24.02.2026 |
9.8 |
| CVE-2026-25882 |
Fiber has a Denial of Service Vulnerability via Route Parameter Overflow |
24.02.2026 |
|