| CVE-2025-70094 |
|
13.02.2026 |
|
| CVE-2026-26221 |
Hyland OnBase Timer Services Unauthenticated .NET Remoting RCE |
13.02.2026 |
|
| CVE-2026-1578 |
HP App – Potential Cross-Site Scripting |
13.02.2026 |
|
| CVE-2026-25531 |
Kanboard TaskCreationController::duplicateProjects() endpoint does not validate user permissions for target projects |
13.02.2026 |
4.3 |
| CVE-2026-23111 |
netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() |
13.02.2026 |
|
| CVE-2026-23112 |
nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec |
13.02.2026 |
|
| CVE-2025-14349 |
Business Logic Error in Universal Software's FlexCity/Kiosk |
13.02.2026 |
8.8 |
| CVE-2026-1618 |
Admin Account Takeover in Universal Sotware's FlexCity/Kiosk |
13.02.2026 |
8.8 |
| CVE-2026-1619 |
IDOR in Universal Sotware's FlexCity/Kiosk |
13.02.2026 |
8.3 |
| CVE-2026-2443 |
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure |
13.02.2026 |
|
| CVE-2025-33042 |
Apache Avro Java SDK: Code injection on Java generated code |
13.02.2026 |
|
| CVE-2026-20796 |
Time-of-check time-of-use vulnerability in common teams API |
13.02.2026 |
3.1 |
| CVE-2026-22892 |
Insufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post Attachments |
13.02.2026 |
4.3 |
| CVE-2026-0872 |
Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon |
13.02.2026 |
|
| CVE-2025-15520 |
RegistrationMagic <= 6.0.7.2 - Subscriber+ Sensitive Data Disclosure |
13.02.2026 |
|
| CVE-2025-48021 |
|
13.02.2026 |
|
| CVE-2025-48022 |
|
13.02.2026 |
|
| CVE-2025-48023 |
|
13.02.2026 |
|
| CVE-2025-1924 |
|
13.02.2026 |
|
| CVE-2025-48019 |
|
13.02.2026 |
|
| CVE-2025-48020 |
|
13.02.2026 |
|
| CVE-2026-25108 |
|
13.02.2026 |
|
| CVE-2026-26249 |
|
13.02.2026 |
|
| CVE-2026-26250 |
|
13.02.2026 |
|
| CVE-2026-26251 |
|
13.02.2026 |
|
| CVE-2026-26252 |
|
13.02.2026 |
|
| CVE-2026-26253 |
|
13.02.2026 |
|
| CVE-2026-26254 |
|
13.02.2026 |
|
| CVE-2026-26255 |
|
13.02.2026 |
|
| CVE-2026-26256 |
|
13.02.2026 |
|
| CVE-2026-26257 |
|
13.02.2026 |
|
| CVE-2026-1721 |
Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site |
13.02.2026 |
|
| CVE-2025-9292 |
Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud Controllers |
13.02.2026 |
|
| CVE-2025-9293 |
Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle Interception |
13.02.2026 |
|
| CVE-2024-21961 |
|
13.02.2026 |
|
| CVE-2025-40905 |
WWW::OAuth 1.000 and earlier for Perl uses insecure rand() function for cryptographic functions |
12.02.2026 |
|
| CVE-2019-25318 |
AVS Audio Converter 9.1.2.600 - Stack Overflow |
12.02.2026 |
|
| CVE-2019-25319 |
Domain Quester Pro 6.02 - Stack Overflow (SEH) |
12.02.2026 |
|
| CVE-2019-25320 |
elearning-script 1.0 - Authentication Bypass |
12.02.2026 |
|
| CVE-2019-25321 |
FTP Navigator 8.03 - Stack Overflow (SEH) |
12.02.2026 |
|
| CVE-2019-25322 |
Heatmiser Netmonitor 3.03 - Hardcoded Credentials |
12.02.2026 |
|
| CVE-2019-25323 |
Heatmiser Netmonitor 3.03 - HTML Injection |
12.02.2026 |
|
| CVE-2019-25324 |
RICOH Web Image Monitor 1.09 - HTML Injection |
13.02.2026 |
|
| CVE-2019-25325 |
Thrive Smart Home 1.1 - 'Smart Home' Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
13.02.2026 |
|
| CVE-2019-25327 |
Prime95 Version 29.8 build 6 - Buffer Overflow (SEH) |
13.02.2026 |
|
| CVE-2019-25328 |
XnConvert 1.82 - Denial of Service |
13.02.2026 |
|
| CVE-2019-25329 |
FTP Navigator 8.03 - 'Custom Command' Denial of Service (SEH) |
12.02.2026 |
|
| CVE-2019-25330 |
SurfOffline Professional 2.2.0.103 - 'Project Name' Denial of Service (SEH) |
12.02.2026 |
|
| CVE-2019-25331 |
AVS Audio Converter 9.1 - 'Exit folder' Buffer Overflow |
12.02.2026 |
|
| CVE-2019-25332 |
FTP Commander Pro 8.03 - Local Stack Overflow |
12.02.2026 |
|
| CVE-2019-25333 |
Bullwark Momentum Series JAWS 1.0 - 'Momentum Series JAWS' Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
12.02.2026 |
|
| CVE-2019-25334 |
Product Key Explorer 4.2.0.0 - 'Name' Denial of Service |
12.02.2026 |
|
| CVE-2019-25335 |
PRO-7070 Hazır Profesyonel Web Sitesi 1.0 - Authentication Bypass |
12.02.2026 |
|
| CVE-2019-25336 |
SpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH) |
12.02.2026 |
|
| CVE-2019-25337 |
OwnCloud 8.1.8 - Username Disclosure |
12.02.2026 |
|
| CVE-2019-25338 |
Dokuwiki 2018-04-22b - Username Enumeration |
12.02.2026 |
|
| CVE-2019-25339 |
GHIA CamIP 1.2 for iOS - 'Password' Denial of Service |
12.02.2026 |
|
| CVE-2019-25340 |
SpotAuditor 5.3.2 - 'Base64' Denial Of Service |
12.02.2026 |
|
| CVE-2019-25341 |
iNetTools for iOS 8.20 - 'Whois' Denial of Service |
12.02.2026 |
|
| CVE-2019-25342 |
Centova Cast 3.2.12 - Denial of Service |
12.02.2026 |
|
| CVE-2020-37167 |
ClamAV ClamBC <= 0.102.0 - 'ClamBC' Executable Regular Expression Error |
12.02.2026 |
|
| CVE-2026-26188 |
Solspace Freeform plugin affected by Stored Cross-Site Scripting (XSS) in Freeform Craft Plugin CP UI (builder/integrations) |
13.02.2026 |
|
| CVE-2025-70092 |
|
12.02.2026 |
|
| CVE-2026-26068 |
emp3r0r Agent-Controlled Metadata to Operator RCE (tmux Command Injection) |
12.02.2026 |
|
| CVE-2026-26185 |
Directus Affected by User Enumeration via Password Reset Timing Attack |
12.02.2026 |
5.3 |
| CVE-2026-26224 |
Intego Log Reporter TOCTOU Local Privilege Escalation |
13.02.2026 |
|
| CVE-2026-26225 |
Intego Personal Backup Task File Privilege Escalation |
12.02.2026 |
|
| CVE-2025-14282 |
privilege escalation via unix domain socket forwardings |
12.02.2026 |
5.4 |
| CVE-2025-70845 |
|
12.02.2026 |
|
| CVE-2026-26075 |
Cross-Site Request Forgery (CSRF) in FastGPT |
12.02.2026 |
|
| CVE-2026-26076 |
ntpd-rs affected by excessive CPU load from malformed packets |
12.02.2026 |
|
| CVE-2026-1358 |
Airleader Master Unrestricted Upload of File with Dangerous Type |
12.02.2026 |
9.8 |
| CVE-2026-25828 |
|
12.02.2026 |
|
| CVE-2026-26069 |
Scraparr Readarr Integration exposes sensitive values as metric labels. |
12.02.2026 |
|
| CVE-2026-26055 |
Unauthenticated Admission Webhook Endpoints in Yoke ATC |
12.02.2026 |
7.5 |
| CVE-2026-26056 |
Arbitrary WASM Code Execution via AnnotationOverrideFlight Injection in Yoke ATC |
12.02.2026 |
8.8 |
| CVE-2026-26011 |
Critical Heap Out-of-bounds Access in `pf_cluster_stats()` via Malicious /initialpose Covariance -- Potential Remote Code Execution |
12.02.2026 |
|
| CVE-2026-26020 |
AutoGPT Affected by Remote Code Execution via Dynamic Module Import in Block Loading (__import__) |
12.02.2026 |
|
| CVE-2026-26000 |
XWiki Platform affected by click-jacking through CSS injection in comments |
12.02.2026 |
|
| CVE-2026-26005 |
ClipBucket v5 enables internal network scans via an SSRF vulnerability |
12.02.2026 |
5 |
| CVE-2026-0619 |
Integer Wraparound DoS in Silicon Labs Matter Implementation |
12.02.2026 |
|
| CVE-2026-25996 |
Inspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output Mode |
12.02.2026 |
|
| CVE-2026-25933 |
Arduino App Lab has Improper Data Validation in Internal Terminal Interface |
12.02.2026 |
6.9 |
| CVE-2026-25949 |
Traefik: TCP readTimeout bypass via STARTTLS on Postgres |
12.02.2026 |
7.5 |
| CVE-2026-25767 |
LavinMQ has incomplete shovel configuration validation |
12.02.2026 |
|
| CVE-2026-25768 |
LavinMQ is missing vhost access control |
12.02.2026 |
|
| CVE-2025-67432 |
|
12.02.2026 |
|
| CVE-2025-67433 |
|
12.02.2026 |
|
| CVE-2025-70314 |
|
12.02.2026 |
|
| CVE-2026-25227 |
authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpoint |
12.02.2026 |
9.1 |
| CVE-2026-25748 |
authentik has a forward authentication bypass with broken cookie |
12.02.2026 |
8.6 |
| CVE-2026-25922 |
authentik has a Signature Verification Bypass via SAML Assertion Wrapping |
12.02.2026 |
8.8 |
| CVE-2019-25343 |
NextVPN 4.10 - Insecure File Permissions |
12.02.2026 |
|
| CVE-2019-25344 |
MobileGo 8.5.0 - Insecure File Permissions |
12.02.2026 |
|
| CVE-2019-25345 |
RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path |
12.02.2026 |
|
| CVE-2019-25346 |
thesystem 1.0 - 'server_name' SQL Injection |
12.02.2026 |
|
| CVE-2019-25347 |
thesystem App 1.0 - 'username' SQL Injection |
12.02.2026 |
|
| CVE-2019-25348 |
|
13.02.2026 |
|
| CVE-2026-24044 |
ESS Community Helm Chart has a weak server key generation method |
12.02.2026 |
|
| CVE-2026-24894 |
FrankenPHP leaks session data between requests in worker mode |
12.02.2026 |
|
| CVE-2026-24895 |
FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of arbitrary files |
12.02.2026 |
|
| CVE-2026-22821 |
mreporting affected by a SQLI on date change |
12.02.2026 |
4.9 |
| CVE-2026-26218 |
newbee-mall Default Seeded Administrator Credentials Allow Account Takeover |
12.02.2026 |
|
| CVE-2026-26219 |
newbee-mall Unsalted MD5 Password Hashing Enables Offline Credential Cracking |
12.02.2026 |
|
| CVE-2026-21434 |
webtransport-go affected by Memory Exhaustion Attack due to Missing Length Check in WT_CLOSE_SESSION Capsule |
12.02.2026 |
5.3 |
| CVE-2026-21435 |
webtransport-go CloseWithError can block indefinitely |
12.02.2026 |
5.3 |
| CVE-2026-21438 |
webtransport-go affected by a Memory Exhaustion Attack due to Missing Cleanup of Streams Map |
12.02.2026 |
5.3 |
| CVE-2023-31323 |
|
12.02.2026 |
|
| CVE-2025-54519 |
|
12.02.2026 |
7.3 |
| CVE-2023-20601 |
|
12.02.2026 |
|
| CVE-2024-36319 |
|
13.02.2026 |
|
| CVE-2025-52533 |
|
13.02.2026 |
|
| CVE-2025-63421 |
|
12.02.2026 |
|
| CVE-2025-69806 |
|
12.02.2026 |
|
| CVE-2025-69807 |
|
12.02.2026 |
|