| CVE-2025-41002 |
SQL injection in Infoticketing |
23.02.2026 |
9.3 |
| CVE-2026-24494 |
SQL injection vulnerability in Order Up Online Ordering System |
23.02.2026 |
9.8 |
| CVE-2026-27574 |
OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCE |
21.02.2026 |
10 |
| CVE-2026-27452 |
ASN.1 TypeScript Library: Decoding an INTEGER could leak the underlying ArrayBuffer |
21.02.2026 |
9.2 |
| CVE-2026-27471 |
ERP: Document access through endpoints due to missing validation |
21.02.2026 |
9.3 |
| CVE-2026-27211 |
Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse |
21.02.2026 |
9.1 |
| CVE-2026-27212 |
Swiper has a Prototype Pollution Vulnerability |
21.02.2026 |
9.4 |
| CVE-2026-27197 |
Sentry: Improper Authentication on SAML SSO process allows user identity linking |
21.02.2026 |
9.1 |
| CVE-2019-25441 |
thesystem 1.0 Command Injection via run_command endpoint |
20.02.2026 |
9.3 |
| CVE-2026-2635 |
MLflow Use of Default Password Authentication Bypass Vulnerability |
20.02.2026 |
9.8 |
| CVE-2026-27112 |
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints |
20.02.2026 |
9.4 |
| CVE-2026-25896 |
fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names |
20.02.2026 |
9.3 |
| CVE-2021-35402 |
|
20.02.2026 |
10 |
| CVE-2026-2333 |
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds |
20.02.2026 |
9.2 |
| CVE-2026-25715 |
Jinan USR IOT Technology Limited (PUSR) USR-W610 Weak Password Requirements |
20.02.2026 |
9.8 |
| CVE-2026-21627 |
Extension - tassos.gr - SQL injection and Unauthenticated File Read in Novarain/Tassos Framework v4.10.14 – v6.0.37 for Joomla |
23.02.2026 |
9.5 |
| CVE-2025-10970 |
SQLi in Kolay Software's Talentics |
20.02.2026 |
9.8 |
| CVE-2026-26064 |
calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execution |
20.02.2026 |
9.3 |
| CVE-2026-26065 |
calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution |
20.02.2026 |
9.3 |
| CVE-2026-26980 |
Ghost has a SQL Injection in its Content API |
20.02.2026 |
9.4 |
| CVE-2026-26988 |
LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream |
20.02.2026 |
9.3 |
| CVE-2025-30410 |
|
21.02.2026 |
9.8 |
| CVE-2025-30411 |
|
21.02.2026 |
10 |
| CVE-2025-30412 |
|
21.02.2026 |
10 |
| CVE-2025-30416 |
|
21.02.2026 |
10 |
| CVE-2026-27476 |
RustFly 2.0.0 Command Injection via UDP Remote Control |
20.02.2026 |
9.3 |
| CVE-2026-27475 |
SPIP < 4.4.9 Insecure Deserialization |
20.02.2026 |
9.2 |
| CVE-2026-2409 |
|
20.02.2026 |
9.3 |
| CVE-2026-26339 |
Hyland Alfresco Transformation Service Argument Injection RCE |
20.02.2026 |
9.3 |
| CVE-2026-24834 |
Kata Container to Guest micro VM privilege escalation |
21.02.2026 |
9.4 |
| CVE-2026-26016 |
Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization |
20.02.2026 |
9.2 |
| CVE-2026-26030 |
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution |
20.02.2026 |
10 |
| CVE-2025-71243 |
SPIP Saisies Plugin < 5.11.1 Remote Code Execution |
19.02.2026 |
9.3 |
| CVE-2025-9953 |
SQLi in Database Software's Databank Accreditation Software |
20.02.2026 |
9.8 |
| CVE-2025-8350 |
Authentication Bypass with Redirect in BiEticaret Software's BiEticaret CMS |
20.02.2026 |
9.8 |
| CVE-2025-12107 |
Potential authenticated Server-Side Template Injection (SSTI) vulnerability. |
20.02.2026 |
10 |
| CVE-2025-13590 |
Authenticated arbitrary file upload via a System REST API requiring administrator permission. |
20.02.2026 |
9.1 |
| CVE-2026-1994 |
s2Member <= 260127 - Unauthenticated Privilege Escalation via Account Takeover |
19.02.2026 |
9.8 |
| CVE-2026-2731 |
Unauthenticated RCE in Dynamicweb 9 and Dynamicweb 8 |
19.02.2026 |
10 |
| CVE-2025-13563 |
Lizza LMS Pro <= 1.0.3 - Unauthenticated Privilege Escalation |
19.02.2026 |
9.8 |
| CVE-2025-13851 |
Buyent Theme (with Buyent Classified Plugin) <= 1.0.7 - Unauthenticated Privilege Escalation via User Registration |
19.02.2026 |
9.8 |
| CVE-2026-0926 |
Prodigy Commerce <= 3.2.9 - Unauthenticated Local File Inclusion via parameters[template_name] |
19.02.2026 |
9.8 |
| CVE-2026-1405 |
Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload |
19.02.2026 |
9.8 |
| CVE-2025-12882 |
Clasifico Listing <= 2.0 - Unauthenticated Privilege Escalation |
19.02.2026 |
9.8 |
| CVE-2025-15586 |
|
19.02.2026 |
10 |
| CVE-2026-2686 |
SECCN Dingcheng G10 session_login.cgi qq os command injection |
23.02.2026 |
9.3 |
| CVE-2026-25548 |
InvoicePlane Vulnerable to Remote Code Execution via Local File Inclusion and Log Poisoning |
19.02.2026 |
9.1 |
| CVE-2019-25362 |
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer OverFlow |
19.02.2026 |
9.3 |
| CVE-2019-25364 |
Win10 MailCarrier 2.51 - 'POP3 User' Remote Buffer Overflow |
19.02.2026 |
9.3 |
| CVE-2026-27174 |
MajorDoMo Unauthenticated Remote Code Execution via Admin Console Eval |
18.02.2026 |
9.3 |
| CVE-2026-27175 |
MajorDoMo Command Injection in rc/index.php via Race Condition |
18.02.2026 |
9.2 |
| CVE-2026-27180 |
MajorDoMo Supply Chain Remote Code Execution via Update URL Poisoning |
20.02.2026 |
9.3 |
| CVE-2026-23491 |
InvoicePlane has Unauthenticated Path Traversal in Guest Controller |
18.02.2026 |
9.3 |
| CVE-2025-14009 |
Zip Slip Vulnerability in nltk/nltk Leading to Remote Code Execution |
19.02.2026 |
10 |
| CVE-2025-70152 |
|
18.02.2026 |
9.8 |
| CVE-2025-70150 |
|
18.02.2026 |
9.8 |
| CVE-2025-15579 |
An Insecure Deserialization vulnerability has been discovered in OpenText™ Directory Services. |
18.02.2026 |
9.5 |
| CVE-2026-2329 |
Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow |
18.02.2026 |
9.3 |
| CVE-2026-1435 |
Incorrect management of session invalidation vulnerability in Graylog Web Interface |
18.02.2026 |
9.3 |
| CVE-2026-1937 |
YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action |
18.02.2026 |
9.8 |
| CVE-2026-1670 |
Honeywell CCTV Products Missing Authentication for Critical Function |
18.02.2026 |
9.3 |
| CVE-2026-22769 |
|
19.02.2026 |
10 |
| CVE-2026-23647 |
Glory RBG-100 Recycler System Hard-coded OS Credentials |
18.02.2026 |
9.3 |
| CVE-2026-22208 |
OpenS100 Portrayal Engine Unrestricted Lua Standard Library Access |
17.02.2026 |
9.4 |
| CVE-2026-26220 |
LightLLM <= 1.1.0 PD Mode Unsafe Deserialization RCE |
17.02.2026 |
9.3 |