| CVE-2026-2090 |
SourceCodester Online Class Record System search.php sql injection |
07.02.2026 |
|
| CVE-2026-2089 |
SourceCodester Online Class Record System controller.php sql injection |
07.02.2026 |
|
| CVE-2026-2088 |
PHPGurukul Beauty Parlour Management System accepted-appointment.php sql injection |
07.02.2026 |
|
| CVE-2026-2087 |
SourceCodester Online Class Record System login.php sql injection |
07.02.2026 |
|
| CVE-2026-2086 |
UTT HiPER 810G Management formFireWall strcpy buffer overflow |
07.02.2026 |
|
| CVE-2026-2085 |
D-Link DWR-M921 USSD Configuration Endpoint formUSSDSetup sub_419F20 command injection |
07.02.2026 |
|
| CVE-2026-2084 |
D-Link DIR-823X set_language os command injection |
07.02.2026 |
|
| CVE-2026-2083 |
code-projects Social Networking Site delete_post.php sql injection |
07.02.2026 |
|
| CVE-2026-2082 |
D-Link DIR-823X set_mac_clone os command injection |
07.02.2026 |
|
| CVE-2026-2081 |
D-Link DIR-823X set_password os command injection |
07.02.2026 |
|
| CVE-2026-2080 |
UTT HiPER 810 formUser setSysAdm command injection |
07.02.2026 |
|
| CVE-2025-15476 |
The Bucketlister <= 0.1.5 - Missing Authorization to Authenticated (Subscriber+) Bucket List Modification |
07.02.2026 |
4.3 |
| CVE-2025-15477 |
The Bucketlister <= 0.1.5 - Authenticated (Contributor+) SQL Injection via `category` and `id` Shortcode Attributes |
07.02.2026 |
6.5 |
| CVE-2026-0555 |
Premmerce <= 1.3.20 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'premmerce_wizard_actions' AJAX Endpoint |
07.02.2026 |
6.4 |
| CVE-2026-1082 |
TITLE ANIMATOR <= 1.0 - Cross-Site Request Forgery to Settings Update |
07.02.2026 |
4.3 |
| CVE-2026-1570 |
Simple Bible Verse via Shortcode <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
07.02.2026 |
6.4 |
| CVE-2026-1573 |
OMIGO <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
07.02.2026 |
6.4 |
| CVE-2026-1608 |
Video Onclick <= 0.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
07.02.2026 |
6.4 |
| CVE-2026-1611 |
Wikiloops Track Player <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
07.02.2026 |
6.4 |
| CVE-2026-1613 |
Wonka Slide <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
07.02.2026 |
6.4 |
| CVE-2026-1634 |
Subitem AL Slider <= 1.0.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] |
07.02.2026 |
6.1 |
| CVE-2026-1643 |
MP-Ukagaka <= 1.5.2 - Reflected Cross-Site Scripting |
07.02.2026 |
6.1 |
| CVE-2026-1675 |
Advanced Country Blocker <= 2.3.1 - Unauthenticated Authorization Bypass via Insecure Default Secret Key |
07.02.2026 |
5.3 |
| CVE-2026-2079 |
yeqifu warehouse Menu Management MenuController.java deleteMenu improper authorization |
07.02.2026 |
|
| CVE-2026-2078 |
yeqifu warehouse Permission Management PermissionController.java deletePermission improper authorization |
07.02.2026 |
|
| CVE-2026-2077 |
yeqifu warehouse Role Management RoleController.java deleteRole improper authorization |
07.02.2026 |
|
| CVE-2026-2076 |
yeqifu warehouse User Management Endpoint UserController.java deleteUser improper authorization |
07.02.2026 |
|
| CVE-2025-15491 |
Post Slides <= 1.0.1 - Contributor+ Local File Inclusion |
07.02.2026 |
|
| CVE-2025-12159 |
Bold Page Builder <= 5.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
07.02.2026 |
6.4 |
| CVE-2025-12803 |
Bold Builder <= 5.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_tabs Shortcode |
07.02.2026 |
6.4 |
| CVE-2025-13463 |
Bold Page Builder <= 5.5.3 - Authenticated (Author+) Stored DOM-based Cross-Site Scripting in Post Grid |
07.02.2026 |
6.4 |
| CVE-2025-15267 |
Bold Page Builder <= 5.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_accordion_item Shortcode |
07.02.2026 |
6.4 |
| CVE-2026-2075 |
yeqifu warehouse Role-Permission Binding RoleController.java saveRolePermission access control |
07.02.2026 |
|
| CVE-2026-2074 |
O2OA HTTP POST Request check xml external entity reference |
07.02.2026 |
|
| CVE-2025-31990 |
HCL DevOps Velocity is susceptible to a Denial of Service vulnerability |
07.02.2026 |
6.8 |
| CVE-2026-25837 |
|
07.02.2026 |
|
| CVE-2026-25838 |
|
07.02.2026 |
|
| CVE-2026-25839 |
|
07.02.2026 |
|
| CVE-2026-25840 |
|
07.02.2026 |
|
| CVE-2026-25841 |
|
07.02.2026 |
|
| CVE-2026-25842 |
|
07.02.2026 |
|
| CVE-2026-25843 |
|
07.02.2026 |
|
| CVE-2026-25844 |
|
07.02.2026 |
|
| CVE-2026-25845 |
|
07.02.2026 |
|
| CVE-2026-2073 |
itsourcecode School Management System index.php sql injection |
07.02.2026 |
|
| CVE-2026-2071 |
UTT 进取 520W formP2PLimitConfig strcpy buffer overflow |
07.02.2026 |
|
| CVE-2020-37079 |
Wing FTP Server < 6.2.7 - Cross-site Request Forgery |
06.02.2026 |
|
| CVE-2020-37095 |
Cyberoam Authentication Client 2.1.2.7 - Buffer Overflow (SEH) |
06.02.2026 |
|
| CVE-2020-37106 |
Business Live Chat Software 1.0 - Cross-Site Request Forgery (Add Admin) |
06.02.2026 |
|
| CVE-2020-37107 |
Core FTP LE 2.2 - Denial of Service |
06.02.2026 |
|
| CVE-2020-37109 |
aSc TimeTables 2020.11.4 - Denial of Service |
06.02.2026 |
|
| CVE-2020-37122 |
SpotFTP-FTP Password Recover 2.4.8 - Denial of Service |
06.02.2026 |
|
| CVE-2020-37135 |
AMSS++ 4.7 - Backdoor Admin Account |
06.02.2026 |
|
| CVE-2020-37141 |
AMSS++ v 4.31 - 'id' SQL Injection |
06.02.2026 |
|
| CVE-2020-37146 |
Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure |
06.02.2026 |
|
| CVE-2020-37147 |
ATutor 2.2.4 - 'id' SQL Injection |
06.02.2026 |
|
| CVE-2020-37154 |
eLection 2.0 - 'id' SQL Injection |
06.02.2026 |
|
| CVE-2020-37155 |
Core FTP Lite 1.3 - Denial of Service (PoC) |
06.02.2026 |
|
| CVE-2020-37157 |
DBPower C300 HD Camera - Remote Configuration Disclosure |
06.02.2026 |
|
| CVE-2020-37159 |
Cuckoo Clock 5.0 - Buffer Overflow |
06.02.2026 |
|
| CVE-2020-37160 |
SprintWork 2.3.1 - Local Privilege Escalation |
06.02.2026 |
|
| CVE-2020-37161 |
Wedding Slideshow Studio 1.36 - 'Name' Buffer Overflow |
06.02.2026 |
|
| CVE-2020-37162 |
Wedding Slideshow Studio 1.36 - 'Key' Buffer Overflow |
06.02.2026 |
|
| CVE-2020-37163 |
QuickDate 1.3.2 - SQL Injection |
06.02.2026 |
|
| CVE-2020-37164 |
AbsoluteTelnet 11.12 - "license entry" Denial of Service |
06.02.2026 |
|
| CVE-2020-37165 |
AbsoluteTelnet 11.12 - "license name" Denial of Service |
06.02.2026 |
|
| CVE-2020-37166 |
AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service |
06.02.2026 |
|
| CVE-2020-37170 |
TapinRadio 2.12.3 - 'address' Denial of Service |
06.02.2026 |
|
| CVE-2020-37171 |
TapinRadio 2.12.3 - 'username' Denial of Service |
06.02.2026 |
|
| CVE-2026-25793 |
Nebula Has Possible Blocklist Bypass via ECDSA Signature Malleability |
06.02.2026 |
|
| CVE-2026-25803 |
3DP-MANAGER Uses Hard-coded Credentials |
06.02.2026 |
9.8 |
| CVE-2026-25804 |
Antrea has invalid enforcement order for network policy rules caused by integer overflow |
06.02.2026 |
|
| CVE-2026-25644 |
DataHub's LDAP Ingestion Source vulnerable to MITM attack through TLS downgrade |
06.02.2026 |
7.5 |
| CVE-2026-25749 |
Heap Overflow in Vim |
06.02.2026 |
6.6 |
| CVE-2026-25754 |
AdonisJS multipart body parsing has Prototype Pollution issue |
06.02.2026 |
7.2 |
| CVE-2026-25762 |
AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection |
06.02.2026 |
7.5 |
| CVE-2026-25757 |
Unauthenticated Spree Commerce users can view completed guest orders by Order ID |
06.02.2026 |
|
| CVE-2026-2070 |
UTT 进取 520W formPolicyRouteConf strcpy buffer overflow |
06.02.2026 |
|
| CVE-2023-6763 |
|
06.02.2026 |
|
| CVE-2026-25763 |
Command Injection on OpenProject repositories leads to Remote Code Execution |
06.02.2026 |
|
| CVE-2026-25764 |
OpenProject vulnerable to Stored HTML injection |
06.02.2026 |
3.5 |
| CVE-2026-2069 |
ggml-org llama.cpp GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based overflow |
06.02.2026 |
|
| CVE-2026-1731 |
Remote code execution vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) |
06.02.2026 |
|
| CVE-2026-1727 |
Information Disclosure via Bucket Squatting in Google Cloud Agentspace. |
06.02.2026 |
|
| CVE-2026-25760 |
Website Path Traversal / Arbitrary File Read (Authenticated) in Sliver |
06.02.2026 |
6.5 |
| CVE-2026-2068 |
UTT 进取 520W formSyslogConf strcpy buffer overflow |
06.02.2026 |
|
| CVE-2025-68621 |
Trilium Notes has a Timing Attack Vulnerability in /api/login/sync |
06.02.2026 |
7.4 |
| CVE-2026-25123 |
Homarr affected by Unauthenticated SSRF / Port-Scan Primitive via widget.app.ping |
06.02.2026 |
5.3 |
| CVE-2026-25533 |
Enclave has a sandbox escape via infinite recursion and error objects |
06.02.2026 |
|
| CVE-2026-25758 |
Spree allows unauthenticated users can access all guest addresses |
06.02.2026 |
|
| CVE-2026-25516 |
NiceGUI's XSS vulnerability in ui.markdown() allows arbitrary JavaScript execution through unsanitized HTML content |
06.02.2026 |
6.1 |
| CVE-2026-25732 |
NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write |
06.02.2026 |
7.5 |