Total
336347 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-15417 | 1 Open5gs | 1 Open5gs | 2026-02-23 | 1.7 LOW | 3.3 LOW |
|
A vulnerability was identified in Open5GS up to 2.7.6. Affected is the function sgwc_s11_handle_create_session_request of the file src/sgwc/s11-handler.c of the component GTPv2-C F-TEID Handler. Such manipulation leads to denial of service. The attack must be carried out locally. The exploit is publicly available and might be used. The name of the patch is 465273d13ba5d47b274c38c9d1b07f04859178a1. A patch should be applied to remediate this issue.
|
|||||
| CVE-2025-15414 | 2026-02-23 | 5.8 MEDIUM | 4.7 MEDIUM | ||
|
A flaw has been found in go-sonic sonic up to 1.1.4. The affected element is the function FetchTheme of the file service/theme/git_fetcher.go of the component Theme Fetching API. Executing a manipulation of the argument uri can lead to server-side request forgery. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2025-15413 | 1 Wasm3 Project | 1 Wasm3 | 2026-02-23 | 4.3 MEDIUM | 5.3 MEDIUM |
|
A vulnerability was detected in wasm3 up to 0.5.0. Impacted is the function op_SetSlot_i32/op_CallIndirect of the file m3_exec.h. Performing a manipulation results in memory corruption. The attack needs to be approached locally. The exploit is now public and may be used. Unfortunately, the project has no active maintainer at the moment.
|
|||||
| CVE-2025-15412 | 1 Webassembly | 1 Wabt | 2026-02-23 | 4.3 MEDIUM | 5.3 MEDIUM |
|
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the resea ...
Show More |
|||||
| CVE-2025-15411 | 1 Webassembly | 1 Wabt | 2026-02-23 | 4.3 MEDIUM | 5.3 MEDIUM |
|
A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recomm ...
Show More |
|||||
| CVE-2025-15409 | 1 Anisha | 1 Online Guitar Store | 2026-02-23 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Delete_product.php. Executing a manipulation of the argument del_pro can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
|
|||||
| CVE-2025-15408 | 1 Anisha | 1 Online Guitar Store | 2026-02-23 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing a manipulation of the argument dre_title results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
|
|||||
| CVE-2024-14020 | 2026-02-23 | 4.6 MEDIUM | 5.0 MEDIUM | ||
|
A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/input.js of the component Formatter Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack can be launched remotely. This attack is characterized by high complexity. The exploitability is said to be difficult. Upgrading to version 3.5.6 will fix this issue. This patch is called 04f ...
Show More |
|||||
| CVE-2023-7333 | 2026-02-23 | 4.3 MEDIUM | 5.3 MEDIUM | ||
|
A weakness has been identified in bluelabsio records-mover up to 1.5.4. The affected element is an unknown function of the component Table Object Handler. This manipulation causes sql injection. The attack needs to be launched locally. Upgrading to version 1.6.0 is sufficient to fix this issue. Patch name: 3f8383aa89f45d861ca081e3e9fd2cc9d0b5dfaa. You should upgrade the affected component.
|
|||||
| CVE-2023-6910 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 6.5 MEDIUM |
|
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.
|
|||||
| CVE-2023-6239 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 5.4 MEDIUM |
|
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
|
|||||
| CVE-2023-6189 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 4.3 MEDIUM |
|
Missing access permissions checks
in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export
jobs using the M-Files API methods.
|
|||||
| CVE-2023-6117 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 5.7 MEDIUM |
|
A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server
before 23.11.13156.0 which allows attackers to execute DoS attacks.
|
|||||
| CVE-2023-5524 | 1 M-files | 1 Web Companion | 2026-02-23 | N/A | 8.2 HIGH |
|
Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows
Remote Code Execution
via specific file types
|
|||||
| CVE-2023-5523 | 1 M-files | 1 Web Companion | 2026-02-23 | N/A | 8.6 HIGH |
|
Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows
Remote Code Execution
|
|||||
| CVE-2023-4479 | 1 M-files | 1 M-files | 2026-02-23 | N/A | 7.3 HIGH |
|
Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.
|
|||||
| CVE-2023-3425 | 1 M-files | 1 Classic Web | 2026-02-23 | N/A | 6.5 MEDIUM |
|
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.
|
|||||
| CVE-2023-3406 | 1 M-files | 1 Classic Web | 2026-02-23 | N/A | 7.7 HIGH |
|
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
|
|||||
| CVE-2023-3405 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 7.5 HIGH |
|
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
|
|||||
| CVE-2023-2480 | 1 M-files | 1 M-files | 2026-02-23 | N/A | 7.5 HIGH |
|
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
|
|||||
| CVE-2023-2325 | 1 M-files | 1 Classic Web | 2026-02-23 | N/A | 7.3 HIGH |
|
Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.
|
|||||
| CVE-2023-2112 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 3.6 LOW |
|
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
|
|||||
| CVE-2023-0384 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 6.5 MEDIUM |
|
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1
due to uncontrolled memory consumption for a scheduled job.
|
|||||
| CVE-2023-0383 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 7.5 HIGH |
|
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1
due to uncontrolled memory consumption.
|
|||||
| CVE-2023-0382 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 6.5 MEDIUM |
|
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1
due to uncontrolled memory consumption.
|
|||||
| CVE-2023-0213 | 2 M-files, Microsoft | 2 M-files, Windows | 2026-02-23 | N/A | 8.8 HIGH |
|
Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.
|
|||||
| CVE-2022-4862 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 5.0 MEDIUM |
|
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information.
This issue affects M-Files New Web: before 22.12.12140.3.
|
|||||
| CVE-2022-4861 | 1 M-files | 1 M-files Client | 2026-02-23 | N/A | 4.8 MEDIUM |
|
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
|
|||||
| CVE-2022-4858 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 4.4 MEDIUM |
|
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
|
|||||
| CVE-2022-4270 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 2.0 LOW |
|
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.
|
|||||
| CVE-2022-1911 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 5.3 MEDIUM |
|
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.
|
|||||
| CVE-2022-4264 | 1 M-files | 1 M-files | 2026-02-23 | N/A | 6.5 MEDIUM |
|
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.
|
|||||
| CVE-2022-3284 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 6.5 MEDIUM |
|
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0.
This issue affects M-Files New Web: before 22.11.12011.0.
|
|||||
| CVE-2022-1606 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 2.4 LOW |
|
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
|
|||||
| CVE-2021-41809 | 1 M-files | 1 M-files Server | 2026-02-23 | 4.0 MEDIUM | 3.5 LOW |
|
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.
|
|||||
| CVE-2021-41808 | 1 M-files | 1 M-files Server | 2026-02-23 | 1.9 LOW | 2.0 LOW |
|
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
|
|||||
| CVE-2021-41807 | 1 M-files | 2 M-files Server, M-files Web | 2026-02-23 | 5.0 MEDIUM | 7.5 HIGH |
|
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
|
|||||
| CVE-2026-23230 | 2026-02-23 | N/A | N/A | ||
|
In the Linux kernel, the following vulnerability has been resolved:
smb: client: split cached_fid bitfields to avoid shared-byte RMW races
is_open, has_lease and on_list are stored in the same bitfield byte in
struct cached_fid but are updated in different code paths that may run
concurrently. Bitfield assignments generate byte read–modify–write
operations (e.g. `orb $mask, addr` on x86_64), so updating one flag can
restore stale values of the others.
A possible interleaving is:
CPU1: loa ...
Show More |
|||||
| CVE-2026-23229 | 2026-02-23 | N/A | N/A | ||
|
In the Linux kernel, the following vulnerability has been resolved:
crypto: virtio - Add spinlock protection with virtqueue notification
When VM boots with one virtio-crypto PCI device and builtin backend,
run openssl benchmark command with multiple processes, such as
openssl speed -evp aes-128-cbc -engine afalg -seconds 10 -multi 32
openssl processes will hangup and there is error reported like this:
virtio_crypto virtio0: dataq.0:id 3 is not a head!
It seems that the data virtqueue nee ...
Show More |
|||||
| CVE-2026-23228 | 2026-02-23 | N/A | N/A | ||
|
In the Linux kernel, the following vulnerability has been resolved:
smb: server: fix leak of active_num_conn in ksmbd_tcp_new_connection()
On kthread_run() failure in ksmbd_tcp_new_connection(), the transport is
freed via free_transport(), which does not decrement active_num_conn,
leaking this counter.
Replace free_transport() with ksmbd_tcp_disconnect().
|
|||||