Total
336347 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-2004 | 1 Postgresql | 1 Postgresql | 2026-02-20 | N/A | 8.8 HIGH |
|
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
|
|||||
| CVE-2026-2003 | 1 Postgresql | 1 Postgresql | 2026-02-20 | N/A | 4.3 MEDIUM |
|
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
|
|||||
| CVE-2026-26235 | 1 Jung-group | 2 Smart Visu Server, Smart Visu Server Firmware | 2026-02-20 | N/A | 7.5 HIGH |
|
JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remotely shutdown or reboot the server. Attackers can send a single POST request to trigger the server reboot without requiring any authentication.
|
|||||
| CVE-2026-27181 | 1 Mjdm | 1 Majordomo | 2026-02-20 | N/A | 7.5 HIGH |
|
MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module. The market module's admin() method reads gr('mode') from $_REQUEST and assigns it to $this->mode at the start of execution, making all mode-gated code paths reachable without authentication via the /objects/?module=market endpoint. The uninstall mode handler calls uninstallPlugin(), which deletes module records from the database, executes the module's uninstall() method via eva ...
Show More |
|||||
| CVE-2025-68924 | 1 Umbraco | 1 Umbraco Forms | 2026-02-20 | N/A | 7.5 HIGH |
|
In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.
|
|||||
| CVE-2026-1340 | 1 Ivanti | 1 Endpoint Manager Mobile | 2026-02-20 | N/A | 9.8 CRITICAL |
|
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
|
|||||
| CVE-2026-27180 | 1 Mjdm | 1 Majordomo | 2026-02-20 | N/A | 9.8 CRITICAL |
|
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning. The saverestore module exposes its admin() method through the /objects/?module=saverestore endpoint without authentication because it uses gr('mode') (which reads directly from $_REQUEST) instead of the framework's $this->mode. An attacker can poison the system update URL via the auto_update_settings mode handler, then trigger the force_update han ...
Show More |
|||||
| CVE-2026-26318 | 1 Systeminformation | 1 Systeminformation | 2026-02-20 | N/A | 8.8 HIGH |
|
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.
|
|||||
| CVE-2026-26267 | 1 Stellar | 1 Rs-soroban-sdk | 2026-02-20 | N/A | 7.5 HIGH |
|
soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` macro contains a bug in how it wires up function calls. `#[contractimpl]` generates code that uses `MyContract::value()` style calls even when it's processing the trait version. This means if an inherent function is also defined with the same name, the inherent function gets called instead of the trait function. This means the Wasm-exported entry point silently calls the wrong fu ...
Show More |
|||||
| CVE-2026-26286 | 1 Sillytavern | 1 Sillytavern | 2026-02-20 | N/A | 8.5 HIGH |
|
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions prior to 1.16.0, a Server-Side Request Forgery (SSRF) vulnerability in the asset download endpoint allows authenticated users to make arbitrary HTTP requests from the server and read the full response body, enabling access to internal services, cloud metadata, and private network resources. The vulnerabi ...
Show More |
|||||
| CVE-2026-26282 | 1 M2team | 1 Nanazip | 2026-02-20 | N/A | 6.6 MEDIUM |
|
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, NanaZip has an out-of-bounds heap read in `.NET Single File` bundle header parser due to missing bounds check. Opening a crafted file with NanaZip causes a crash or leaks heap data to the user. Version 6.0.1630.0 patches the issue.
|
|||||
| CVE-2025-33236 | 1 Nvidia | 1 Nemo | 2026-02-20 | N/A | 7.8 HIGH |
|
NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
|
|||||
| CVE-2025-33241 | 1 Nvidia | 1 Nemo | 2026-02-20 | N/A | 7.8 HIGH |
|
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
|
|||||
| CVE-2026-0406 | 1 Netgear | 2 Xr1000v2, Xr1000v2 Firmware | 2026-02-20 | N/A | 8.0 HIGH |
|
An insufficient input validation vulnerability in the NETGEAR XR1000v2
allows attackers connected to the router's LAN to execute OS command
injections.
|
|||||
| CVE-2025-33243 | 1 Nvidia | 1 Nemo | 2026-02-20 | N/A | 7.8 HIGH |
|
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
|
|||||
| CVE-2025-33245 | 1 Nvidia | 1 Nemo | 2026-02-20 | N/A | 8.0 HIGH |
|
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
|
|||||
| CVE-2025-33246 | 1 Nvidia | 1 Nemo | 2026-02-20 | N/A | 7.8 HIGH |
|
NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection by supplying crafted input to a configuration parameter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, or information disclosure.
|
|||||
| CVE-2025-33249 | 1 Nvidia | 1 Nemo | 2026-02-20 | N/A | 7.8 HIGH |
|
NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
|
|||||
| CVE-2026-0408 | 1 Netgear | 8 Ex2800, Ex2800 Firmware, Ex3110 and 5 more | 2026-02-20 | N/A | 8.0 HIGH |
|
A path traversal vulnerability in NETGEAR WiFi range extenders allows
an attacker with LAN authentication to access the router's IP and
review the contents of the dynamically generated webproc file, which
records the username and password submitted to the router GUI.
|
|||||
| CVE-2025-33250 | 1 Nvidia | 1 Nemo | 2026-02-20 | N/A | 7.8 HIGH |
|
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
|
|||||
| CVE-2025-33251 | 1 Nvidia | 1 Nemo | 2026-02-20 | N/A | 7.8 HIGH |
|
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
|
|||||
| CVE-2026-0407 | 1 Netgear | 8 Ex2800, Ex2800 Firmware, Ex3110 and 5 more | 2026-02-20 | N/A | 8.0 HIGH |
|
An insufficient authentication vulnerability in NETGEAR WiFi range
extenders allows a network adjacent attacker with WiFi authentication or
a physical Ethernet port connection to bypass the authentication
process and access the admin panel.
|
|||||
| CVE-2026-26312 | 1 Stalw | 1 Stalwart | 2026-02-20 | N/A | 6.5 MEDIUM |
|
Stalwart is a mail and collaboration server. A denial-of-service vulnerability exists in Stalwart Mail Server versions 0.13.0 through 0.15.4 where accessing a specially crafted email containing malformed nested `message/rfc822` MIME parts via IMAP or JMAP causes excessive CPU and memory consumption, potentially leading to an out-of-memory condition and server crash. The malformed structure causes the `mail-parser` crate to produce cyclical references in its parsed representation, which Stalwart ...
Show More |
|||||
| CVE-2025-33252 | 1 Nvidia | 1 Nemo | 2026-02-20 | N/A | 7.8 HIGH |
|
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
|
|||||
| CVE-2025-33253 | 1 Nvidia | 1 Nemo | 2026-02-20 | N/A | 7.8 HIGH |
|
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
|
|||||
| CVE-2025-15314 | 1 Tanium | 1 End-user-cx | 2026-02-20 | N/A | 5.5 MEDIUM |
|
Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
|
|||||
| CVE-2026-0403 | 1 Netgear | 20 Rbe970, Rbe970 Firmware, Rbe971 and 17 more | 2026-02-20 | N/A | 8.0 HIGH |
|
An insufficient input validation vulnerability in NETGEAR Orbi routers
allows attackers connected to the router's LAN to execute OS command
injections.
|
|||||
| CVE-2025-14728 | 2 Linux, Rapid7 | 2 Linux Kernel, Velociraptor | 2026-02-20 | N/A | 6.8 MEDIUM |
|
Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore directory. The issue occurs due to insufficient sanitization of directory names which end with a ".", only encoding the final "." AS "%2E".
Although files can be written to incorrect locations, the containing directory must end with "%2E". This ...
Show More |
|||||
| CVE-2026-2692 | 1 Cocoteanet | 1 Cyreneadmin | 2026-02-20 | 4.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.3.0. This affects an unknown part of the file /api/system/user/getAvatar of the component Image Handler. Performing a manipulation of the argument Avatar results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used.
|
|||||
| CVE-2026-2693 | 1 Cocoteanet | 1 Cyreneadmin | 2026-02-20 | 4.0 MEDIUM | 4.3 MEDIUM |
|
A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the file /api/system/dashboard/getCount of the component System Info Endpoint. Executing a manipulation can lead to improper authorization. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
|
|||||
| CVE-2026-2605 | 1 Tanium | 1 Tanos | 2026-02-20 | N/A | 5.3 MEDIUM |
|
Tanium addressed an insertion of sensitive information into log file vulnerability in TanOS.
|
|||||
| CVE-2026-26202 | 1 Kaleidos | 1 Penpot | 2026-02-20 | N/A | 7.5 HIGH |
|
Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user can read arbitrary files from the server by supplying a local file path (e.g. `/etc/passwd`) as a font data chunk in the `create-font-variant` RPC endpoint, resulting in the file contents being stored and retrievable as a "font" asset. This is an arbitrary file read vulnerability. Any authenticated user with team edit permissions can read arbitrary files accessible to the Penpot ...
Show More |
|||||
| CVE-2026-2848 | 1 Oretnom23 | 1 Simple Responsive Tourism Website | 2026-02-20 | 7.5 HIGH | 7.3 HIGH |
|
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
|
|||||
| CVE-2026-26967 | 1 Pjsip | 1 Pjsip | 2026-02-20 | N/A | 5.3 MEDIUM |
|
PJSIP is a free and open source multimedia communication library written in C. In versions 2.16 and below, there is a critical Heap-based Buffer Overflow vulnerability in PJSIP's H.264 unpacketizer. The bug occurs when processing malformed SRTP packets, where the unpacketizer reads a 2-byte NAL unit size field without validating that both bytes are within the payload buffer bounds. The vulnerability affects applications that receive video using H.264. A patch is available at https://github.com/p ...
Show More |
|||||
| CVE-2026-27014 | 1 M2team | 1 Nanazip | 2026-02-20 | N/A | 5.5 MEDIUM |
|
NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested directories cause unbounded recursion (stack overflow) in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.
|
|||||
| CVE-2026-26960 | 1 Isaacs | 1 Tar | 2026-02-20 | N/A | 7.1 HIGH |
|
node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.
|
|||||
| CVE-2026-24959 | 2026-02-20 | N/A | 8.5 HIGH | ||
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.1.
|
|||||
| CVE-2026-24955 | 2026-02-20 | N/A | 7.1 HIGH | ||
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Whizz Plugins whizz-plugins allows Reflected XSS.This issue affects Whizz Plugins: from n/a through <= 1.9.
|
|||||
| CVE-2026-24950 | 2026-02-20 | N/A | 7.5 HIGH | ||
|
Authorization Bypass Through User-Controlled Key vulnerability in themeplugs Authorsy authorsy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Authorsy: from n/a through <= 1.0.6.
|
|||||
| CVE-2026-24948 | 2026-02-20 | N/A | 7.1 HIGH | ||
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Reflector reflector-plugins allows Reflected XSS.This issue affects Reflector: from n/a through <= 1.2.2.
|
|||||