Total
336347 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-30410 | 2026-02-20 | N/A | 9.8 CRITICAL | ||
|
Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 41800.
|
|||||
| CVE-2026-21620 | 2026-02-20 | N/A | N/A | ||
|
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. This vulnerability is associated with program files lib/tftp/src/tftp_file.erl, src/tftp_file.erl.
This issue affects otp: from 17.0, from 07b8f441ca711f9812fad9e9115bab3c3aa92f79; otp: from 5.10 before 7.0; otp: from 1.0.
|
|||||
| CVE-2026-26958 | 2026-02-20 | N/A | N/A | ||
|
filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographic primitives. In versions 1.1.0 and earlier, MultiScalarMult produces invalid results or undefined behavior if the receiver is not the identity point. If (*Point).MultiScalarMult is called on an initialized point that is not the identity point, it returns an incorrect result. If the method is called on an uninitialized point, the behavior is undefined. In particular, if the rec ...
Show More |
|||||
| CVE-2026-26063 | 2026-02-20 | N/A | N/A | ||
|
CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attackers to bypass input validation in the transaction API. The issue has been fixed in version 1.2.3. If upgrading is not immediately possible, restrict API access to trusted networks or IP ranges; enforce strict input validation at the application layer; and/or monitor transaction logs for anomalies or suspicious activity. These mitigations reduce exposure but do not fully elimina ...
Show More |
|||||
| CVE-2026-27476 | 2026-02-20 | N/A | 9.8 CRITICAL | ||
|
RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 without proper sanitization. Attackers can send crafted hex-encoded payloads containing system commands to execute arbitrary operations on the target system, including reverse shell establishment and command execution.
|
|||||
| CVE-2026-2232 | 2026-02-20 | N/A | 7.5 HIGH | ||
|
The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 4.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
|
|||||
| CVE-2026-2738 | 2026-02-20 | N/A | N/A | ||
|
Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peer when the AEAD tag appears at the end of the encrypted packet
|
|||||
| CVE-2026-26953 | 2026-02-20 | N/A | 5.4 MEDIUM | ||
|
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and above have a Stored HTML Injection vulnerability in the active sessions table located on the API settings page, allowing an attacker with valid credentials to inject arbitrary HTML code that will be rendered in the browser of any administrator who visits the active sessions page. The rowCallback function contains the value data.x_forwarded_for, which is ...
Show More |
|||||
| CVE-2026-26952 | 2026-02-20 | N/A | 5.4 MEDIUM | ||
|
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below are vulnerable to stored HTML injection through the local DNS records configuration page, which allows an authenticated administrator to inject code that is stored in the Pi-hole configuration and rendered every time the DNS records table is viewed. The populateDataTable() function contains a data variable with the full DNS record value exactly as ...
Show More |
|||||
| CVE-2026-27328 | 2026-02-20 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in DevsBlink EduBlink edublink allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EduBlink: from n/a through <= 2.0.7.
|
|||||
| CVE-2026-26050 | 2026-02-20 | N/A | 7.8 HIGH | ||
|
The installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with administrative privileges.
|
|||||
| CVE-2026-20139 | 1 Splunk | 2 Splunk, Splunk Cloud Platform | 2026-02-20 | N/A | 4.3 MEDIUM |
|
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.8, 9.3.9, and 9.2.12, and Splunk Cloud Platform versions below 10.2.2510.3, 10.1.2507.8, 10.0.2503.9, and 9.3.2411.121, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload into the `realname`, `tz`, or `email` parameters of the `/splunkd/__raw/services/authentication/users/username` REST API endpoint when they change a password. This could potentially lead to a client‑side denial‑of‑s ...
Show More |
|||||
| CVE-2026-1470 | 1 N8n | 1 N8n | 2026-02-20 | N/A | 9.9 CRITICAL |
|
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime.
An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including una ...
Show More |
|||||
| CVE-2026-0760 | 1 Deepwisdom | 1 Metagpt | 2026-02-20 | N/A | 9.8 CRITICAL |
|
Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the deserialize_message function. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data ...
Show More |
|||||
| CVE-2026-0761 | 1 Deepwisdom | 1 Metagpt | 2026-02-20 | N/A | 9.8 CRITICAL |
|
Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the actionoutput_str_to_mapping function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker c ...
Show More |
|||||
| CVE-2026-26731 | 1 Totolink | 2 A3002ru-v2, A3002ru Firmware | 2026-02-20 | N/A | 8.8 HIGH |
|
TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the routernamer`parameter in the formDnsv6 function.
|
|||||
| CVE-2026-26732 | 1 Totolink | 2 A3002ru-v2, A3002ru Firmware | 2026-02-20 | N/A | 8.8 HIGH |
|
TOTOLINK A3002RU V2.1.1-B20211108.1455 was discovered to contain a stack-based buffer overflow via the vpnUser or vpnPassword` parameters in the formFilter function.
|
|||||
| CVE-2026-26736 | 1 Totolink | 2 A3002ru-v3, A3002ru Firmware | 2026-02-20 | N/A | 8.8 HIGH |
|
TOTOLINK A3002RU_V3 V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the static_ipv6 parameter in the formIpv6Setup function.
|
|||||
| CVE-2026-2629 | 2026-02-20 | 7.5 HIGH | 7.3 HIGH | ||
|
A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is the function Promise of the file lib/tts-providers/mac-os.js of the component TTS Provider. This manipulation of the argument phrase causes os command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no ver ...
Show More |
|||||
| CVE-2026-27325 | 2026-02-20 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-27324 | 2026-02-20 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-27323 | 2026-02-20 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-27322 | 2026-02-20 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-27321 | 2026-02-20 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-27320 | 2026-02-20 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-27319 | 2026-02-20 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-27318 | 2026-02-20 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-27317 | 2026-02-20 | N/A | N/A | ||
|
Rejected reason: Not used
|
|||||
| CVE-2026-26995 | 2026-02-20 | N/A | N/A | ||
|
Rejected reason: Further research determined the issue is an external dependency vulnerability.
|
|||||
| CVE-2026-21434 | 1 Quic-go | 1 Webtransport-go | 2026-02-19 | N/A | 5.3 MEDIUM |
|
webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive memory consumption in webtransport-go's session implementation by sending a WT_CLOSE_SESSION capsule containing an excessively large Application Error Message. The implementation does not enforce the draft-mandated limit of 1024 bytes on this field, allowing a peer to send an arbitrarily large message payload that is fully read and stored in memory. This allows an attacker to c ...
Show More |
|||||
| CVE-2026-21435 | 1 Quic-go | 1 Webtransport-go | 2026-02-19 | N/A | 5.3 MEDIUM |
|
webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by preventing or indefinitely delaying WebTransport session closure. A malicious peer can withhold QUIC flow control credit on the CONNECT stream, blocking transmission of the WT_CLOSE_SESSION capsule and causing the close operation to hang. This vulnerability is fixed in v0.10.0.
|
|||||
| CVE-2026-21438 | 1 Quic-go | 1 Webtransport-go | 2026-02-19 | N/A | 5.3 MEDIUM |
|
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Closed streams were not removed from an internal session map, preventing garbage collection of their resources. This vulnerability is fixed in v0.10.0.
|
|||||
| CVE-2026-0573 | 1 Github | 1 Enterprise Server | 2026-02-19 | N/A | 9.0 CRITICAL |
|
An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorization tokens. The repository_pages API insecurely followed HTTP redirects when fetching artifact URLs, preserving the authorization header containing a privileged JWT. An authenticated user could redirect these requests to an attacker-controlled domain, exfiltrate the Actions.ManageOrgs JWT, and leverage it for potential remote code execution. Attackers ...
Show More |
|||||
| CVE-2026-27056 | 2026-02-19 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in StellarWP iThemes Sync ithemes-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iThemes Sync: from n/a through <= 3.2.8.
|
|||||
| CVE-2026-25348 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Alt Text AI: from n/a through <= 1.10.15.
|
|||||
| CVE-2026-25338 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.7.4.
|
|||||
| CVE-2026-25336 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in wpcoachify Coachify coachify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coachify: from n/a through <= 1.1.5.
|
|||||
| CVE-2026-25333 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in peregrinethemes Shopwell shopwell allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shopwell: from n/a through <= 1.0.11.
|
|||||
| CVE-2026-25325 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through <= 4.7.8.
|
|||||
| CVE-2026-25321 | 2026-02-19 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in PSM Plugins SupportCandy supportcandy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SupportCandy: from n/a through <= 3.4.4.
|
|||||