Total
336347 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-11547 | 1 Axis | 1 Camera Station Pro | 2026-02-17 | N/A | 7.8 HIGH |
|
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
|
|||||
| CVE-2026-24328 | 1 Sap | 1 Business Server Pages | 2026-02-17 | N/A | 6.1 MEDIUM |
|
SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.
|
|||||
| CVE-2025-12757 | 1 Axis | 1 Camera Station Pro | 2026-02-17 | N/A | 4.6 MEDIUM |
|
An AXIS Camera Station Pro feature can be exploited in a way that allows a non-admin user to view information they are not permitted to.
|
|||||
| CVE-2025-13064 | 1 Axis | 1 Camera Station Pro | 2026-02-17 | N/A | 4.5 MEDIUM |
|
A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script which is executed by the server. This attack is only possible if the admin uses a client that have been tampered with.
|
|||||
| CVE-2025-65120 | 1 Groupsession | 1 Groupsession | 2026-02-17 | N/A | 6.1 MEDIUM |
|
Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. If a user accesses a crafted page or URL, an arbitrary script may be executed on the web browser of the user.
|
|||||
| CVE-2025-12063 | 1 Axis | 1 Camera Station Pro | 2026-02-17 | N/A | 5.7 MEDIUM |
|
An insecure direct object reference allowed a non-admin user to modify or remove certain data objects without having the appropriate permissions.
|
|||||
| CVE-2026-2259 | 1 Strlen | 1 Lobster | 2026-02-17 | 1.7 LOW | 3.3 LOW |
|
A vulnerability has been found in aardappel lobster up to 2025.4. Affected by this issue is the function lobster::Parser::ParseStatements in the library dev/src/lobster/parser.h of the component Parsing. The manipulation leads to memory corruption. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The identifier of the patch is 2f45fe860d00990e79e13250251c1dde633f1f89. Applying a patch is the recommended action to fix this is ...
Show More |
|||||
| CVE-2025-66284 | 1 Groupsession | 1 Groupsession | 2026-02-17 | N/A | 5.4 MEDIUM |
|
Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and GroupSession ZION prior to ver5.7.1. A logged-in user can prepare a malicious page or URL, and an arbitrary script may be executed on the web browser when another user accesses it.
|
|||||
| CVE-2026-25956 | 1 Frappe | 1 Frappe | 2026-02-17 | N/A | 6.1 MEDIUM |
|
Frappe is a full-stack web application framework. Prior to 14.99.14 and 15.94.0, an attacker could craft a malicious signup URL for a frappe site which could lead to an open redirect (or reflected XSS, depending on the crafted payload) when a user signs up. This vulnerability is fixed in 14.99.14 and 15.94.0.
|
|||||
| CVE-2025-70083 | 1 Opensatkit | 1 Opensatkit | 2026-02-17 | N/A | 7.8 HIGH |
|
An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and must be treated as untrusted input. The program copies DirName into the local buffer DirWithSep using strcpy. The size of this buffer is OS_MAX_PATH_LEN. If the length of DirName is greater than or equal to OS_MAX_PATH_LEN, a stack buffer overflow occurs, overwriting adjacent stack memory. The path length check (FileUtil_AppendPathSep) is performed after the strcpy operation, m ...
Show More |
|||||
| CVE-2025-70084 | 1 Opensatkit | 1 Opensatkit | 2026-02-17 | N/A | 7.5 HIGH |
|
Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete arbitrary files via crafted value to the FileUtil_GetFileInfo function.
|
|||||
| CVE-2025-70085 | 1 Opensatkit | 1 Opensatkit | 2026-02-17 | N/A | 9.8 CRITICAL |
|
An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Source1Filename and the string returned by FileUtil_FileStateStr) into this buffer without any length checking and without using bounded format specifiers such as %.*s. If the filename length approaches OS_MAX_PATH_LEN (commonly 64-256 bytes), the combined formatted string together with constant text can exceed 256 bytes, resulting in a stack buffer ov ...
Show More |
|||||
| CVE-2024-50618 | 1 Cipplanner | 1 Cipace | 2026-02-17 | N/A | 4.3 MEDIUM |
|
A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the system is configured to allow login with internal accounts, an attacker can possibly obtain full authentication if the secret in a single-factor authentication scheme gets compromised.
|
|||||
| CVE-2025-70091 | 1 Opensourcepos | 1 Open Source Point Of Sale | 2026-02-17 | N/A | 6.5 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter.
|
|||||
| CVE-2025-70093 | 1 Opensourcepos | 1 Open Source Point Of Sale | 2026-02-17 | N/A | 7.4 HIGH |
|
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
|
|||||
| CVE-2025-70094 | 1 Opensourcepos | 1 Open Source Point Of Sale | 2026-02-17 | N/A | 6.5 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category parameter.
|
|||||
| CVE-2025-70095 | 1 Opensourcepos | 1 Open Source Point Of Sale | 2026-02-17 | N/A | 6.5 MEDIUM |
|
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
|
|||||
| CVE-2025-67737 | 1 Azuracast | 1 Azuracast | 2026-02-17 | N/A | 3.1 LOW |
|
AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint that is intended for internal use by the SFTP software sftpgo, exposing it to the public-facing HTTP API for AzuraCast installations. A user with specific internal knowledge of a station's operations can craft a custom HTTP request that would affect the contents of a station's database, without revealing any internal information about the station. In order to carry out an attack, ...
Show More |
|||||
| CVE-2026-24854 | 1 Churchcrm | 1 Churchcrm | 2026-02-17 | N/A | 8.8 HIGH |
|
ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor.php` in ChurchCRM prior to version 6.7.2. Any authenticated user, including one with zero assigned permissions, can exploit SQL injection through the `PerID` parameter. Version 6.7.2 contains a patch for the issue.
|
|||||
| CVE-2026-24855 | 1 Churchcrm | 1 Churchcrm | 2026-02-17 | N/A | 5.4 MEDIUM |
|
ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) vulnerability occurs in Create Events in Church Calendar. Users with low privileges can create XSS payloads in the Description field. This payload is stored in the database, and when other users view that event (including the admin), the payload is triggered, leading to account takeover. Version 6.7.2 fixes the vulnerability.
|
|||||
| CVE-2026-1731 | 1 Beyondtrust | 2 Privileged Remote Access, Remote Support | 2026-02-17 | N/A | 9.8 CRITICAL |
|
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
|
|||||
| CVE-2026-20620 | 1 Apple | 1 Macos | 2026-02-17 | N/A | 7.7 HIGH |
|
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3, macOS Sonoma 14.8.4. An attacker may be able to cause unexpected system termination or read kernel memory.
|
|||||
| CVE-2026-20636 | 1 Apple | 5 Ipados, Iphone Os, Macos and 2 more | 2026-02-17 | N/A | 6.5 MEDIUM |
|
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, Safari 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
|
|||||
| CVE-2026-20640 | 1 Apple | 2 Ipados, Iphone Os | 2026-02-17 | N/A | 4.6 MEDIUM |
|
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to iPhone may be able to take and view screenshots of sensitive data from the iPhone during iPhone Mirroring with Mac.
|
|||||
| CVE-2026-20641 | 1 Apple | 6 Ipados, Iphone Os, Macos and 3 more | 2026-02-17 | N/A | 7.1 HIGH |
|
A privacy issue was addressed with improved checks. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An app may be able to identify what other apps a user has installed.
|
|||||
| CVE-2024-33648 | 2026-02-17 | N/A | 6.5 MEDIUM | ||
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemory Grubb Recencio Book Reviews allows DOM-Based XSS.This issue affects Recencio Book Reviews: from n/a through 1.66.0.
|
|||||
| CVE-2020-37007 | 1 Salihciftci | 1 Liman | 2026-02-17 | N/A | 5.3 MEDIUM |
|
Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests.
|
|||||
| CVE-2026-20616 | 1 Apple | 4 Ipados, Iphone Os, Macos and 1 more | 2026-02-17 | N/A | 6.5 MEDIUM |
|
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3, macOS Sonoma 14.8.4, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexpected app termination.
|
|||||
| CVE-2026-24532 | 2026-02-17 | N/A | 4.3 MEDIUM | ||
|
Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteLock Security – WP Hardening, Login Security & Malware Scans: from n/a through 5.0.2.
|
|||||
| CVE-2025-63065 | 2026-02-17 | N/A | 5.3 MEDIUM | ||
|
Authorization Bypass Through User-Controlled Key vulnerability in David Lingren Media LIbrary Assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media LIbrary Assistant: from n/a through 3.29.
|
|||||
| CVE-2025-69055 | 2026-02-17 | N/A | 6.5 MEDIUM | ||
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Builder allows Path Traversal.This issue affects BM Content Builder: from n/a before 3.16.3.3.
|
|||||
| CVE-2024-11831 | 2026-02-17 | N/A | 5.4 MEDIUM | ||
|
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or we ...
Show More |
|||||
| CVE-2025-26637 | 1 Microsoft | 12 Windows 10 1507, Windows 10 1607, Windows 10 22h2 and 9 more | 2026-02-16 | N/A | 6.8 MEDIUM |
|
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
|
|||||
| CVE-2026-1783 | 2026-02-16 | N/A | N/A | ||
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
|
|||||
| CVE-2023-1211 | 1 Phpipam | 1 Phpipam | 2026-02-16 | N/A | 7.2 HIGH |
|
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
|
|||||
| CVE-2022-4407 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-02-16 | N/A | 6.1 MEDIUM |
|
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
|
|||||
| CVE-2022-3766 | 1 Phpmyfaq | 1 Phpmyfaq | 2026-02-16 | N/A | 6.1 MEDIUM |
|
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
|
|||||
| CVE-2022-0088 | 1 Yourls | 1 Yourls | 2026-02-16 | 4.3 MEDIUM | 7.4 HIGH |
|
Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.
|
|||||
| CVE-2025-9566 | 2026-02-16 | N/A | 8.1 HIGH | ||
|
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file.
Binary-Affected: podman
Upstream-version-introduced: v4.0.0
Upstream-version-fixed: v5.6.1
|
|||||
| CVE-2025-38162 | 1 Linux | 1 Linux Kernel | 2026-02-16 | N/A | 5.5 MEDIUM |
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_pipapo: prevent overflow in lookup table allocation
When calculating the lookup table size, ensure the following
multiplication does not overflow:
- desc->field_len[] maximum value is U8_MAX multiplied by
NFT_PIPAPO_GROUPS_PER_BYTE(f) that can be 2, worst case.
- NFT_PIPAPO_BUCKETS(f->bb) is 2^8, worst case.
- sizeof(unsigned long), from sizeof(*f->lt), lt in
struct nft_pipapo_field.
Then, use check_mu ...
Show More |
|||||