Total
336347 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-23967 | 1 Juneandgreen | 1 Sm-crypto | 2026-02-25 | N/A | 7.5 HIGH |
|
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library prior to version 0.3.14. An attacker can derive a new valid signature for a previously signed message from an existing signature. Version 0.3.14 patches the issue.
|
|||||
| CVE-2026-23966 | 1 Juneandgreen | 1 Sm-crypto | 2026-02-25 | N/A | 9.1 CRITICAL |
|
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto prior to version 0.3.14. By interacting with the SM2 decryption interface multiple times, an attacker can fully recover the private key within approximately several hundred interactions. Version 0.3.14 patches the issue.
|
|||||
| CVE-2018-5410 | 1 Dokan-dev | 1 Dokany | 2026-02-25 | 7.2 HIGH | 7.8 HIGH |
|
Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys driver. An attacker can create a device handle to the system driver and send arbitrary input that will trigger the vulnerability. This vulnerability was introduced in the 1.0.0.5000 version update.
|
|||||
| CVE-2026-2537 | 1 Comfast | 2 Cf-e4, Cf-e4 Firmware | 2026-02-25 | 5.8 MEDIUM | 4.7 MEDIUM |
|
A vulnerability was identified in Comfast CF-E4 2.6.0.1. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the component HTTP POST Request Handler. Such manipulation of the argument timestr leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2026-23965 | 1 Juneandgreen | 1 Sm-crypto | 2026-02-25 | N/A | 7.5 HIGH |
|
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature forgery vulnerability exists in the SM2 signature verification logic of sm-crypto prior to version 0.4.0. Under default configurations, an attacker can forge valid signatures for arbitrary public keys. If the message space contains sufficient redundancy, the attacker can fix the prefix of the message associated with the forged signature to satisfy specific formatting requirements. ...
Show More |
|||||
| CVE-2026-25061 | 2 Debian, Digitalcorpora | 2 Debian Linux, Tcpflow | 2026-02-25 | N/A | 7.5 HIGH |
|
tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame elements and performs a length check on the wrong field when handling the TIM element. A crafted frame with a large TIM length can cause a 1-byte out-of-bounds write past `tim.bitmap[251]`. The overflow is small and DoS is the likely impact; code execution is potential, but still up in the air. The affected structure is stack-allocated in `handle_beacon()` and related handlers. ...
Show More |
|||||
| CVE-2025-65715 | 1 Formulahendry | 1 Coderunner | 2026-02-25 | N/A | 7.8 HIGH |
|
An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace.
|
|||||
| CVE-2026-21483 | 1 Nadh | 1 Listmonk | 2026-02-25 | N/A | 5.4 MEDIUM |
|
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to version 6.0.0, lower-privileged user with campaign management permissions can inject malicious JavaScript into campaigns or templates. When a higher-privileged user (Super Admin) views or previews this content, the XSS executes in their browser context, allowing the attacker to perform privileged actions such as creating backdoor admin accounts. The attack can be weaponized via the public archive feature, where ...
Show More |
|||||
| CVE-2026-3197 | 2026-02-25 | N/A | N/A | ||
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
|
|||||
| CVE-2026-27368 | 2026-02-25 | N/A | 5.3 MEDIUM | ||
|
Missing Authorization vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.19.7.
|
|||||
| CVE-2026-22383 | 2026-02-25 | N/A | 5.4 MEDIUM | ||
|
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3.
|
|||||
| CVE-2026-27204 | 1 Bytecodealliance | 1 Wasmtime | 2026-02-25 | N/A | 6.5 MEDIUM |
|
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interfaces are susceptible to guest-controlled resource exhaustion on the host. Wasmtime did not appropriately place limits on resource allocations requested by the guests. This serves as a Denial of Service vector. Wasmtime 24.0.6, 36.0.6, 40.0.4, 41.0.4, and 42.0.0 have all been released with the fix for this issue. These versions do not prevent this issue ...
Show More |
|||||
| CVE-2026-22350 | 2026-02-25 | N/A | 6.5 MEDIUM | ||
|
Missing Authorization vulnerability in add-ons.org PDF for Elementor Forms + Drag And Drop Template Builder pdf-for-elementor-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through <= 6.3.1.
|
|||||
| CVE-2025-69403 | 2026-02-25 | N/A | 9.9 CRITICAL | ||
|
Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using Malicious Files.This issue affects Bravis Addons: from n/a through <= 1.1.9.
|
|||||
| CVE-2025-61145 | 1 Libtiff | 1 Libtiff | 2026-02-25 | N/A | 5.0 MEDIUM |
|
libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.
|
|||||
| CVE-2025-61144 | 1 Libtiff | 1 Libtiff | 2026-02-25 | N/A | 7.3 HIGH |
|
libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.
|
|||||
| CVE-2025-61143 | 1 Libtiff | 1 Libtiff | 2026-02-25 | N/A | 5.5 MEDIUM |
|
libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.
|
|||||
| CVE-2022-31595 | 1 Sap | 1 Adaptive Server Enterprise | 2026-02-25 | 6.5 MEDIUM | 8.8 HIGH |
|
SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
|
|||||
| CVE-2026-27195 | 1 Bytecodealliance | 1 Wasmtime | 2026-02-25 | N/A | 7.5 HIGH |
|
Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the default, which brought with it a new implementation of `[Typed]Func::call_async` which made it capable of calling async-typed guest export functions. However, that implementation had a bug leading to a panic under certain circumstances: First, the host embedding calls `[Typed]Func::call_async` on a function exported by a component, polling the returned `Future` once. Second, the ...
Show More |
|||||
| CVE-2026-27729 | 1 Astro | 1 \@astrojs\/node | 2026-02-25 | N/A | 5.9 MEDIUM |
|
Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default request body size limit, which can lead to memory exhaustion DoS. A single large POST to a valid action endpoint can crash the server process on memory-constrained deployments. On-demand rendered sites built with Astro can define server actions, which automatically parse incoming request bodies (JSON or FormData). The body is buffered entirely into memory with no size limit — a single oversized reques ...
Show More |
|||||
| CVE-2026-25545 | 1 Astro | 1 \@astrojs\/node | 2026-02-25 | N/A | 8.6 HIGH |
|
Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered custom error page (eg. `404.astro` or `500.astro`) are vulnerable to SSRF. If the `Host:` header is changed to an attacker's server, it will be fetched on `/500.html` and they can redirect this to any internal URL to read the response body through the first request. An attacker who can access the application without `Host:` header validation (eg. through finding the origin IP behi ...
Show More |
|||||
| CVE-2022-2845 | 2 Fedoraproject, Vim | 2 Fedora, Vim | 2026-02-25 | N/A | 7.8 HIGH |
|
Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.
|
|||||
| CVE-2022-2824 | 1 Open-emr | 1 Openemr | 2026-02-25 | N/A | 8.8 HIGH |
|
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
|
|||||
| CVE-2022-2820 | 1 Namelessmc | 1 Nameless | 2026-02-25 | N/A | 7.0 HIGH |
|
Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.
|
|||||
| CVE-2022-2818 | 1 Agentejo | 1 Cockpit | 2026-02-25 | N/A | 9.8 CRITICAL |
|
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
|
|||||
| CVE-2022-2732 | 1 Open-emr | 1 Openemr | 2026-02-25 | N/A | 8.3 HIGH |
|
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.
|
|||||
| CVE-2022-2637 | 1 Hitachi | 1 Storage Plug-in | 2026-02-25 | N/A | 5.4 MEDIUM |
|
Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation.This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.0.
|
|||||
| CVE-2022-2636 | 1 Hestiacp | 1 Control Panel | 2026-02-25 | N/A | 8.5 HIGH |
|
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
|
|||||
| CVE-2022-2598 | 2 Debian, Vim | 2 Debian Linux, Vim | 2026-02-25 | N/A | 6.5 MEDIUM |
|
Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.
|
|||||
| CVE-2022-2596 | 1 Node-fetch Project | 1 Node-fetch | 2026-02-25 | N/A | 5.9 MEDIUM |
|
Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.
|
|||||
| CVE-2022-2368 | 1 Microweber | 1 Microweber | 2026-02-25 | 7.5 HIGH | 6.5 MEDIUM |
|
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.
|
|||||
| CVE-2026-21444 | 1 Libtpms Project | 1 Libtpms | 2026-02-25 | N/A | 5.5 MEDIUM |
|
libtpms, a library that provides software emulation of a Trusted Platform Module, has a flaw in versions 0.10.0 and 0.10.1. The commonly used integration of libtpms with OpenSSL 3.x contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decryption steps. The highest threat from this vulnerability is to data confide ...
Show More |
|||||
| CVE-2022-2054 | 1 Nuitka | 1 Nuitka | 2026-02-25 | 7.2 HIGH | 8.4 HIGH |
|
Code Injection in GitHub repository nuitka/nuitka prior to 0.9.
|
|||||
| CVE-2022-28773 | 1 Sap | 2 Netweaver, Web Dispatcher | 2026-02-25 | 5.0 MEDIUM | 7.5 HIGH |
|
Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash, leading to denial of service, but can be restarted automatically.
|
|||||
| CVE-2022-28771 | 1 Sap | 1 Business One License Service Api | 2026-02-25 | 5.0 MEDIUM | 7.5 HIGH |
|
Due to missing authentication check, SAP Business one License service API - version 10.0 allows an unauthenticated attacker to send malicious http requests over the network. On successful exploitation, an attacker can break the whole application making it inaccessible.
|
|||||
| CVE-2026-3151 | 1 Angeljudesuarez | 1 College Management System | 2026-02-25 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
|
|||||
| CVE-2025-21120 | 1 Dell | 1 Avamar | 2026-02-25 | N/A | 8.3 HIGH |
|
Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
|
|||||
| CVE-2026-3152 | 1 Angeljudesuarez | 1 College Management System | 2026-02-25 | 7.5 HIGH | 7.3 HIGH |
|
A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/teacher-salary.php. This manipulation of the argument teacher_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
|
|||||
| CVE-2026-3153 | 1 Admerc | 1 Document Management System | 2026-02-25 | 7.5 HIGH | 7.3 HIGH |
|
A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||
| CVE-2026-3163 | 1 Remyandrade | 1 Website Link Extractor | 2026-02-25 | 6.5 MEDIUM | 6.3 MEDIUM |
|
A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function file_get_contents of the component URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
|
|||||