| CVE-2026-86244 | 2.1 | 19.4 | n/a | FastAdmin | CWE-79 | FastAdmin User Controller User.php login cross site scripting |
| CVE-2026-86278 | 2.1 | 19.4 | SourceCodester | Syllabus-Aligned Learning Management & Examination System | CWE-79 | SourceCodester Syllabus-Aligned Learning Management & Examination System mana… |
| CVE-2026-86282 | 5.5 | 19.3 | jaychouchannel | Tourism-Management-System | CWE-74 | jaychouchannel Tourism-Management-System CommonDao CommonController.java sql … |
| CVE-2026-86268 | 5.5 | 18.8 | itsourcecode | School Management System | CWE-74 | itsourcecode School Management System User_Login.php sql injection |
| CVE-2026-86290 | 5.5 | 18.8 | SourceCodester | Online Voting System | CWE-74 | SourceCodester Online Voting System ajax.php save_category sql injection |
| CVE-2026-86342 | 5.3 | 18.8 | MISP | MISP | CWE-862 | MISP Freetext Feed Preview Improper Authorization Exposes Restricted Event an… |
| CVE-2026-86264 | 2.1 | 18.0 | sfturing | ssm_pro | CWE-79 | sfturing ssm_pro Order Endpoint OrderController.java cross site scripting |
| CVE-2026-86271 | 2.0 | 13.9 | n/a | FluentCMS | CWE-862 | FluentCMS PermissionManager.cs GetAccessible authorization |
| CVE-2026-86279 | 2.1 | 13.3 | SourceCodester | Syllabus-Aligned Learning Management & Examination System | CWE-384 | SourceCodester Syllabus-Aligned Learning Management & Examination System Logi… |
| CVE-2026-86285 | 2.1 | 12.7 | n/a | BookStack | CWE-266 | BookStack Attachment Edit Endpoint AttachmentController.php getUpdateForm acc… |
| CVE-2026-86280 | 5.5 | 11.9 | SourceCodester | Syllabus-Aligned Learning Management & Examination System | CWE-310 | SourceCodester Syllabus-Aligned Learning Management & Examination System cict… |
| CVE-2026-86332 | 6.5 | 11.5 | Red Hat | Red Hat OpenShift AI (RHOAI) | CWE-862 | Odh-dashboard: odh-dashboard: nim credential secret readable by any authentic… |
| CVE-2026-86269 | 2.1 | 10.4 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System emp_edit1.php sql injection |
| CVE-2026-20503 | 5.3 | 10.2 | MediaTek, Inc. | MediaTek chipset | CWE-617 | In Modem, there is a possible system crash due to a missing bounds check. Thi… |
| CVE-2026-20504 | 5.3 | 10.2 | MediaTek, Inc. | MediaTek chipset | CWE-617 | In Modem, there is a possible system crash due to a missing bounds check. Thi… |
| CVE-2026-20513 | 4.4 | 9.8 | MediaTek, Inc. | MediaTek chipset | CWE-35 | In Audio HAL, there is a possible information disclosure due to improper inpu… |
| CVE-2026-86236 | 2.1 | 9.9 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System pro_transac.php add sql injection |
| CVE-2026-86245 | 2.1 | 9.9 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System sup_transac.php sql injection |
| CVE-2026-86265 | 2.1 | 9.9 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System us_transac.php sql injection |
| CVE-2026-86267 | 2.1 | 9.9 | itsourcecode | Information System Society Membership System | CWE-74 | itsourcecode Information System Society Membership System check_student.php s… |
| CVE-2026-86270 | 2.1 | 9.9 | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System settings_edit.php sql injection |
| CVE-2026-78254 | await | 8.7 | Apache Software Foundation | Apache Ant | CWE-23 | Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write |
| CVE-2026-78043 | 5.6 | 6.7 | OpenVPN | OpenVPN | CWE-22 | The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows lo… |
| CVE-2026-86281 | 2.1 | 5.3 | SourceCodester | Syllabus-Aligned Learning Management & Examination System | CWE-352 | SourceCodester Syllabus-Aligned Learning Management & Examination System cros… |
| CVE-2026-14297 | 8.7 | 5.0 | Nordic Semiconductor ASA | nRF Connect SDK | CWE-787 | The Continuous Glucose Monitoring Service's Record Access Control Point (RACP… |
| CVE-2026-20501 | 8.4 | 4.5 | MediaTek, Inc. | MediaTek chipset | CWE-122 | In vdec, there is a possible out of bounds write due to a heap buffer overflo… |
| CVE-2026-20502 | 8.4 | 4.3 | MediaTek, Inc. | MediaTek chipset | CWE-122 | In vdec, there is a possible out of bounds write due to a missing bounds chec… |
| CVE-2026-20515 | 5.5 | 4.3 | MediaTek, Inc. | MediaTek chipset | CWE-416 | In gpu, there is a possible system crash due to use after free. This could le… |
| CVE-2026-84226 | 8.5 | 3.8 | OpenVPN | OpenVPN | CWE-426 | OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows … |
| CVE-2026-20500 | 5.5 | 3.7 | MediaTek, Inc. | MediaTek chipset | CWE-295 | In Modem, there is a possible system crash due to improper input validation. … |
| CVE-2026-20516 | 5.5 | 3.7 | MediaTek, Inc. | MediaTek chipset | CWE-926 | In MiracastService, there is a possible escalation of privilege due to a conf… |
| CVE-2026-20509 | 6.7 | 3.6 | MediaTek, Inc. | MediaTek chipset | CWE-121 | In Power HAL, there is a possible out of bounds write due to a missing bounds… |
| CVE-2026-20510 | 6.7 | 3.6 | MediaTek, Inc. | MediaTek chipset | CWE-415 | In camera middleware, there is a possible escalation of privilege due to doub… |
| CVE-2026-20518 | 4.4 | 3.6 | MediaTek, Inc. | MediaTek chipset | CWE-125 | In geniezone, there is a possible information disclosure due to a missing bou… |
| CVE-2026-20506 | 6.7 | 3.1 | MediaTek, Inc. | MediaTek chipset | CWE-416 | In Audio HAL, there is a possible escalation of privilege due to use after fr… |
| CVE-2026-20507 | 6.7 | 3.1 | MediaTek, Inc. | MediaTek chipset | CWE-416 | In Audio HAL, there is a possible escalation of privilege due to use after fr… |
| CVE-2026-20508 | 6.7 | 3.1 | MediaTek, Inc. | MediaTek chipset | CWE-843 | In Power HAL, there is a possible escalation of privilege due to type confusi… |
| CVE-2026-20511 | 6.7 | 3.2 | MediaTek, Inc. | MediaTek chipset | CWE-416 | In SurfaceFlinger, there is a possible memory corruption due to use after fre… |
| CVE-2026-20517 | 6.7 | 3.1 | MediaTek, Inc. | MediaTek chipset | CWE-416 | In geniezone, there is a possible escalation of privilege due to use after fr… |
| CVE-2026-20514 | 4.4 | 2.6 | MediaTek, Inc. | MediaTek chipset | CWE-307 | In Audio HAL, there is a possible information disclosure due to a missing per… |
| CVE-2026-20512 | await | 2.6 | MediaTek, Inc. | MediaTek chipset | CWE-307 | In Audio HAL, there is a possible escalation of privilege due to improper inp… |
| CVE-2026-86314 | 6.2 | 2.5 | Samsung Opensource | Walrus | CWE-190 | Integer overflow in the source-bounds check in Memory::init() (src/runtime/Me… |
| CVE-2026-86315 | 6.2 | 2.4 | Samsung Opensource | Escargot | CWE-197 | An out-of-bounds write caused by numeric truncation Samsung Open Source Escar… |
| CVE-2026-86313 | 7.8 | 1.8 | Samsung Opensource | Walrus | CWE-787 | Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflo… |
| CVE-2026-78221 | 5.9 | 1.8 | OpenVPN | OpenVPN | CWE-131 | An incorrect buffer size calculation in the Windows Interactive Service in Op… |
| CVE-2026-14296 | 7.5 | 1.4 | Nordic Semiconductor ASA | nRF54H20 | CWE-347 | nRF54H20: MCUBoot can be tricked to executing unauthenticated code |
| CVE-2026-81830 | 5.6 | 1.2 | OpenVPN | OpenVPN | CWE-73 | The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local … |
| CVE-2026-82312 | 1.8 | 1.0 | OpenVPN | OpenVPN | CWE-412 | OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows l… |
| CVE-2026-18796 | 6.8 | 0.1 | Nordic Semiconductor ASA | nRF5340 | CWE-1342 | QSPI flash encryption side-channel leakage |
| CVE-2026-75650 | 10.0 | — | Adobe | Adobe Commerce | CWE-1336 | Adobe Commerce | Improper Neutralization of Special Elements Used in a Templa… |
| CVE-2026-7861 | 9.8 | — | Next4Biz Information Technologies Inc. | CSM (Customer Service Management) | CWE-502 | Code Injection in Next4Biz's CSM (Customer Service Management) |
| CVE-2026-18922 | 9.8 | — | Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | CWE-287 | 389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalati… |
| CVE-2026-76578 | 9.8 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-306 | Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator c… |
| CVE-2026-86478 | 9.8 | — | JetBrains | YouTrack | CWE-290 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authenticat… |
| CVE-2026-86480 | 9.8 | — | JetBrains | Hub | CWE-306 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could regist… |
| CVE-2026-6223 | 9.4 | — | Bahçelievler Muncipality | BiHayat App | CWE-307 | OTP Bypass in Bahçelievler Muncipality's BiHayat App |
| CVE-2026-61410 | 9.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-862 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80238 | 9.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-250 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86296 | 9.3 | — | D-Link | DIR-822A | CWE-119 | D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow |
| CVE-2026-86543 | 9.3 | — | knowns-dev | knowns | CWE-306 | knowns before 0.30.0 Unauthenticated Management API Exposure |
| CVE-2026-86426 | 9.2 | — | librenms | librenms | CWE-287 | LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion |
| CVE-2026-86404 | 8.8 | — | Red Hat | Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 | CWE-502 | Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildf… |
| CVE-2026-86482 | 8.8 | — | JetBrains | YouTrack | CWE-266 | In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes … |
| CVE-2026-86542 | 8.8 | — | knowns-dev | knowns | CWE-22 | knowns before 0.30.0 Path Traversal via Import Name |
| CVE-2022-51017 | 8.7 | — | pmmp | PocketMine-MP | CWE-20 | PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data |
| CVE-2026-19204 | 8.7 | — | Eclipse Foundation | Eclipse Jetty | CWE-770 | A client may send a WebSocket frame with an unknown opcode and a very large d… |
| CVE-2026-86427 | 8.7 | — | librenms | librenms | CWE-77 | LibreNMS before 26.8.0 Argument Injection via graph_title |
| CVE-2026-86428 | 8.7 | — | thephpleague | commonmark | CWE-407 | commonmark 1.5.0 before 2.10.0 Denial of Service via Attributes |
| CVE-2026-86429 | 8.7 | — | thephpleague | commonmark | CWE-407 | commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes |
| CVE-2026-86430 | 8.7 | — | thephpleague | commonmark | CWE-407 | league/commonmark before 2.9.1 Denial of Service via parsing |
| CVE-2026-86433 | 8.7 | — | thephpleague | commonmark | CWE-407 | commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes |
| CVE-2026-86434 | 8.7 | — | thephpleague | commonmark | CWE-407 | commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision |
| CVE-2026-86435 | 8.7 | — | thephpleague | commonmark | CWE-407 | commonmark 1.5.0 before 2.8.4 Denial of Service via Footnote |
| CVE-2026-86439 | 8.7 | — | knowns-dev | knowns | CWE-22 | knowns before 0.30.0 Path Traversal via MCP doc and memory tools |
| CVE-2026-86452 | 8.7 | — | MISP | MISP | CWE-400 | MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and R… |
| CVE-2026-86538 | 8.7 | — | knowns-dev | knowns | CWE-22 | knowns before 0.30.0 Path Traversal via templateFile parameter |
| CVE-2026-86299 | 8.6 | — | Linksys | RE7000 | CWE-77 | Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection |
| CVE-2026-86437 | 8.6 | — | laradashboard | laradashboard | CWE-863 | Lara Dashboard before 1.3.2 Incorrect Authorization in Core-Upgrade Archive U… |
| CVE-2026-86438 | 8.6 | — | laradashboard | laradashboard | CWE-862 | Lara Dashboard before 1.3.2 Missing Authorization in Marketplace Module Insta… |
| CVE-2026-86492 | 8.5 | — | JetBrains | YouTrack | CWE-488 | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-… |
| CVE-2026-86540 | 8.5 | — | knowns-dev | knowns | CWE-78 | knowns before 0.30.0 Arbitrary Code Execution via LSP Binary |
| CVE-2026-19843 | 8.4 | — | Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | CWE-78 | 389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit … |
| CVE-2026-86502 | 8.4 | — | JetBrains | IntelliJ IDEA | CWE-306 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on … |
| CVE-2026-84173 | 8.3 | — | Eclipse Foundation | Eclipse Ankaios | CWE-863 | In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Int… |
| CVE-2026-79645 | 8.2 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-306 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-82586 | 8.2 | — | ash-project | ash_lua | CWE-424 | AshLua read operation aggregate bypasses the exposed-field allow-list, exposi… |
| CVE-2026-82753 | 8.2 | — | ash-project | ash_authentication_oauth2_server | CWE-770 | Unauthenticated authorize requests create unbounded, never-expiring CIMD clie… |
| CVE-2026-86297 | 8.2 | — | D-Link | DIR-605 | CWE-189 | D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one |
| CVE-2026-79678 | 8.1 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-95 | Freeipa: idm: freeipa: idp-add eval() reachable before authorization check al… |
| CVE-2026-80132 | 8.1 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-306 | ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicati… |
| CVE-2026-86479 | 8.1 | — | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missin… |
| CVE-2026-80166 | 7.8 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-269 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86504 | 7.8 | — | JetBrains | IntelliJ IDEA | CWE-829 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation… |
| CVE-2026-80134 | 7.7 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-798 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86494 | 7.7 | — | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauth… |
| CVE-2026-86498 | 7.7 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link… |
| CVE-2026-79639 | 7.6 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-6377 | 7.5 | — | Next4Biz Information Technologies Inc. | CSM (Customer Service Management) | CWE-22 | Path Traversal in Next4Biz's CSM (Customer Service Management) |
| CVE-2026-14444 | 7.5 | — | Very Good Plugins | WP Fusion (Pro) | CWE-269 | WP Fusion (Pro) <= 3.47.13 - Authenticated (Subscriber+) Privilege Escalation… |
| CVE-2026-18355 | 7.5 | — | Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | CWE-191 | 389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length… |
| CVE-2026-18453 | 7.5 | — | Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | CWE-476 | 389-ds-base: 389-ds-base: pre-authentication null pointer dereference via pag… |
| CVE-2026-76560 | 7.5 | — | Red Hat | Red Hat Directory Server 11.7 E4S for RHEL 8 | CWE-863 | 389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule ch… |
| CVE-2026-78480 | 7.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-306 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80135 | 7.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-703 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79644 | 7.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80131 | 7.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-22 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80133 | 7.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-23 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80164 | 7.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-61409 | 7.3 | — | Dell | Secure Connect Gateway (SCG) 5.0 Application | CWE-78 | Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.… |
| CVE-2026-79643 | 7.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-480 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79691 | 7.3 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-6431 | 7.2 | — | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | CWE-79 | User Profile Builder <= 3.15.7 - Unauthenticated Stored Cross-Site Scripting … |
| CVE-2026-80127 | 7.2 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-78 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86541 | 7.2 | — | knowns-dev | knowns | CWE-22 | knowns before 0.30.0 Path Traversal via code.replace MCP action |
| CVE-2026-86544 | 7.2 | — | knowns-dev | knowns | CWE-863 | knowns before 0.30.0 Authorization Bypass via Misclassified Code Actions |
| CVE-2022-51010 | 7.1 | — | pmmp | PocketMine-MP | CWE-20 | PocketMine-MP before 4.4.2 Server Crash via Item ID |
| CVE-2022-51012 | 7.1 | — | pmmp | PocketMine-MP | CWE-20 | PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization |
| CVE-2022-51013 | 7.1 | — | pmmp | PocketMine-MP | CWE-20 | PocketMine-MP before 4.2.3 Denial of Service via NBT Metadata |
| CVE-2022-51014 | 7.1 | — | pmmp | PocketMine-MP | CWE-248 | PocketMine-MP before 4.0.7 Denial of Service via JSON Decoding |
| CVE-2022-51015 | 7.1 | — | pmmp | PocketMine-MP | CWE-20 | PocketMine-MP before 4.0.6 Denial of Service via PlayerActionPacket |
| CVE-2022-51018 | 7.1 | — | pmmp | PocketMine-MP | CWE-400 | PocketMine-MP before 3.26.5 Input Validation via Book Pages |
| CVE-2026-80130 | 7.1 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-23 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86347 | 7.1 | — | MISP | MISP | CWE-400 | MISP Missing Authorization on Template File Upload Allows Authenticated Disk … |
| CVE-2026-86408 | 7.1 | — | MISP | MISP | CWE-639 | MISP Missing Authorization in Cryptographic Key View Exposes Signing Keys fro… |
| CVE-2026-86419 | 7.0 | — | MISP | MISP | CWE-200 | MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosu… |
| CVE-2026-78325 | 6.9 | — | Standard Notes | Standard Notes | CWE-79 | XSS in Standard Notes on Android via Malicious Google Keep and Evernote HTML … |
| CVE-2026-86303 | 6.9 | — | 92181 | markdown | CWE-119 | 92181 markdown md.c lds out-of-bounds |
| CVE-2026-86317 | 6.9 | — | ggml-org | llama.cpp | CWE-617 | ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion |
| CVE-2026-86431 | 6.9 | — | thephpleague | commonmark | CWE-79 | commonmark before 2.9.1 XSS via AttributesExtension form feed bypass |
| CVE-2026-86432 | 6.9 | — | thephpleague | commonmark | CWE-405 | commonmark 2.0.0 before 2.8.4 Denial of Service via XML |
| CVE-2026-86539 | 6.9 | — | knowns-dev | knowns | CWE-918 | knowns through 0.33.0 Server-Side Request Forgery via embedding-models endpoint |
| CVE-2026-82325 | 6.8 | — | OpenVPN | ovpn-dco-win | CWE-415 | A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5… |
| CVE-2026-85201 | 6.8 | — | Eclipse Foundation | Eclipse Ankaios | CWE-789 | In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the… |
| CVE-2026-86497 | 6.8 | — | JetBrains | YouTrack | CWE-201 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-… |
| CVE-2026-12757 | 6.5 | — | icegram | Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress | CWE-94 | Email Subscribers & Newsletters <= 5.9.27 - Unauthenticated Arbitrary Shortco… |
| CVE-2026-78488 | 6.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-78 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80126 | 6.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-667 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80129 | 6.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-22 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80170 | 6.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-798 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86488 | 6.5 | — | JetBrains | YouTrack | CWE-639 | In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueLi… |
| CVE-2026-86489 | 6.5 | — | JetBrains | YouTrack | CWE-639 | In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API dis… |
| CVE-2026-86490 | 6.5 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed … |
| CVE-2026-86493 | 6.5 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed … |
| CVE-2026-86495 | 6.5 | — | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed c… |
| CVE-2026-2390 | 6.4 | — | codesupplyco | Powerkit – Supercharge your WordPress Site | CWE-79 | Powerkit <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting … |
| CVE-2026-80128 | 6.4 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-287 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-77697 | 6.3 | — | Zohocorp | ManageEngine Endpoint Central | CWE-269 | Privilege Escalation |
| CVE-2026-82754 | 6.3 | — | ash-project | ash_authentication_oauth2_server | CWE-424 | ash_authentication_oauth2_server aliases every protocol endpoint under /.well… |
| CVE-2026-82755 | 6.3 | — | ash-project | ash_authentication_oauth2_server | CWE-524 | ash_authentication_oauth2_server serves tenant-specific OAuth metadata as pub… |
| CVE-2026-82756 | 6.3 | — | ash-project | ash_authentication_oauth2_server | CWE-116 | ash_authentication_oauth2_server interpolates a tenant-derived value into the… |
| CVE-2026-82757 | 6.3 | — | ash-project | ash_authentication_oauth2_server | CWE-918 | ash_authentication_oauth2_server CIMD fetcher classifies IPv4-in-IPv6 and sit… |
| CVE-2026-82758 | 6.3 | — | ash-project | ash_authentication_oauth2_server | CWE-287 | ash_authentication_oauth2_server treats an empty resolved secret as valid, op… |
| CVE-2026-85640 | 6.3 | — | Zohocorp | ManageEngine Endpoint Central | CWE-269 | Privilege Escalation |
| CVE-2026-86420 | 6.3 | — | ImageMagick | ImageMagick | CWE-400 | ImageMagick before 7.1.2-30 Denial of Service Memory Budget |
| CVE-2026-86421 | 6.3 | — | ImageMagick | ImageMagick | CWE-400 | ImageMagick before 7.1.2-30 Memory Leak via MSL decoder |
| CVE-2026-79734 | 5.9 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80125 | 5.9 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86506 | 5.9 | — | JetBrains | GoLand | CWE-306 | In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand pr… |
| CVE-2026-77698 | 5.7 | — | Zohocorp | ManageEngine Endpoint Central | CWE-269 | Privilege Escalation |
| CVE-2026-79642 | 5.6 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-78487 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-321 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-79975 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-295 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80054 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-732 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80056 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-532 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80057 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-321 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80058 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-312 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80167 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-321 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-80178 | 5.5 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-269 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86292 | 5.5 | — | SourceCodester | Simple Traffic Offense System | CWE-287 | SourceCodester Simple Traffic Offense System User Creation saveuser.php missi… |
| CVE-2026-86293 | 5.5 | — | SourceCodester | Simple Traffic Offense System | CWE-287 | SourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.ph… |
| CVE-2026-86295 | 5.5 | — | D-Link | DIR-895L | CWE-74 | D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection |
| CVE-2026-86298 | 5.5 | — | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System delete_subject.php sql injec… |
| CVE-2026-86300 | 5.5 | — | Tenda | AC9 | CWE-287 | Tenda AC9 Web Management R7WebsSecurityHandler improper authentication |
| CVE-2026-86302 | 5.5 | — | code-projects | Hospital Information System | CWE-200 | code-projects Hospital Information System SQL Database Backup File his.sql in… |
| CVE-2026-86305 | 5.5 | — | light0011 | cms | CWE-284 | light0011 cms Upload.class.php upload unrestricted upload |
| CVE-2026-86306 | 5.5 | — | light0011 | cms | CWE-287 | light0011 cms Cookie Helper UserModel.class.php improper authentication |
| CVE-2026-86308 | 5.5 | — | light0011 | cms | CWE-200 | light0011 cms Debug Mode config.php information disclosure |
| CVE-2026-86318 | 5.5 | — | java-json-tools | json-patch | CWE-119 | java-json-tools json-patch JsonMergePatchDeserializer.java JsonMergePatch.fro… |
| CVE-2026-86319 | 5.5 | — | java-json-tools | json-patch | CWE-400 | java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply res… |
| CVE-2026-86321 | 5.5 | — | java-json-tools | jackson-coreutils | CWE-918 | java-json-tools jackson-coreutils URL Validation JsonLoader.java JsonLoader.f… |
| CVE-2026-86500 | 5.5 | — | JetBrains | YouTrack | CWE-266 | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a us… |
| CVE-2026-12853 | 5.4 | — | rocklobsterinc | Flamingo | CWE-862 | Flamingo <= 2.6.2 - Authenticated (Contributor+) Missing Authorization to Una… |
| CVE-2026-86483 | 5.4 | — | JetBrains | YouTrack | CWE-79 | In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Ag… |
| CVE-2022-51011 | 5.3 | — | pmmp | PocketMine-MP | CWE-20 | PocketMine-MP before 4.2.10 Denial of Service via Chat Messages |
| CVE-2022-51016 | 5.3 | — | pmmp | PocketMine-MP | CWE-294 | PocketMine-MP before 4.0.0 Authentication Bypass via Login Replay |
| CVE-2026-4945 | 5.3 | — | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | CWE-639 | Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Ver… |
| CVE-2026-8279 | 5.3 | — | masteriyo | Masteriyo LMS – LMS Course Builder, Quizzes & Certificates | CWE-862 | Masteriyo LMS <= 2.2.0 - Missing Authorization to Unauthenticated Arbitrary C… |
| CVE-2026-86416 | 5.3 | — | ILIAS-eLearning e.V. | ILIAS | CWE-862 | ILIAS before 9.23, 10.11, and 11.4 Missing Authorization in Group Object Acti… |
| CVE-2026-86417 | 5.3 | — | MISP | MISP | CWE-200 | MISP Dashboard Template REST API Exposes Template Owner Email Addresses to Un… |
| CVE-2026-86436 | 5.3 | — | laradashboard | laradashboard | CWE-862 | Lara Dashboard before 1.3.2 Missing Authorization in Post-Builder Media Uploa… |
| CVE-2026-86451 | 5.3 | — | MISP | MISP | CWE-639 | MISP Event Graph Object Reference Lookup Exposes References from Unauthorized… |
| CVE-2026-86469 | 5.3 | — | Red Hat | Red Hat Enterprise Linux 10 | CWE-59 | Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path |
| CVE-2026-86351 | 5.1 | — | MISP | MISP | CWE-20 | MISP User Homepage Validation Allows Authenticated Open Redirect via Protocol… |
| CVE-2026-86440 | 5.1 | — | MISP | MISP | CWE-20 | MISP Dashboard Button Widget Allows Stored XSS via Unsafe javascript: and Bac… |
| CVE-2026-77699 | 5.0 | — | Zohocorp | ManageEngine Endpoint Central | CWE-269 | Privilege Escalation |
| CVE-2026-79943 | 4.8 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-297 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86423 | 4.8 | — | ImageMagick | ImageMagick | CWE-416 | ImageMagick before 7.1.2-30 Heap-use-after-free via GetList |
| CVE-2026-86425 | 4.8 | — | ImageMagick | ImageMagick | CWE-416 | ImageMagick before 7.1.2-30 Heap-use-after-free via Layer |
| CVE-2026-80176 | 4.7 | — | Dell | Secure Connect Gateway 5.0 - Application | CWE-257 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Applicat… |
| CVE-2026-86484 | 4.6 | — | JetBrains | YouTrack | CWE-79 | In JetBrains YouTrack before 2026.2.18634 angularJS template injection in ass… |
| CVE-2026-86481 | 4.3 | — | JetBrains | YouTrack | CWE-639 | In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure… |
| CVE-2026-86496 | 4.3 | — | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk … |
| CVE-2026-86499 | 4.3 | — | JetBrains | YouTrack | CWE-862 | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all… |
| CVE-2026-86486 | 3.7 | — | JetBrains | YouTrack | CWE-306 | In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler fai… |
| CVE-2025-52651 | 3.5 | — | HCL Software | MyXalytics | CWE-20 | HCL MyXalytics is affected by multiple security vulnerabilities. |
| CVE-2025-52652 | 3.5 | — | HCL Software | MyXalytics | CWE-451 | HCL MyXalytics is affected by multiple security vulnerabilities. |
| CVE-2025-52657 | 3.5 | — | HCL Software | MyXalytics | CWE-770 | HCL MyXalytics is affected by multiple security vulnerabilities. |
| CVE-2026-86491 | 3.5 | — | JetBrains | YouTrack | CWE-79 | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project… |
| CVE-2026-86485 | 3.3 | — | JetBrains | YouTrack | CWE-291 | In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowe… |
| CVE-2026-86503 | 3.3 | — | JetBrains | IntelliJ IDEA | CWE-918 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could… |
| CVE-2026-86505 | 3.3 | — | JetBrains | IntelliJ IDEA | CWE-201 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked… |
| CVE-2026-86487 | 3.1 | — | JetBrains | YouTrack | CWE-863 | In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed… |
| CVE-2026-86501 | 2.8 | — | JetBrains | IntelliJ IDEA | CWE-532 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be wr… |
| CVE-2026-82584 | 2.3 | — | ash-project | igniter | CWE-150 | Terminal escape sequence injection in the mix igniter.install confirmation pr… |
| CVE-2026-86418 | 2.3 | — | MISP | MISP | CWE-200 | MISP Dashboard Organisation Picker Exposes Hidden Organisation Metadata to Un… |
| CVE-2026-86441 | 2.3 | — | MISP | MISP | CWE-200 | MISP Dashboard Organisation Widgets Bypass Organisation-Index Restrictions an… |
| CVE-2026-81638 | 2.1 | — | ash-project | ash_double_entry | CWE-173 | Non-canonical ULID spellings are accepted and alias to the same record in ash… |
| CVE-2026-86291 | 2.1 | — | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System us_edit1.php sql injection |
| CVE-2026-86294 | 2.1 | — | SourceCodester | Simple Traffic Offense System | CWE-79 | SourceCodester Simple Traffic Offense System Settings Update Endpoint save-se… |
| CVE-2026-86307 | 2.1 | — | light0011 | cms | CWE-352 | light0011 cms cross-site request forgery |
| CVE-2026-86309 | 2.1 | — | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System pro_searchfrm.php sql injection |
| CVE-2026-86310 | 2.1 | — | itsourcecode | Sales and Inventory System | CWE-74 | itsourcecode Sales and Inventory System cust_edit1.php sql injection |
| CVE-2026-86301 | 2.0 | — | code-projects | Hospital Information System | CWE-79 | code-projects Hospital Information System Patient Management editPatient.php … |
| CVE-2026-86424 | 2.0 | — | ImageMagick | ImageMagick | CWE-59 | ImageMagick before 7.1.2-30 Path Traversal via TOCTOU Symlink Race |
| CVE-2026-86422 | 1.0 | — | ImageMagick | ImageMagick | CWE-59 | ImageMagick before 7.1.2-30 Path Policy TOCTOU Symlink Race |
| CVE-2026-16028 | await | — | — | Protocol-HTTP2 | CWE-401 | Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via clo… |
| CVE-2026-86287 | await | — | — | Net-IP-LPM | CWE-1287 | Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths |