Browse CVEs

225 CVEs analyzed. 653 pending.

All Critical High Medium Low
CVE-2025-70958 6.1

Multiple reflected cross-site scripting (XSS) vulnerabilities in Subrion CMS v4.2.1 installation module allow attackers to inject malicious JavaScript...

Feb 2, 2026
CVE-2025-70959 5.4

A stored cross-site scripting vulnerability in Tendenci CMS allows attackers to inject malicious scripts into the Jobs module. When users view affecte...

Feb 2, 2026
CVE-2025-70960 5.4

A stored cross-site scripting (XSS) vulnerability in Tendenci CMS v15.3.7 allows attackers to inject malicious scripts into forum posts that execute w...

Feb 2, 2026
CVE-2025-15395 4.3

This CVE describes an access control vulnerability in IBM Jazz Foundation that allows authenticated users to perform actions or view data beyond their...

Feb 2, 2026
CVE-2025-14914 7.6

This vulnerability allows a privileged user in IBM WebSphere Application Server Liberty to upload a zip archive containing path traversal sequences, w...

Feb 2, 2026
CVE-2026-1703 N/A

This CVE describes a path traversal vulnerability in pip's wheel archive extraction. When installing a maliciously crafted wheel file, attackers can w...

Feb 2, 2026
CVE-2022-50980 6.5

An unauthenticated attacker on the same Controller Area Network (CAN) bus can disrupt operations by rapidly switching between configuration presets. T...

Feb 2, 2026
CVE-2022-50981 9.8

CVE-2022-50981 allows unauthenticated remote attackers to gain full administrative access to affected devices because they ship without a default pass...

Feb 2, 2026
CVE-2022-50976 7.7

This vulnerability allows a local attacker with physical USB access to cause a full device reset by using an invalid reset file. It affects devices th...

Feb 2, 2026
CVE-2022-50977 7.5

CVE-2022-50977 allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration presets via HTTP requests. Th...

Feb 2, 2026
CVE-2022-50978 7.5

This vulnerability allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration presets via Modbus TCP. I...

Feb 2, 2026
CVE-2022-50979 6.5

This vulnerability allows an unauthenticated attacker on the same network segment to disrupt operations by switching between multiple configuration pr...

Feb 2, 2026
CVE-2022-50975 8.8

This vulnerability allows an unauthenticated remote attacker to hijack existing user sessions and gain full administrative access to affected devices....

Feb 2, 2026
CVE-2026-24070 8.8

This vulnerability allows local privilege escalation on macOS systems running Native Access. A low-privileged user can exploit DYLIB injection in the ...

Feb 2, 2026
CVE-2026-24071 7.8

This vulnerability allows attackers to bypass code signature verification in Native Access's XPC service on macOS through PID reuse attacks. An attack...

Feb 2, 2026
CVE-2026-1186 N/A

EAP Legislator contains a path traversal vulnerability in its file extraction functionality. Attackers can craft malicious zipx archives that, when op...

Feb 2, 2026
CVE-2026-1760 5.3

This HTTP request smuggling vulnerability in SoupServer allows remote attackers to send specially crafted requests that bypass normal request processi...

Feb 2, 2026
CVE-2026-1761 8.6

A stack-based buffer overflow vulnerability in libsoup allows remote attackers to execute arbitrary code or crash applications by sending specially cr...

Feb 2, 2026
CVE-2025-8587 8.6

This SQL injection vulnerability in AKCE Software's SKSPro allows attackers to execute arbitrary SQL commands on the database. All SKSPro installation...

Feb 2, 2026
CVE-2026-1757 6.2

A memory leak vulnerability in xmllint's interactive shell allows local denial-of-service attacks. When users input only whitespace, the program fails...

Feb 2, 2026
CVE-2025-6208 5.3

The SimpleDirectoryReader component in llama_index.core versions before 0.12.41 has a memory management flaw where it loads all files from a directory...

Feb 2, 2026
CVE-2025-7105 5.7

This vulnerability in LibreChat allows attackers to exploit an unrestricted fork function to create numerous content forks containing large Mermaid gr...

Feb 2, 2026
CVE-2026-0599 7.5

This vulnerability in huggingface/text-generation-inference allows unauthenticated attackers to trigger resource exhaustion by exploiting unbounded ex...

Feb 2, 2026
CVE-2024-4147 7.5

This vulnerability allows authenticated users in lunary-ai/lunary to delete prompts belonging to other organizations through ID manipulation. The appl...

Feb 2, 2026
CVE-2024-5386 9.6

In lunary-ai/lunary version 1.2.2, a privilege escalation vulnerability allows users with 'viewer' role to hijack other user accounts by obtaining pas...

Feb 2, 2026
CVE-2024-5986 9.1

This vulnerability in h2o-3 allows remote attackers to write arbitrary data to any file on the server, potentially leading to remote code execution an...

Feb 2, 2026
CVE-2025-10279 7.0

This CVE describes a local privilege escalation vulnerability in mlflow versions before 3.4.0 where temporary directories for Python virtual environme...

Feb 2, 2026
CVE-2024-2356 9.6

This CVE describes a Local File Inclusion vulnerability in the lollms-webui application that allows attackers to execute arbitrary Python code remotel...

Feb 2, 2026
CVE-2026-1751 3.1

This vulnerability in GitLab CE/EE allows unauthorized users to edit merge request approval rules under specific conditions. It affects all GitLab ins...

Feb 2, 2026
CVE-2026-1117 8.2

This vulnerability allows unauthenticated attackers to trigger resource-intensive text generation operations and manipulate server state in the lollms...

Feb 2, 2026
CVE-2024-54263 7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Talemy Spirit Framework WordPress plugin. Attackers can exploit improper filename c...

Feb 2, 2026
CVE-2026-20420 7.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...

Feb 2, 2026
CVE-2026-20421 7.5

This vulnerability allows remote attackers to cause a system crash (denial of service) in affected modem devices by connecting to a rogue base station...

Feb 2, 2026
CVE-2026-20422 7.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by connectin...

Feb 2, 2026
CVE-2026-20411 7.8

This CVE describes a use-after-free vulnerability in the cameraisp component that could allow local privilege escalation. Attackers with System privil...

Feb 2, 2026
CVE-2026-20412 7.8

CVE-2026-20412 is an out-of-bounds write vulnerability in the cameraisp component that allows local privilege escalation. Attackers with initial Syste...

Feb 2, 2026
CVE-2026-20413 6.7

This CVE describes an out-of-bounds write vulnerability in the imgsys component due to missing bounds checks. It allows local privilege escalation fro...

Feb 2, 2026
CVE-2026-20414 6.7

This CVE describes a use-after-free vulnerability in the imgsys component that allows local privilege escalation. An attacker who already has System p...

Feb 2, 2026
CVE-2026-20415 5.5

This vulnerability in the imgsys component allows memory corruption due to improper locking. It enables local denial of service attacks when exploited...

Feb 2, 2026
CVE-2026-20417 5.3

This CVE describes an out-of-bounds write vulnerability in PCIe drivers that could allow local privilege escalation. Attackers with initial System pri...

Feb 2, 2026
CVE-2026-20418 9.8

CVE-2026-20418 is a critical out-of-bounds write vulnerability in Thread protocol implementations that allows remote attackers to execute arbitrary co...

Feb 2, 2026
CVE-2026-20419 7.5

This vulnerability in MediaTek wlan AP/STA firmware allows remote attackers within wireless range to cause denial of service by making the system unre...

Feb 2, 2026
CVE-2026-20404 7.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. An attacker can crash the system by connectin...

Feb 2, 2026
CVE-2026-20405 7.5

This vulnerability in MediaTek modems allows remote denial of service through system crashes when devices connect to rogue base stations. Attackers ca...

Feb 2, 2026
CVE-2026-20406 7.5

This vulnerability allows remote denial of service attacks against devices with affected MediaTek modems. An attacker can crash the system by connecti...

Feb 2, 2026
CVE-2026-20407 9.3

This CVE describes a privilege escalation vulnerability in MediaTek wlan STA drivers where missing bounds checks allow local attackers to gain elevate...

Feb 2, 2026
CVE-2026-20408 8.8

This CVE describes a heap buffer overflow vulnerability in wlan (wireless LAN) components that allows remote attackers to execute arbitrary code witho...

Feb 2, 2026
CVE-2026-20409 7.8

CVE-2026-20409 is an out-of-bounds write vulnerability in the imgsys component that allows local privilege escalation. Attackers with initial System p...

Feb 2, 2026
CVE-2026-20410 6.7

This CVE describes an out-of-bounds write vulnerability in imgsys (likely MediaTek image processing subsystem) that allows local privilege escalation....

Feb 2, 2026
CVE-2026-20401 7.5

This vulnerability allows remote denial of service attacks against mobile devices with affected MediaTek modems. An attacker can crash the system by c...

Feb 2, 2026