CVE Feed

    Dashboard / CVE

    7.7
    High

    CVE-2026-20620

    Last Modified: 16 Apr 2026

    An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An attacker may be able to cause unexpected system termination or read kernel memory.

    Published: 11 Feb 2026
    6.5
    Medium

    CVE-2026-20636

    Last Modified: 16 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 11 Feb 2026
    5.7
    Medium

    CVE-2025-46302

    Last Modified: 28 Apr 2026

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2026-20661

    Last Modified: 16 Apr 2026

    An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

    Published: 11 Feb 2026
    7.5
    High

    CVE-2026-20650

    Last Modified: 15 Apr 2026

    A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Bluetooth packets.

    Published: 11 Feb 2026
    3.3
    Low

    CVE-2026-20646

    Last Modified: 15 Apr 2026

    A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read sensitive location information.

    Published: 11 Feb 2026
    7.8
    High

    CVE-2026-20611

    Last Modified: 16 Apr 2026

    An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.

    Published: 11 Feb 2026
    5.7
    Medium

    CVE-2025-46305

    Last Modified: 27 Apr 2026

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.

    Published: 11 Feb 2026
    5.5
    Medium

    CVE-2026-20666

    Last Modified: 16 Apr 2026

    An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.

    Published: 11 Feb 2026
    5.5
    Medium

    CVE-2026-20627

    Last Modified: 22 Aug 2026

    An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, watchOS 26.3. An app may be able to access sensitive user data.

    Published: 11 Feb 2026
    3.1
    Low

    CVE-2026-20671

    Last Modified: 16 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to intercept network traffic.

    Published: 11 Feb 2026
    7.8
    High

    CVE-2026-20626

    Last Modified: 15 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3. A malicious app may be able to gain root privileges.

    Published: 11 Feb 2026
    5.5
    Medium

    CVE-2026-20630

    Last Modified: 22 Aug 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access protected user data.

    Published: 11 Feb 2026
    5.7
    Medium

    CVE-2025-46304

    Last Modified: 7 Apr 2026

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. A malicious HID device may cause an unexpected process crash.

    Published: 11 Feb 2026
    8.8
    High

    CVE-2026-20667

    Last Modified: 16 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, watchOS 26.3. An app may be able to break out of its sandbox.

    Published: 11 Feb 2026
    7.8
    High

    CVE-2026-20610

    Last Modified: 15 Apr 2026

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.

    Published: 11 Feb 2026
    5.5
    Medium

    CVE-2026-20647

    Last Modified: 15 Apr 2026

    This issue was addressed with improved data protection. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.

    Published: 11 Feb 2026
    7.1
    High

    CVE-2026-20606

    Last Modified: 15 Apr 2026

    This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to bypass certain Privacy preferences.

    Published: 11 Feb 2026
    5.5
    Medium

    CVE-2025-43537

    Last Modified: 22 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.

    Published: 11 Feb 2026
    9.3
    Critical

    CVE-2026-26215

    Last Modified: 17 Apr 2026

    manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticated remote code execution. The FastAPI endpoints /simple_execute/{method} and /execute/{method} deserialize attacker-controlled request bodies using pickle.loads() without validation. Although a nonce-based authorization check is intended to restrict access, the nonce defaults to an empty string and the check is skipped, allowing remote attackers to execute arbitrary code in the server context by sending a crafted pickle payload.

    Published: 11 Feb 2026
    7.1
    High

    CVE-2026-1669

    Last Modified: 17 Apr 2026

    Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references.

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2026-26031

    Last Modified: 17 Apr 2026

    Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were able to access the full list of enrolled students (by email) in batches. This vulnerability is fixed in 2.44.0.

    Published: 11 Feb 2026
    7.5
    High

    CVE-2026-26029

    Last Modified: 17 Apr 2026

    sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability exists in sf-mcp-server due to unsafe use of child_process.exec when constructing Salesforce CLI commands with user-controlled input. Successful exploitation allows attackers to execute arbitrary shell commands with the privileges of the MCP server process.

    Published: 11 Feb 2026
    5.3
    Medium

    CVE-2026-26023

    Last Modified: 17 Apr 2026

    Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. User or llm inputs containing echarts containing a specific javascript payload will be executed. This vulnerability is fixed in 1.13.0.

    Published: 11 Feb 2026
    9.4
    Critical

    CVE-2026-26021

    Last Modified: 17 Apr 2026

    set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using Array.prototype. This has been fixed in version 2.0.5.

    Published: 11 Feb 2026
    6.5
    Medium

    CVE-2026-26012

    Last Modified: 17 Apr 2026

    vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization member can retrieve all ciphers within an organization, regardless of collection permissions. The endpoint /ciphers/organization-details is accessible to any organization member and internally uses Cipher::find_by_org to retrieve all ciphers. These ciphers are returned with CipherSyncType::Organization without enforcing collection-level access control. This vulnerability is fixed in 1.35.3.

    Published: 11 Feb 2026
    4.1
    Medium

    CVE-2026-26019

    Last Modified: 18 Apr 2026

    LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langchain/community is a web crawler that recursively follows links from a starting URL. Its preventOutside option (enabled by default) is intended to restrict crawling to the same site as the base URL. The implementation used String.startsWith() to compare URLs, which does not perform semantic URL validation. An attacker who controls content on a crawled page could include links to domains that share a string prefix with the target, causing the crawler to follow links to attacker-controlled or internal infrastructure. Additionally, the crawler performed no validation against private or reserved IP addresses. A crawled page could include links targeting cloud metadata services, localhost, or RFC 1918 addresses, and the crawler would fetch them without restriction. This vulnerability is fixed in 1.1.14.

    Published: 11 Feb 2026
    5.9
    Medium

    CVE-2026-26014

    Last Modified: 18 Apr 2026

    Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1.0 use random nonce generation with AES GCM ciphers, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack". Upgrade to v3.0.11, v3.1.1, or later.

    Published: 11 Feb 2026
    7.6
    High

    CVE-2026-26010

    Last Modified: 17 Apr 2026

    OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies). This vulnerability is fixed in 1.11.8.

    Published: 11 Feb 2026
    7.1
    High

    CVE-2026-25999

    Last Modified: 18 Apr 2026

    Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or deletion of metadata for any tenant. By sending a crafted request to the /resetMemoryCache endpoint, an attacker can clear cached configurations, environments, and cluster data. This vulnerability is fixed in 2.10.2.

    Published: 11 Feb 2026
    8.1
    High

    CVE-2026-25994

    Last Modified: 17 Apr 2026

    PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.

    Published: 11 Feb 2026
    8.6
    High

    CVE-2026-25990

    Last Modified: 30 Apr 2026

    Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

    Published: 11 Feb 2026
    8.5
    High

    CVE-2020-37158

    Last Modified: 20 Feb 2026

    AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.

    Published: 11 Feb 2026
    6.9
    Medium

    CVE-2020-37156

    Last Modified: 15 Apr 2026

    BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard without valid credentials. Attackers can exploit the vulnerability by sending a crafted payload with '=''or' parameters to bypass login authentication and gain unauthorized access.

    Published: 11 Feb 2026
    7.7
    High

    CVE-2020-37153

    Last Modified: 5 Mar 2026

    ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with root permissions through cron task manipulation.

    Published: 11 Feb 2026
    8.7
    High

    CVE-2020-37104

    Last Modified: 5 Mar 2026

    ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a list of 6-digit PIN combinations and fuzz the backup download URL to exfiltrate sensitive database information from the /database_backup/ directory.

    Published: 11 Feb 2026
    5.1
    Medium

    CVE-2019-25313

    Last Modified: 15 Apr 2026

    FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML form to trick authenticated users into submitting a request that creates a new local admin account with a predefined password.

    Published: 11 Feb 2026
    8.6
    High

    CVE-2026-25935

    Last Modified: 17 Apr 2026

    Vikunja is a todo-app to organize your life. Prior to 1.1.0, TaskGlanceTooltip.vue temporarily creates a div and sets the innerHtml to the description. Since there is no escaping on either the server or client side, a malicious user can share a project, create a malicious task, and cause an XSS on hover. This vulnerability is fixed in 1.1.0.

    Published: 11 Feb 2026
    8.4
    High

    CVE-2026-25924

    Last Modified: 17 Apr 2026

    Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulnerability in Kanboard allows an authenticated administrator to achieve full Remote Code Execution (RCE). Although the application correctly hides the plugin installation interface when the PLUGIN_INSTALLER configuration is set to false, the underlying backend endpoint fails to verify this security setting. An attacker can exploit this oversight to force the server to download and install a malicious plugin, leading to arbitrary code execution. This vulnerability is fixed in 1.2.50.

    Published: 11 Feb 2026
    8.7
    High

    CVE-2026-25759

    Last Modified: 17 Apr 2026

    Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allows authenticated users with content creation permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. Malicious user must have an account with control panel access and content creation permissions. This vulnerability can be exploited to allow super admin accounts to be created. This has been fixed in 6.2.3.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37215

    Last Modified: 15 Apr 2026

    MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the 'User Name and Registration Code' field to trigger an application crash.

    Published: 11 Feb 2026
    8.7
    High

    CVE-2020-37214

    Last Modified: 15 Apr 2026

    Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path parameter. Attackers can exploit the path parameter in /admin/voyager-assets to read arbitrary files like /etc/passwd and .env configuration files.

    Published: 11 Feb 2026
    6.7
    Medium

    CVE-2020-37213

    Last Modified: 15 Apr 2026

    TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized buffer in the license key field. Attackers can generate a 6000-byte payload and paste it into the activation field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37212

    Last Modified: 26 Feb 2026

    SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37211

    Last Modified: 26 Feb 2026

    SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37210

    Last Modified: 26 Feb 2026

    SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37209

    Last Modified: 20 Feb 2026

    SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37208

    Last Modified: 20 Feb 2026

    SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash and denial of service.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37207

    Last Modified: 26 Feb 2026

    SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37206

    Last Modified: 28 Jul 2026

    ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload to trigger an application crash when pasted into the registration key field.

    Published: 11 Feb 2026