CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2026-24737

    Last Modified: 18 Apr 2026

    jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following methods or properties, a user can inject arbitrary PDF objects, such as JavaScript actions, which are executed when the victim opens the document. The vulnerable API members are AcroformChoiceField.addOption, AcroformChoiceField.setOptions, AcroFormCheckBox.appearanceState, and AcroFormRadioButton.appearanceState. The vulnerability has been fixed in [email protected].

    Published: 2 Feb 2026
    8
    High

    CVE-2026-23997

    Last Modified: 18 Apr 2026

    FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. The flaw occurs in the History view, where historical data is rendered without proper HTML entity encoding. This allows an attacker to execute arbitrary JavaScript in the browser of viewing the history by administrators.

    Published: 2 Feb 2026
    7.3
    High

    CVE-2026-0924

    Last Modified: 21 Apr 2026

    BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoCleaner: 1.15.2.

    Published: 2 Feb 2026
    8.2
    High

    CVE-2026-1778

    Last Modified: 18 Apr 2026

    Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton Python model is imported, incorrectly allowing for requests with invalid and self-signed certificates to succeed.

    Published: 2 Feb 2026
    Unknown

    CVE-2026-25549

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 2 Feb 2026
    8.5
    High

    CVE-2026-1777

    Last Modified: 18 Apr 2026

    The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A third party with permissions to both call this API and permissions to modify objects in the Training Jobs S3 output location may have the ability to upload arbitrary artifacts which are executed the next time the Training Job is invoked.

    Published: 2 Feb 2026
    4.6
    Medium

    CVE-2026-24007

    Last Modified: 18 Apr 2026

    Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap is missing CSRF protection in the Overview inconsistent items. An attacker could use this vulnerability to trick victims into repairing inconsistent items (creating artifact links from the release). This vulnerability is fixed in Tuleap Community Edition 17.0.99.1768924735 and Tuleap Enterprise Edition 17.2-5, 17.1-6, and 17.0-9.

    Published: 2 Feb 2026
    7
    High

    CVE-2026-24051

    Last Modified: 15 Jun 2026

    OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.

    Published: 2 Feb 2026
    9.3
    Critical

    CVE-2026-24471

    Last Modified: 18 Apr 2026

    continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote server to cause the local server to sign an arbitrary event upon user interaction. Upon a user account leaving a room (rejecting an invite), joining a room or knocking on a room, the victim server may ask a remote server for assistance. If the victim asks the attacker server for assistance the attacker is able to provide an arbitrary event, which the victim will sign and return to the attacker. For the /leave endpoint, this works for any event with a supported room version, where the origin and origin_server_ts is set by the victim. For the /join endpoint, an additionally victim-set content field in the format of a join membership is needed. For the /knock endpoint, an additional victim-set content field in the format of a knock membership and a room version not between 1 and 6 is needed. This was exploited as a part of a larger chain against the continuwuity.org homeserver. This vulnerability affects all Conduit-derived servers. This vulnerability is fixed in Continuwuity 0.5.1, Conduit 0.10.11, Grapevine 0aae932b, and Tuwunel 1.4.9.

    Published: 2 Feb 2026
    8.6
    High

    CVE-2026-22229

    Last Modified: 16 Apr 2026

    A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the TP-Link Archer BE230 v1.2 and Deco BE25 v1.0. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Deco BE25 v1.0: through 1.1.1 Build 20250822.

    Published: 2 Feb 2026
    8.5
    High

    CVE-2026-22227

    Last Modified: 18 Apr 2026

    A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420.

    Published: 2 Feb 2026
    8.5
    High

    CVE-2026-22226

    Last Modified: 4 Jun 2026

    A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1.2 and Archer AX73 v2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AX73 v2 < 1.3.1 Build 20260430.

    Published: 2 Feb 2026
    8.5
    High

    CVE-2026-22225

    Last Modified: 18 Apr 2026

    A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the Archer BE230 v1.2  and Archer AXE75 v1.0. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AXE v1.0 < 1.5.3 Build 20260209 rel. 71108.

    Published: 2 Feb 2026
    8.5
    High

    CVE-2026-22224

    Last Modified: 18 Apr 2026

    A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface on the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420.

    Published: 2 Feb 2026
    8.5
    High

    CVE-2026-22223

    Last Modified: 18 Apr 2026

    An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID.This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420.

    Published: 2 Feb 2026
    8.5
    High

    CVE-2026-22222

    Last Modified: 18 Apr 2026

    An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID.This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420.

    Published: 2 Feb 2026
    8.5
    High

    CVE-2026-0631

    Last Modified: 31 Jul 2026

    An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AXE75 v1 < 1.5.6 Build 20260623.

    Published: 2 Feb 2026
    8.5
    High

    CVE-2026-0630

    Last Modified: 16 Apr 2026

    An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID.This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AXE v1.0 < 1.5.3 Build 20260209 rel. 71108.

    Published: 2 Feb 2026
    8.5
    High

    CVE-2026-22221

    Last Modified: 18 Apr 2026

    An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID.This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420.

    Published: 2 Feb 2026
    6.8
    Medium

    CVE-2026-1232

    Last Modified: 18 Apr 2026

    A medium-severity vulnerability has been identified in BeyondTrust Privilege Management for Windows versions <=25.7. Under certain conditions, a local authenticated user with elevated privileges may be able to bypass the product’s anti-tamper protections, which could allow access to protected application components and the ability to modify product configuration.

    Published: 2 Feb 2026
    4.5
    Medium

    CVE-2026-1770

    Last Modified: 18 Apr 2026

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass sandbox restrictions and obtain RCE (Remote Code Execution).

    Published: 2 Feb 2026
    6.5
    Medium

    CVE-2025-47402

    Last Modified: 11 Feb 2026

    Transient DOS when processing a received frame with an excessively large authentication information element.

    Published: 2 Feb 2026
    7.8
    High

    CVE-2025-47399

    Last Modified: 26 Feb 2026

    Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.

    Published: 2 Feb 2026
    7.8
    High

    CVE-2025-47398

    Last Modified: 26 Feb 2026

    Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers.

    Published: 2 Feb 2026
    7.8
    High

    CVE-2025-47397

    Last Modified: 26 Feb 2026

    Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.

    Published: 2 Feb 2026
    7.1
    High

    CVE-2025-47366

    Last Modified: 26 Feb 2026

    Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.

    Published: 2 Feb 2026
    6.8
    Medium

    CVE-2025-47364

    Last Modified: 26 Feb 2026

    Memory corruption while calculating offset from partition start point.

    Published: 2 Feb 2026
    6.8
    Medium

    CVE-2025-47363

    Last Modified: 26 Feb 2026

    Memory corruption when calculating oversized partition sizes without proper checks.

    Published: 2 Feb 2026
    7.8
    High

    CVE-2025-47359

    Last Modified: 26 Feb 2026

    Memory Corruption when multiple threads simultaneously access a memory free API.

    Published: 2 Feb 2026
    7.8
    High

    CVE-2025-47358

    Last Modified: 26 Feb 2026

    Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inadvertently.

    Published: 2 Feb 2026
    7.6
    High

    CVE-2025-14914

    Last Modified: 26 Feb 2026

    IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive containing path traversal sequences resulting in an overwrite of files leading to arbitrary code execution.

    Published: 2 Feb 2026
    4.3
    Medium

    CVE-2025-15395

    Last Modified: 11 Feb 2026

    IBM Jazz Foundation 7.0.3 through 7.0.3 iFix019 and 7.1.0 through 7.1.0 iFix005 is vulnerable to access control violations that allows the users to view or access/perform actions beyond their expected capability.

    Published: 2 Feb 2026
    2
    Low

    CVE-2026-1703

    Last Modified: 18 Apr 2026

    When pip is installing and extracting a maliciously crafted wheel archive, files may be extracted outside the installation directory. The path traversal is limited to prefixes of the installation directory, thus isn't able to inject or overwrite executable files in typical situations.

    Published: 2 Feb 2026
    9.8
    Critical

    CVE-2022-50981

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.

    Published: 2 Feb 2026
    6.5
    Medium

    CVE-2022-50980

    Last Modified: 15 Apr 2026

    A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via CAN.

    Published: 2 Feb 2026
    6.5
    Medium

    CVE-2022-50979

    Last Modified: 15 Apr 2026

    An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (RS485).

    Published: 2 Feb 2026
    7.5
    High

    CVE-2022-50978

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).

    Published: 2 Feb 2026
    7.5
    High

    CVE-2022-50977

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP.

    Published: 2 Feb 2026
    7.7
    High

    CVE-2022-50976

    Last Modified: 15 Apr 2026

    A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.

    Published: 2 Feb 2026
    8.8
    High

    CVE-2022-50975

    Last Modified: 15 Apr 2026

    An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the device if configuration via ethernet is enabled.

    Published: 2 Feb 2026
    8.6
    High

    CVE-2026-1186

    Last Modified: 18 Apr 2026

    EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Legislator application) and choose arbitrary path outside the intended directory (e.x. system startup) where files will be extracted by the victim upon opening the file. This issue was fixed in version 2.25a.

    Published: 2 Feb 2026
    7.8
    High

    CVE-2026-24071

    Last Modified: 18 Apr 2026

    It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses _xpc_connection_get_pid(arg2) as argument for the hasValidSignature function. This value can not be trusted since it is vulnerable to PID reuse attacks.

    Published: 2 Feb 2026
    8.8
    High

    CVE-2026-24070

    Last Modified: 29 Apr 2026

    During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helper2`, which is used by Native Access to trigger functions via XPC communication like copy-file, remove or set-permissions, is deployed as well. The communication with the XPC service of the privileged helper is only allowed if the client process is signed with the corresponding certificate and fulfills the following code signing requirement: "anchor trusted and certificate leaf[subject.CN] = \"Developer ID Application: Native Instruments GmbH (83K5EG6Z9V)\"" The Native Access application was found to be signed with the `com.apple.security.cs.allow-dyld-environment-variables` and `com.apple.security.cs.disable-library-validation` entitlements leading to DYLIB injection and therefore command execution in the context of this application. A low privileged user can exploit the DYLIB injection to trigger functions of the privileged helper XPC service resulting in privilege escalation by first deleting the /etc/sudoers file and then copying a malicious version of that file to /etc/sudoers.

    Published: 2 Feb 2026
    8.6
    High

    CVE-2025-8587

    Last Modified: 5 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows SQL Injection. This issue affects SKSPro: through 07012026.

    Published: 2 Feb 2026
    5.6
    Medium

    CVE-2026-1766

    Last Modified: 16 Jun 2026

    A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by providing a malicious MP3 file, leading to a denial of service (DoS), which causes an application crash, and potentially disclosing sensitive information from the heap memory.

    Published: 2 Feb 2026
    5.6
    Medium

    CVE-2026-1764

    Last Modified: 16 Jun 2026

    A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by triggering a read of unmapped memory. In some cases, it could also lead to information disclosure by reading visible heap data.

    Published: 2 Feb 2026
    5.6
    Medium

    CVE-2026-1767

    Last Modified: 16 Jun 2026

    A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the parsing of performer tags can lead to a read beyond the allocated buffer, potentially causing a Denial of Service (DoS) due to a crash or enabling information disclosure.

    Published: 2 Feb 2026
    5.6
    Medium

    CVE-2026-1765

    Last Modified: 16 Jun 2026

    A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially crafted MP3 files. A remote attacker could exploit this by providing a malicious MP3 file, leading to a Denial of Service (DoS) where the application crashes. It may also potentially expose sensitive information from the system's memory.

    Published: 2 Feb 2026
    7.5
    High

    CVE-2026-0599

    Last Modified: 18 Apr 2026

    A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The issue arises when the router scans inputs for Markdown image links and performs a blocking HTTP GET request, reading the entire response body into memory and cloning it before decoding. This behavior can lead to resource exhaustion, including network bandwidth saturation, memory inflation, and CPU overutilization. The vulnerability is triggered even if the request is later rejected for exceeding token limits. The default deployment configuration, which lacks memory usage limits and authentication, exacerbates the impact, potentially crashing the host machine. The issue is resolved in version 3.3.7.

    Published: 2 Feb 2026
    9.1
    Critical

    CVE-2024-5986

    Last Modified: 15 Apr 2026

    A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploiting the `/3/Parse` endpoint to inject attacker-controlled data as the header of an empty file, which is then exported using the `/3/Frames/framename/export` endpoint. The impact of this vulnerability includes the potential for remote code execution and complete access to the system running h2o-3, as attackers can overwrite critical files such as private SSH keys or script files.

    Published: 2 Feb 2026