Vulnerebility FEBRUARY
H
ECV
KB
KEV
|
2026()
2025()
|
Vulnerebility Calendar
Top Vulnerebility
List of Attack
CWE
Anti-Debug
Tricks
2026 January February March April May June July August September October November December
|
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
| 27.2.26 | CVE-2026-20127 | an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. | ||
| 27.2.26 | CVE-2022-20775 | a path traversal vulnerability that allows an authenticated, local attacker to gain elevated privileges and execute arbitrary commands as root. | ||
| 27.2.26 | CVE-2026-20127 | Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | ||
| 26.2.26 | Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup Warning | When Claude Code was started in a new directory, it displayed a warning asking, "Do you trust the files in this folder?". This warning did not properly document that selecting "Yes, proceed" would allow Claude Code to execute files in the folder without additional confirmation. This may not have been clear to a user so we have updated the warning to clarify this functionality. | ||
| 26.2.26 | CVE-2025-59536 | (CVSS score: 8.7) - A code injection vulnerability that allows execution of arbitrary shell commands automatically upon tool initialization when a user starts Claude Code in an untrusted directory. (Fixed in version 1.0.111 in October 2025) | ||
| 26.2.26 | CVE-2026-21852 | (CVSS score: 5.3) - An information disclosure vulnerability in Claude Code's project-load flow that allows a malicious repository to exfiltrate data, including Anthropic API keys. (Fixed in version 2.0.65 in January 2026) | ||
| 26.2.26 | CVE-2025-40538 | A broken access control vulnerability that allows an attacker to create a system admin user and execute arbitrary code as root via domain admin or group admin privileges. | ||
| 26.2.26 | CVE-2025-40539 | A type confusion vulnerability that allows an attacker to execute arbitrary native code as root. | ||
| 26.2.26 | CVE-2025-40540 | A type confusion vulnerability that allows an attacker to execute arbitrary native code as root. | ||
| 26.2.26 | CVE-2025-40541 | An insecure direct object reference (IDOR) vulnerability that allows an attacker to execute native code as root. | ||
| 21.2.26 | CVE-2026-22769 | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. | ||
| 21.2.26 | CVE-2025-49113 | A deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. (Fixed in June 2025) | ||
| 21.2.26 | CVE-2025-68461 | A cross-site scripting vulnerability via the animate tag in an SVG document. (Fixed in December 2025) | ||
| 20.2.26 | CVE-2026-26119 | Windows Admin Center Elevation of Privilege Vulnerability | ||
| 20.2.26 | CVE-2026-26119 | Windows Admin Center Elevation of Privilege Vulnerability | ||
| 19.2.26 | CVE-2026-2329 | CVE-2026-2329: Critical Unauthenticated Stack Buffer Overflow in Grandstream GXP1600 VoIP Phones (FIXED) | ||
| 18.2.26 | CVE-2026-2441 | (CVSS score: 8.8) - A use-after-free vulnerability in Google Chrome that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| 18.2.26 | CVE-2024-7694 | (CVSS score: 7.2) - An arbitrary file upload vulnerability in TeamT5 ThreatSonar Anti-Ransomware versions 3.4.5 and earlier that could allow an attacker to upload malicious files and achieve arbitrary system command execution on the server. | ||
| 18.2.26 | CVE-2020-7796 | (CVSS score: 9.8) - A server-side request forgery (SSRF) vulnerability in Synacor Zimbra Collaboration Suite (ZCS) that could allow an attacker to send a crafted HTTP request to a remote host and obtain unauthorized access to sensitive information. | ||
| 18.2.26 | CVE-2008-0015 | (CVSS score: 8.8) - A stack-based buffer overflow vulnerability in Microsoft Windows Video ActiveX Control that could allow an attacker to achieve remote code execution by setting up a specially crafted web page. | ||
| 18.2.26 | CVE-2025-65717 | An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page. | ||
| 18.2.26 | CVE-2025-65715 | An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace. | ||
| 18.2.26 | CVE-2025-65716 | An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file. | ||
| 16.2.26 | CVE-2026-2441 | Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | ||
| 13.2.26 | CVE-2026-1731 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user. | ||
| 12.2.26 | CVE-2026-20700 | A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. | ||
| 11.2.26 | CVE-2026-21533 | (CVSS score: 7.8) - An improper privilege management in Windows Remote Desktop that allows an authorized attacker to elevate privileges locally. | VULNEREBILITY | VULNEREBILITY |
| 11.2.26 | CVE-2026-21525 | (CVSS score: 6.2) - A null pointer dereference in Windows Remote Access Connection Manager that allows an unauthorized attacker to deny service locally. | VULNEREBILITY | VULNEREBILITY |
| 11.2.26 | CVE-2026-21519 | (CVSS score: 7.8) - An access of resource using incompatible type ('type confusion') in the Desktop Window Manager that allows an authorized attacker to elevate privileges locally. | VULNEREBILITY | VULNEREBILITY |
| 11.2.26 | CVE-2026-21514 | (CVSS score: 7.8) - A reliance on untrusted inputs in a security decision in Microsoft Office Word that allows an unauthorized attacker to bypass a security feature locally. | VULNEREBILITY | VULNEREBILITY |
| 11.2.26 | CVE-2026-21513 | (CVSS score: 8.8) - A protection mechanism failure in MSHTML Framework that allows an unauthorized attacker to bypass a security feature over a network. | VULNEREBILITY | VULNEREBILITY |
| 11.2.26 | CVE-2026-21510 | (CVSS score: 8.8) - A protection mechanism failure in Windows Shell that allows an unauthorized attacker to bypass a security feature over a network. | VULNEREBILITY | VULNEREBILITY |
| 10.2.26 | CVE-2026-21643 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | VULNEREBILITY | VULNEREBILITY |
| 9.2.26 | CVE-2026-1731 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user. | VULNEREBILITY | VULNEREBILITY |
| 8.2.26 | CVE-2025-11953 | The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments. | VULNEREBILITY | VULNEREBILITY |
| 6.2.26 | Evaluating and mitigating the growing risk of LLM-discovered 0-days | Claude Opus 4.6, released today, continues a trajectory of meaningful improvements in AI models’ cybersecurity capabilities. Last fall, we wrote that we believed we were at an inflection point for AI's impact on cybersecurity—that progress could become quite fast, and now was the moment to accelerate defensive use of AI. | VULNEREBILITY | VULNEREBILITY |
| 5.2.26 | CVE-2026-25049 | n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running n8n. | VULNEREBILITY | VULNEREBILITY |
| 4.2.26 | CVE-2021-39935 | (CVSS score: 7.5/6.8) - A server-side request forgery (SSRF) vulnerability in GitLab Community and Enterprise Editions that could allow unauthorized external users to perform Server Side Requests via the CI Lint API | VULNEREBILITY | VULNEREBILITY |
| 4.2.26 | CVE-2025-64328 | (CVSS score: 8.6) - An operating system command injection vulnerability in Sangoma FreePBX that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function and potentially obtain remote access to the system as an asterisk user | VULNEREBILITY | VULNEREBILITY |
| 4.2.26 | CVE-2019-19006 | (CVSS score: 9.8) - An improper authentication vulnerability in Sangoma FreePBX that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX administrator | VULNEREBILITY | VULNEREBILITY |
| 4.2.26 | CVE-2025-40551 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | VULNEREBILITY | VULNEREBILITY |
| 4.2.26 | DockerDash | DockerDash: Two Attack Paths, One AI Supply Chain Crisis | VULNEREBILITY | VULNEREBILITY |
| 3.2.26 | CVE-2026-25253 | OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value. | VULNEREBILITY | VULNEREBILITY |