Vulnerebility FEBRUARY  H  ECV  KB  KEV |  2026()  2025() |
Vulnerebility Calendar  Top Vulnerebility  List of Attack  CWE   Anti-Debug Tricks


2026  January  February  March  April  May  June  July  August  September  October  November  December


DATE

NAME

INFO

CATEGORY

SUBCATE

27.2.26 CVE-2026-20127 an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

VULNEREBILITY

VULNEREBILITY

27.2.26 CVE-2022-20775 a path traversal vulnerability that allows an authenticated, local attacker to gain elevated privileges and execute arbitrary commands as root.

VULNEREBILITY

VULNEREBILITY

27.2.26 CVE-2026-20127 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

VULNEREBILITY

VULNEREBILITY

26.2.26 Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup Warning When Claude Code was started in a new directory, it displayed a warning asking, "Do you trust the files in this folder?". This warning did not properly document that selecting "Yes, proceed" would allow Claude Code to execute files in the folder without additional confirmation. This may not have been clear to a user so we have updated the warning to clarify this functionality.

VULNEREBILITY

VULNEREBILITY

26.2.26 CVE-2025-59536 (CVSS score: 8.7) - A code injection vulnerability that allows execution of arbitrary shell commands automatically upon tool initialization when a user starts Claude Code in an untrusted directory. (Fixed in version 1.0.111 in October 2025)

VULNEREBILITY

VULNEREBILITY

26.2.26 CVE-2026-21852 (CVSS score: 5.3) - An information disclosure vulnerability in Claude Code's project-load flow that allows a malicious repository to exfiltrate data, including Anthropic API keys. (Fixed in version 2.0.65 in January 2026)

VULNEREBILITY

VULNEREBILITY

26.2.26 CVE-2025-40538 A broken access control vulnerability that allows an attacker to create a system admin user and execute arbitrary code as root via domain admin or group admin privileges.

VULNEREBILITY

VULNEREBILITY

26.2.26 CVE-2025-40539 A type confusion vulnerability that allows an attacker to execute arbitrary native code as root.

VULNEREBILITY

VULNEREBILITY

26.2.26 CVE-2025-40540 A type confusion vulnerability that allows an attacker to execute arbitrary native code as root.

VULNEREBILITY

VULNEREBILITY

26.2.26 CVE-2025-40541 An insecure direct object reference (IDOR) vulnerability that allows an attacker to execute native code as root.

VULNEREBILITY

VULNEREBILITY

21.2.26 CVE-2026-22769 Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability.

VULNEREBILITY

VULNEREBILITY

21.2.26 CVE-2025-49113 A deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. (Fixed in June 2025)

VULNEREBILITY

VULNEREBILITY

21.2.26 CVE-2025-68461 A cross-site scripting vulnerability via the animate tag in an SVG document. (Fixed in December 2025)

VULNEREBILITY

VULNEREBILITY

20.2.26 CVE-2026-26119 Windows Admin Center Elevation of Privilege Vulnerability

VULNEREBILITY

VULNEREBILITY

20.2.26 CVE-2026-26119 Windows Admin Center Elevation of Privilege Vulnerability

VULNEREBILITY

VULNEREBILITY

19.2.26 CVE-2026-2329 CVE-2026-2329: Critical Unauthenticated Stack Buffer Overflow in Grandstream GXP1600 VoIP Phones (FIXED)

VULNEREBILITY

VULNEREBILITY

18.2.26 CVE-2026-2441 (CVSS score: 8.8) - A use-after-free vulnerability in Google Chrome that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page.

VULNEREBILITY

VULNEREBILITY

18.2.26 CVE-2024-7694 (CVSS score: 7.2) - An arbitrary file upload vulnerability in TeamT5 ThreatSonar Anti-Ransomware versions 3.4.5 and earlier that could allow an attacker to upload malicious files and achieve arbitrary system command execution on the server.

VULNEREBILITY

VULNEREBILITY

18.2.26 CVE-2020-7796 (CVSS score: 9.8) - A server-side request forgery (SSRF) vulnerability in Synacor Zimbra Collaboration Suite (ZCS) that could allow an attacker to send a crafted HTTP request to a remote host and obtain unauthorized access to sensitive information.

VULNEREBILITY

VULNEREBILITY

18.2.26 CVE-2008-0015 (CVSS score: 8.8) - A stack-based buffer overflow vulnerability in Microsoft Windows Video ActiveX Control that could allow an attacker to achieve remote code execution by setting up a specially crafted web page.

VULNEREBILITY

VULNEREBILITY

18.2.26 CVE-2025-65717 An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.

VULNEREBILITY

VULNEREBILITY

18.2.26 CVE-2025-65715 An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace.

VULNEREBILITY

VULNEREBILITY

18.2.26 CVE-2025-65716 An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file.

VULNEREBILITY

VULNEREBILITY

16.2.26 CVE-2026-2441 Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

VULNEREBILITY

VULNEREBILITY

13.2.26 CVE-2026-1731 BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

VULNEREBILITY

VULNEREBILITY

12.2.26 CVE-2026-20700 A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3.

VULNEREBILITY

VULNEREBILITY

11.2.26 CVE-2026-21533 (CVSS score: 7.8) - An improper privilege management in Windows Remote Desktop that allows an authorized attacker to elevate privileges locally. VULNEREBILITY VULNEREBILITY
11.2.26 CVE-2026-21525 (CVSS score: 6.2) - A null pointer dereference in Windows Remote Access Connection Manager that allows an unauthorized attacker to deny service locally. VULNEREBILITY VULNEREBILITY
11.2.26 CVE-2026-21519 (CVSS score: 7.8) - An access of resource using incompatible type ('type confusion') in the Desktop Window Manager that allows an authorized attacker to elevate privileges locally. VULNEREBILITY VULNEREBILITY
11.2.26 CVE-2026-21514 (CVSS score: 7.8) - A reliance on untrusted inputs in a security decision in Microsoft Office Word that allows an unauthorized attacker to bypass a security feature locally. VULNEREBILITY VULNEREBILITY
11.2.26 CVE-2026-21513 (CVSS score: 8.8) - A protection mechanism failure in MSHTML Framework that allows an unauthorized attacker to bypass a security feature over a network. VULNEREBILITY VULNEREBILITY
11.2.26 CVE-2026-21510 (CVSS score: 8.8) - A protection mechanism failure in Windows Shell that allows an unauthorized attacker to bypass a security feature over a network. VULNEREBILITY VULNEREBILITY
10.2.26 CVE-2026-21643 An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. VULNEREBILITY VULNEREBILITY
9.2.26 CVE-2026-1731 BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user. VULNEREBILITY VULNEREBILITY
8.2.26 CVE-2025-11953 The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments. VULNEREBILITY VULNEREBILITY
6.2.26 Evaluating and mitigating the growing risk of LLM-discovered 0-days Claude Opus 4.6, released today, continues a trajectory of meaningful improvements in AI models’ cybersecurity capabilities. Last fall, we wrote that we believed we were at an inflection point for AI's impact on cybersecurity—that progress could become quite fast, and now was the moment to accelerate defensive use of AI. VULNEREBILITY VULNEREBILITY
5.2.26 CVE-2026-25049 n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running n8n. VULNEREBILITY VULNEREBILITY
4.2.26 CVE-2021-39935 (CVSS score: 7.5/6.8) - A server-side request forgery (SSRF) vulnerability in GitLab Community and Enterprise Editions that could allow unauthorized external users to perform Server Side Requests via the CI Lint API VULNEREBILITY VULNEREBILITY
4.2.26 CVE-2025-64328 (CVSS score: 8.6) - An operating system command injection vulnerability in Sangoma FreePBX that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function and potentially obtain remote access to the system as an asterisk user VULNEREBILITY VULNEREBILITY
4.2.26 CVE-2019-19006 (CVSS score: 9.8) - An improper authentication vulnerability in Sangoma FreePBX that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX administrator VULNEREBILITY VULNEREBILITY
4.2.26 CVE-2025-40551 SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. VULNEREBILITY VULNEREBILITY
4.2.26 DockerDash DockerDash: Two Attack Paths, One AI Supply Chain Crisis VULNEREBILITY VULNEREBILITY
3.2.26 CVE-2026-25253 OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value. VULNEREBILITY VULNEREBILITY