Total CVEs

125,574

Critical Severity

2,253

High Severity

7,771

Last 7 Days

1,108
Quick preset (or use dates below)
Clear Filters
Showing 201 - 220 of 1,441 CVEs
CVE-2026-22227 HIGH - 7.2

A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromi...

Vendor: TP-Link Systems Inc.
Product: Archer BE230 v1.2
Published: Feb 02, 2026
Source: NVD
CVE-2026-22226 HIGH - 7.2

A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of confi...

Vendor: TP-Link Systems Inc.
Product: Archer BE230 v1.2
Published: Feb 02, 2026
Source: NVD
CVE-2026-22225 HIGH - 7.2

A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrit...

Vendor: TP-Link Systems Inc.
Product: Archer BE230 v1.2
Published: Feb 02, 2026
Source: NVD
CVE-2026-22224 HIGH - 7.2

A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface on the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configu...

Vendor: TP-Link Systems Inc.
Product: Archer BE230 v1.2
Published: Feb 02, 2026
Source: NVD
CVE-2026-22223 HIGH - 8.0

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration inte...

Vendor: TP-Link System Inc.
Product: Archer BE230 v1.2
Published: Feb 02, 2026
Source: NVD
CVE-2026-22222 HIGH - 8.0

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration int...

Vendor: TP-Link Systems Inc.
Product: Archer BE230 v1.2
Published: Feb 02, 2026
Source: NVD
CVE-2026-22221 HIGH - 8.0

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration inte...

Vendor: TP-Link Systems Inc.
Product: Archer BE230 v1.2
Published: Feb 02, 2026
Source: NVD
CVE-2026-0631 HIGH - 8.0

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration ...

Vendor: tp-link
Product: archer_be230_firmware
Published: Feb 02, 2026
Source: NVD
CVE-2026-0630 HIGH - 8.0

An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration int...

Vendor: tp-link
Product: archer_be230_firmware
Published: Feb 02, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: null_blk: fix kmemleak by releasing references to fault configfs items When CONFIG_BLK_DEV_NULL_BLK_FAULT_INJECTION is enabled, the null-blk driver sets up fault injection support by creating the timeout_inject, requeue_inject, an...

Vendor: Linux
Product: Linux
Published: Jan 31, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: inet: frags: drop fraglist conntrack references Jakub added a warning in nf_conntrack_cleanup_net_list() to make debugging leaked skbs/conntrack references more obvious. syzbot reports this as triggering, and I can also reproduce...

Vendor: Linux
Product: Linux
Published: Jan 31, 2026
Source: NVD
CVE-2026-24868 HIGH - 7.5

Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability affects Firefox < 147.0.2.

Vendor: Mozilla
Product: Firefox
Published: Jan 27, 2026
Source: NVD
CVE-2025-55095 MEDIUM - 4.2

The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters an extended partition entry in the partition table, it recursively calls itself to mount the next logical partition. This recursion occurs in _ux_host_class_stor...

Vendor: Eclipse Foundation
Product: Eclipse ThreadX - USBX
Published: Jan 27, 2026
Source: NVD
CVE-2020-36939 HIGH - 7.5

Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating path traversal parameters. Attackers can exploit the disabled Rack::Protection module to read sensitive system files like /etc/passwd and retrieve Apache Cas...

Vendor: avalanche123
Product: Cassandra Web
Published: Jan 27, 2026
Source: NVD

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in FASTSHIFT X-TRACK (Software/X-Track/USER/App/Utils/lv_img_png/PNGdec/src modules). This vulnerability is associated with program files inflate.C. This issue affects X-TRACK: throug...

Vendor: FASTSHIFT
Product: X-TRACK
Published: Jan 27, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzbot reported use-after-free of inet6_ifaddr in inet6_addr_del(). [0] The cited commit accidentally moved ipv6_del_addr() for mngtmpaddr before reading its ifp->flags for tempora...

Vendor: Linux
Product: Linux
Published: Jan 25, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() syzbot was able to crash the kernel in rt6_uncached_list_flush_dev() in an interesting way [1] Crash happens in list_del_init()/INIT_LIST_HEAD() while writing l...

Vendor: Linux
Product: Linux
Published: Jan 25, 2026
Source: NVD
CVE-2025-14609 MEDIUM - 5.3

The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.9. This is due to missing capability checks on the REST API endpoint '/wise-analytics/v1/report'. This makes it possible for unauthenticated attackers to access sensitiv...

Vendor: marcinlawrowski
Product: Wise Analytics
Published: Jan 24, 2026
Source: NVD
CVE-2026-1386 MEDIUM - 6.0

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at ja...

Vendor: amazon
Product: firecracker
Published: Jan 23, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: nfsd: provide locking for v4_end_grace Writing to v4_end_grace can race with server shutdown and result in memory being accessed after it was freed - reclaim_str_hashtbl in particularly. We cannot hold nfsd_mutex across the nfsd4...

Vendor: Linux
Product: Linux
Published: Jan 23, 2026
Source: NVD