Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,857
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,501 - 2,520 of 3,451 CVEs
CVE-2025-50192 CRITICAL - 9.8

Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30.

Vendor: chamilo
Product: chamilo-lms
Published: Mar 02, 2026
Source: NVD
CVE-2025-50190 CRITICAL - 9.8

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue has been patched in version 1.11.30.

Vendor: chamilo
Product: chamilo-lms
Published: Mar 02, 2026
Source: NVD
CVE-2025-50187 CRITICAL - 9.8

Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has been patched in version 1.11.28.

Vendor: chamilo
Product: chamilo-lms
Published: Mar 02, 2026
Source: NVD
CVE-2026-3432 CRITICAL - 9.1

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any user by supplying thei...

Vendor: sim
Product: sim
Published: Mar 02, 2026
Source: NVD
CVE-2026-3431 CRITICAL - 9.8

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including rea...

Vendor: sim
Product: sim
Published: Mar 02, 2026
Source: NVD
CVE-2025-14532 CRITICAL - 9.8

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue was fixed in versions above 5.0.

Vendor: Studio Fabryka
Product: DobryCMS
Published: Mar 02, 2026
Source: NVD
CVE-2026-3422 CRITICAL - 9.8

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

Vendor: edetw
Product: u-office_force
Published: Mar 02, 2026
Source: NVD
CVE-2026-3000 CRITICAL - 9.8

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.

Vendor: changingtec
Product: idexpert
Published: Mar 02, 2026
Source: NVD
CVE-2026-2999 CRITICAL - 9.8

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.

Vendor: changingtec
Product: idexpert
Published: Mar 02, 2026
Source: NVD
CVE-2026-28411 CRITICAL - 9.8

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This vulnerability can be leveraged to completely bypass authe...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Feb 27, 2026
Source: NVD
CVE-2026-28409 CRITICAL - 10.0

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authen...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Feb 27, 2026
Source: NVD
CVE-2026-28408 CRITICAL - 9.8

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its own authentication and permission checks. A malicious user could make a request through tools lik...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Feb 27, 2026
Source: NVD
CVE-2026-28268 CRITICAL - 9.8

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a critical...

Vendor: go-vikunja
Product: vikunja
Published: Feb 27, 2026
Source: NVD
CVE-2026-28231 CRITICAL - 9.1

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds r...

Vendor: bigcat88
Product: pillow_heif
Published: Feb 27, 2026
Source: NVD
CVE-2026-27755 CRITICAL - 9.8

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge authenticated sessions by computing predictable MD5-based cookies. Attackers who know or guess valid credentials can calculate the session identifier o...

Vendor: Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks)
Product: SODOLA SL902-SWTGW124AS
Published: Feb 27, 2026
Source: NVD
CVE-2026-27751 CRITICAL - 9.8

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain administrative access to the management interface. Attackers can authenticate using the hardcoded default credentials without password change enforcement to g...

Vendor: Shenzhen Hongyavision Technology Co., Ltd. (Sodola Networks)
Product: SODOLA SL902-SWTGW124AS
Published: Feb 27, 2026
Source: NVD
CVE-2026-2750 CRITICAL - 9.1

Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.

Published: Feb 27, 2026
Source: NVD
CVE-2026-2749 CRITICAL - 9.9

Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.

Published: Feb 27, 2026
Source: NVD
CVE-2025-11252 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects windesk.Fm: through 27022026. NOTE: The vendor was contacted early about this disclosure b...

Vendor: Signum Technology Promotion and Training Inc.
Product: windesk.fm
Published: Feb 27, 2026
Source: NVD
CVE-2026-24352 CRITICAL - 9.8

PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was notified early about t...

Vendor: PluXml
Product: PluXml CMS
Published: Feb 27, 2026
Source: NVD