Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,750
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,821 - 2,840 of 3,470 CVEs
CVE-2025-15573 CRITICAL - 9.4

The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.solaxcloud.com, TCP 8883). This allows attackers in a man-in-the-middle position to act as the legitimate MQTT server and issue arbitrary commands to devic...

Vendor: SolaX Power
Product: Pocket WiFi 3.0, Pocket WiFi+LAN, Pocket WiFi+4GM, Pocket WiFi+LAN 2.0, Pocket WiFi 4.0
Published: Feb 12, 2026
Source: NVD
CVE-2025-14892 CRITICAL - 9.8

The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.

Vendor: Unknown
Product: Prime Listing Manager
Published: Feb 12, 2026
Source: NVD
CVE-2026-1729 CRITICAL - 9.8

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possib...

Published: Feb 12, 2026
Source: NVD
CVE-2026-20677 CRITICAL - 9.0

A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. A shortcut may be able to bypass sandbox restrictions.

Vendor: Apple
Product: macOS, visionOS, iOS and iPadOS
Published: Feb 11, 2026
Source: NVD
CVE-2025-67135 CRITICAL - 9.8

Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.

Published: Feb 11, 2026
Source: NVD
CVE-2026-26021 CRITICAL - 9.8

set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbi...

Vendor: ahdinosaur
Product: set-in
Published: Feb 11, 2026
Source: NVD
CVE-2020-37186 CRITICAL - 9.8

Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system commands through a craft...

Vendor: Chevere SpA
Product: Chevereto
Published: Feb 11, 2026
Source: NVD
CVE-2020-37184 CRITICAL - 9.8

Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite SEH handlers and execute system commands by injecting malicious bytecode into the inpu...

Vendor: Allok Soft
Product: Allok Video Converter
Published: Feb 11, 2026
Source: NVD
CVE-2020-37183 CRITICAL - 9.8

Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload in the License Name input field to trigger a buffer overflow a...

Vendor: Allok Soft
Product: Allok RM RMVB to AVI MPEG DVD Converter
Published: Feb 11, 2026
Source: NVD
CVE-2020-37181 CRITICAL - 9.8

Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structured Exception Handler (SEH) through a malicious registration code input. Attackers can craft a payload with specific offsets and partial SEH overwrite techniques to potentially exec...

Vendor: TorrentRockYou
Product: Torrent FLV Converter
Published: Feb 11, 2026
Source: NVD
CVE-2020-37176 CRITICAL - 9.8

Torrent 3GP Converter 1.51 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the application's registration dialog to trigger code execution and o...

Vendor: Torrentrockyou
Product: Torrent 3GP Converter
Published: Feb 11, 2026
Source: NVD
CVE-2020-37153 CRITICAL - 9.8

ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute arbitrary code with roo...

Vendor: ASTPP
Product: ASTPP
Published: Feb 11, 2026
Source: NVD
CVE-2025-70085 CRITICAL - 9.8

An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Source1Filename and the string returned by FileUtil_FileStateStr) into this buffer without any length checking and without using bounded format specifiers...

Vendor: opensatkit
Product: opensatkit
Published: Feb 11, 2026
Source: NVD
CVE-2025-65128 CRITICAL - 9.1

A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows unauthenticated attackers on the local network to modify router and network configurations. By invoking operations whose names end with "*_nocommit" and supp...

Published: Feb 11, 2026
Source: NVD
CVE-2026-25084 CRITICAL - 9.8

Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.

Vendor: ZLAN Information Technology Co.
Product: ZLAN5143D
Published: Feb 11, 2026
Source: NVD
CVE-2026-24789 CRITICAL - 9.8

An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

Vendor: ZLAN Information Technology Co.
Product: ZLAN5143D
Published: Feb 11, 2026
Source: NVD
CVE-2025-64075 CRITICAL - 10.0

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie value.

Published: Feb 11, 2026
Source: NVD
CVE-2026-2249 CRITICAL - 9.8

METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges. This results in the compro...

Published: Feb 11, 2026
Source: NVD
CVE-2026-2248 CRITICAL - 9.8

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with root (UID 0) privileges. This results in full system comp...

Published: Feb 11, 2026
Source: NVD
CVE-2025-12059 CRITICAL - 9.8

Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Logo j-Platform: from 3.29.6.4 through 13112025.

Vendor: Logo Software Industry and Trade Inc.
Product: Logo j-Platform
Published: Feb 11, 2026
Source: NVD