Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
Showing 2,861 - 2,880 of 3,597 CVEs
CVE-2026-25057 CRITICAL - 9.1

MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able to upload a zip file to create an assignment from an exported configuration (courses/<:course_id>/assignments/upload_config_files). The uploaded zip file entry names are used...

Vendor: MarkUsProject
Product: Markus
Published: Feb 09, 2026
Source: NVD
CVE-2026-24679 CRITICAL - 9.1

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array indices without bounds checks, causing an out-of-bounds read in libusb_udev_select_interface. This vulnerability is fixed in 3.22.0.

Vendor: FreeRDP
Product: FreeRDP
Published: Feb 09, 2026
Source: NVD
CVE-2026-24677 CRITICAL - 9.1

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts server-controlled dimensions and does not validate the source buffer size, leading to an out-of-bounds read in sws_scale. This vulnerability is fixed in 3.22.0.

Vendor: FreeRDP
Product: FreeRDP
Published: Feb 09, 2026
Source: NVD

Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can return an error if secure randomness cannot be obtained. Because no error is returned by the Fiber v2 UUID functions, application code may unknowingly...

Vendor: go
Product: github.com/gofiber/fiber/v2
Published: Feb 09, 2026
Source: GitHub
CVE-2025-6830 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Password Module allows SQL Injection.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way. This issue affe...

Published: Feb 09, 2026
Source: NVD
CVE-2026-25848 CRITICAL - 9.1

In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

Vendor: JetBrains
Product: Hub
Published: Feb 09, 2026
Source: NVD
CVE-2026-2234 CRITICAL - 9.1

C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail content.

Published: Feb 09, 2026
Source: NVD
CVE-2026-22906 CRITICAL - 9.8

User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can decrypt and recover plaintext usernames and passwords, especially when combined with the authentication bypass.

Vendor: WAGO
Product: 0852-1322, 0852-1328
Published: Feb 09, 2026
Source: NVD
CVE-2026-22904 CRITICAL - 9.8

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.

Vendor: WAGO
Product: 0852-1322, 0852-1328
Published: Feb 09, 2026
Source: NVD
CVE-2026-22903 CRITICAL - 9.8

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.

Vendor: WAGO
Product: 0852-1322, 0852-1328
Published: Feb 09, 2026
Source: NVD
CVE-2026-1868 CRITICAL - 9.9

GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted Duo ...

Published: Feb 09, 2026
Source: NVD
CVE-2026-1615 CRITICAL - 9.8

All versions of the package jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this v...

Vendor: npm
Product: jsonpath
Published: Feb 09, 2026
Source: NVD
CVE-2025-15027 CRITICAL - 9.8

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_login_register_ajax_create_final_user' function. This makes it poss...

Vendor: jayarsiech
Product: JAY Login & Register
Published: Feb 08, 2026
Source: NVD
CVE-2026-25560 CRITICAL - 9.8

WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.

Vendor: WeKan
Product: WeKan
Published: Feb 07, 2026
Source: NVD
CVE-2020-37162 CRITICAL - 9.8

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration key input that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload of 1608 bytes to trigger a stack-based buffer overflow and execute commands through the ...

Vendor: Wedding Slideshow Studio
Product: Wedding Slideshow Studio
Published: Feb 07, 2026
Source: NVD
CVE-2020-37161 CRITICAL - 9.8

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the registration name field with malicious payload. Attackers can craft a specially designed payload to trigger remote code execution, demonstrating the ability to ru...

Vendor: Wedding Slideshow Studio
Product: Wedding Slideshow Studio
Published: Feb 07, 2026
Source: NVD
CVE-2020-37159 CRITICAL - 9.8

Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory registers in the alarm scheduling feature. Attackers can craft a malicious payload exceeding 260 bytes to overwrite EIP and EBP, enabling shellcode execution wit...

Vendor: Parallaxis
Product: Cuckoo Clock
Published: Feb 07, 2026
Source: NVD
CVE-2020-37095 CRITICAL - 9.8

Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) memory. Attackers can craft a malicious input in the 'Cyberoam Server Address' field to trigger a bind TC...

Vendor: Cyberoam
Product: Cyberoam Authentication Client
Published: Feb 07, 2026
Source: NVD
CVE-2026-25803 CRITICAL - 9.8

3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known default credentials (admin/admin) upon the first initialization. Attackers with network access to the application's login interface can gain full...

Vendor: denpiligrim
Product: 3dp-manager
Published: Feb 06, 2026
Source: NVD
CVE-2026-25763 CRITICAL - 9.9

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exists in OpenProject’s repository changes endpoint (/projects/:project_id/repository/changes) when rendering the “latest changes” view via git log. By sup...

Vendor: opf
Product: openproject
Published: Feb 06, 2026
Source: NVD