Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
Showing 2,901 - 2,920 of 3,597 CVEs
CVE-2020-37138 CRITICAL - 9.8

10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious text file with carefully constructed payload to trigger a stack-based buffer overflow and bypass...

Vendor: 10-Strike Software
Product: Network Inventory Explorer
Published: Feb 05, 2026
Source: NVD
CVE-2020-37129 CRITICAL - 9.8

Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file mo...

Vendor: Microvirt
Product: Memu Play
Published: Feb 05, 2026
Source: NVD
CVE-2020-37127 CRITICAL - 9.8

Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause a denial of service by supplying excessive input. Attackers can trigger a core dump and terminate the dhcp_release process by sending a crafted input string longer than 16 charact...

Vendor: dnsmasq
Product: dnsmasq-utils
Published: Feb 05, 2026
Source: NVD
CVE-2020-37126 CRITICAL - 9.8

Free Desktop Clock 3.0 contains a stack overflow vulnerability in the Time Zones display name input that allows attackers to overwrite Structured Exception Handler (SEH) registers. Attackers can exploit the vulnerability by crafting a malicious Unicode input that triggers an access violation and pot...

Vendor: Drive Software Company
Product: Free Desktop Clock
Published: Feb 05, 2026
Source: NVD
CVE-2020-37125 CRITICAL - 9.8

Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection payloads to download and ...

Vendor: EDIMAX Technology
Product: EW-7438RPn Mini
Published: Feb 05, 2026
Source: NVD
CVE-2020-37124 CRITICAL - 9.8

B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) with crafted input. Attackers can leverage an egg hunter technique and carefully constructed payload to inject and execute malicious code during bas...

Vendor: 4Mhz
Product: B64dec
Published: Feb 05, 2026
Source: NVD
CVE-2020-37123 CRITICAL - 9.8

Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Attackers can exploit the unsanitized input in ping.php to write arbitrary PHP files and execute system commands by appending shell metacharacters.

Vendor: wcchandler
Product: Pinger
Published: Feb 05, 2026
Source: NVD
CVE-2020-37121 CRITICAL - 9.8

CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious M3U playlist file with 536 bytes of buffer and shellcode to trigger remote code ex...

Vendor: Code::Blocks
Product: Code::Blocks
Published: Feb 05, 2026
Source: NVD
CVE-2020-37120 CRITICAL - 9.8

Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious text file with carefully constructed payload to execute arbitrary code by overwriting SEH and tri...

Vendor: Rubo Medical Imaging
Product: Rubo DICOM Viewer
Published: Feb 05, 2026
Source: NVD
CVE-2020-37119 CRITICAL - 9.8

Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute shellcode through a carefu...

Vendor: Nsasoft
Product: Nsauditor
Published: Feb 05, 2026
Source: NVD
CVE-2025-68721 CRITICAL - 9.1

Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access control checks and gain unauthorized access to the SSL Certificates management endpoint (page=sslcerts). This allows the at...

Vendor: axigen
Product: axigen_mail_server
Published: Feb 05, 2026
Source: NVD
CVE-2026-25752 CRITICAL - 9.1

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, remote attacker to modify device tags via WebSockets. Exploitation allows an unauthenticated, remote attacker to bypass role-based access controls and ov...

Vendor: npm
Product: fuxa-server
Published: Feb 05, 2026
Source: GitHub
CVE-2026-25895 CRITICAL - 9.8

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This affects FUXA through version 1.2.9. This issue has been patched i...

Vendor: npm
Product: fuxa-server
Published: Feb 05, 2026
Source: GitHub
CVE-2026-25894 CRITICAL - 9.8

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote attacker to gain administrative access and execute arbitrary code on the server. This affects FUXA through version 1.2.9 when authentication is enable...

Vendor: npm
Product: fuxa-server
Published: Feb 05, 2026
Source: GitHub
CVE-2026-25751 CRITICAL - 7.5

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUXA allows an unauthenticated, remote attacker to retrieve sensitive administrative database credentials. Exploitation allows an unauthenticated, remote attacker to obtain the full s...

Vendor: npm
Product: fuxa-server
Published: Feb 05, 2026
Source: GitHub
CVE-2026-25893 CRITICAL - 9.8

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the heartbeat refresh API and execute arbitrary code on the server. This issue has be...

Vendor: npm
Product: fuxa-server
Published: Feb 05, 2026
Source: GitHub
CVE-2026-25539 CRITICAL - 9.1

SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Remote Code Execution (RCE) by writing to sensitive l...

Vendor: siyuan-note
Product: siyuan
Published: Feb 04, 2026
Source: NVD
CVE-2025-13375 CRITICAL - 9.8

IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.

Vendor: IBM
Product: Common Cryptographic Architecture, IBM 4769 Developers Toolkit
Published: Feb 04, 2026
Source: NVD
CVE-2026-25632 CRITICAL - 10.0

EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field....

Vendor: pip
Product: epyt-flow
Published: Feb 04, 2026
Source: GitHub
CVE-2025-62878 CRITICAL - 10.0

A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.

Vendor: go
Product: github.com/rancher/local-path-provisioner
Published: Feb 04, 2026
Source: GitHub