Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,623
Quick preset (or use dates below)
Clear Filters
Showing 2,941 - 2,960 of 3,597 CVEs
CVE-2020-37071 CRITICAL - 9.8

CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard downlo...

Vendor: CraftCMS
Product: CraftCMS
Published: Feb 03, 2026
Source: NVD
CVE-2020-37070 CRITICAL - 9.8

CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attackers can exploit the vulnerability by sending a specially crafted payload to the CloudMe service running on port 8888, enabling remote code execution.

Vendor: CloudMe
Product: CloudMe
Published: Feb 03, 2026
Source: NVD
CVE-2020-37069 CRITICAL - 9.8

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

Vendor: Konica Minolta
Product: FTP Utility
Published: Feb 03, 2026
Source: NVD
CVE-2020-37068 CRITICAL - 9.8

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

Vendor: Konica Minolta
Product: FTP Utility
Published: Feb 03, 2026
Source: NVD
CVE-2020-37067 CRITICAL - 9.8

Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP service.

Vendor: Utillyty
Product: Filetto
Published: Feb 03, 2026
Source: NVD
CVE-2020-37066 CRITICAL - 9.8

GoldWave 5.70 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting malicious input in the File Open URL dialog. Attackers can generate a specially crafted text file with Unicode-encoded shellcode to trigger a stack-based overflow and execute commands w...

Vendor: GoldWave
Product: GoldWave
Published: Feb 03, 2026
Source: NVD
CVE-2020-37065 CRITICAL - 9.8

StreamRipper32 version 2.6 contains a buffer overflow vulnerability in the Station/Song Section that allows attackers to overwrite memory by manipulating the SongPattern input. Attackers can craft a malicious payload exceeding 256 bytes to potentially execute arbitrary code and compromise the applic...

Vendor: StreamRipper
Product: StreamRipper32
Published: Feb 03, 2026
Source: NVD
CVE-2025-10878 CRITICAL - 10.0

A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication completely. Successful exploitation grants full admin...

Vendor: Insaat
Product: Fikir Odalari AdminPando
Published: Feb 03, 2026
Source: NVD
CVE-2026-25241 CRITICAL - 9.8

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows remote attackers to execute arbitrary SQL via a crafted package version. This issue has been patched in versi...

Vendor: pear
Product: pearweb
Published: Feb 03, 2026
Source: NVD
CVE-2026-25240 CRITICAL - 9.8

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are provided as an array and interpolated into an IN (...) clause. This issue has been patched in version 1.33.0.

Vendor: pear
Product: pearweb
Published: Feb 03, 2026
Source: NVD
CVE-2026-25238 CRITICAL - 9.8

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value. This issue has been patched in version 1.33.0.

Vendor: pear
Product: pearweb
Published: Feb 03, 2026
Source: NVD
CVE-2026-25237 CRITICAL - 9.8

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable PHP code execution if attacker-controlled content reaches the evaluated replacement. This issue has been patched in ver...

Vendor: pear
Product: pearweb
Published: Feb 03, 2026
Source: NVD
CVE-2026-25236 CRITICAL - 9.8

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution for an IN (...) list. This issue has been patched in version 1.33.0.

Vendor: pear
Product: pearweb
Published: Feb 03, 2026
Source: NVD
CVE-2026-25234 CRITICAL - 9.8

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with access to the category manager workflow to inject SQL via a category id. This issue has been patched in version 1.33.0.

Vendor: pear
Product: pearweb
Published: Feb 03, 2026
Source: NVD
CVE-2026-25233 CRITICAL - 9.1

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update, or delete roadmaps. This issue has been patched in version 1.33.0.

Vendor: pear
Product: pearweb
Published: Feb 03, 2026
Source: NVD
CVE-2025-70841 CRITICAL - 10.0

Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file. The exposed file contains Laravel application encryption key (APP_KEY), database credentials, SMTP/SendGrid API...

Published: Feb 03, 2026
Source: NVD
CVE-2025-69431 CRITICAL - 9.8

The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slot, and then access the USB drive's directory mounted on the NAS using ...

Published: Feb 03, 2026
Source: NVD
CVE-2025-69430 CRITICAL - 9.8

An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (version equal to or prior to V1.9.12), and DM200 (version equal to or prior to V1.2.23) that could be exploited by attackers to leak or tamper with the int...

Published: Feb 03, 2026
Source: NVD
CVE-2025-67189 CRITICAL - 9.8

A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The urlKeyword parameter is not properly validated, and the function concatenates multiple user-controlled fields into a fixed-size stack buffer without performing boundary checks. A ...

Vendor: totolink
Product: a950rg_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-67188 CRITICAL - 9.8

A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg interface of the /lib/cste_modules/ipv6.so module. The function fails to properly validate the length of the user-controlled radvdinterfacename parameter, allowing remote attackers...

Vendor: totolink
Product: a950rg_firmware
Published: Feb 03, 2026
Source: NVD