Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,725
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 2,961 - 2,980 of 3,470 CVEs
CVE-2025-67187 CRITICAL - 9.8

A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists in the setIpQosRules interface of /lib/cste_modules/firewall.so where the comment parameter is not properly validated for length.

Vendor: totolink
Product: a950rg_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-67186 CRITICAL - 9.8

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /lib/cste_modules/firewall.so. The vulnerability occurs because the `url` parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, pot...

Vendor: totolink
Product: a950rg_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-63624 CRITICAL - 9.8

SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows a remote attacker to execute arbitrary code via the imei_list.aspx file.

Published: Feb 03, 2026
Source: NVD
CVE-2025-61506 CRITICAL - 9.8

An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint.

Published: Feb 03, 2026
Source: NVD
CVE-2025-57529 CRITICAL - 9.8

YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validation. This allows remote unauthenticated attackers to execute arbitrary SQL commands via crafted input to the parameter. Successful exploitation could ...

Published: Feb 03, 2026
Source: NVD
CVE-2025-46651 CRITICAL - 9.1

Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain n...

Published: Feb 03, 2026
Source: NVD
CVE-2026-25526 CRITICAL - 9.8

JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-i...

Vendor: maven
Product: com.hubspot.jinjava:jinjava
Published: Feb 03, 2026
Source: GitHub
CVE-2025-64712 CRITICAL - 9.8

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write or overwrite arbitrary...

Vendor: pip
Product: unstructured
Published: Feb 03, 2026
Source: GitHub
CVE-2026-1568 CRITICAL - 9.6

Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Console" installations, resulting in full account takeove...

Published: Feb 03, 2026
Source: NVD
CVE-2025-5319 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Management System allows SQL Injection.This issue affects DIGITA Efficiency Management System:...

Published: Feb 03, 2026
Source: NVD
CVE-2026-24465 CRITICAL - 9.8

Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code execution.

Vendor: ELECOM CO.,LTD.
Product: WAB-S733IW2-PD, WAB-S733IW-AC, WAB-S733IW-PD, WAB-S300IW2-PD, WAB-S300IW-AC, WAB-S300IW-PD
Published: Feb 03, 2026
Source: NVD
CVE-2026-25142 CRITICAL - 10.0

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can be used for escaping the sandbox / remote code execution. This vulnerability is fixed in 0.8.27.

Vendor: nyariv
Product: SandboxJS
Published: Feb 02, 2026
Source: NVD
CVE-2026-25137 CRITICAL - 9.1

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the database manager without any authentication. This allows unauthorized actors to delete and download the entire database, including Odoos file store. Un...

Vendor: NixOS
Product: nixpkgs
Published: Feb 02, 2026
Source: NVD
CVE-2025-66480 CRITICAL - 9.8

Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.xiaoleilu.loServer.action.UploadFileAction. The application exposes an endpoint (/fs) that handles ...

Vendor: wildfirechat
Product: im-server
Published: Feb 02, 2026
Source: NVD

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to before 2.0.39, a prototype pollution vulnerability exists in locutus. Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input containe...

Vendor: npm
Product: locutus
Published: Feb 02, 2026
Source: GitHub
CVE-2026-25510 CRITICAL - 10.0

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated user with file editor permissions can achieve Remote Code Execution (RCE) by leveraging the file creation and save...

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: Feb 02, 2026
Source: GitHub
CVE-2026-25505 CRITICAL - 9.8

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.

Vendor: pip
Product: bambuddy
Published: Feb 02, 2026
Source: GitHub

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-46724. TableChatAgent can call pandas_eval tool to evaluate the expression. There is a WAF in langroid/utils/pandas_utils.py introduced to block code in...

Vendor: pip
Product: langroid
Published: Feb 02, 2026
Source: GitHub
CVE-2026-23515 CRITICAL - 10.0

Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated use...

Vendor: npm
Product: @signalk/set-system-time
Published: Feb 02, 2026
Source: GitHub
CVE-2026-22778 CRITICAL - 9.8

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion g...

Vendor: pip
Product: vllm
Published: Feb 02, 2026
Source: GitHub