Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,725
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,981 - 3,000 of 3,470 CVEs
CVE-2022-50981 CRITICAL - 9.8

An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.

Published: Feb 02, 2026
Source: NVD
CVE-2026-24071 CRITICAL - 9.3

It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks.Β The connection handler function uses _xpc_connection_get_pid(arg2) as argume...

Vendor: Native Instruments
Product: Native Access
Published: Feb 02, 2026
Source: NVD
CVE-2024-5986 CRITICAL - 9.1

A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploiting the `/3/Parse` endpoint to inject attacker-controlled data as the header of an empty file, which is then exported using the `/3/Frames/framename/e...

Vendor: maven
Product: ai.h2o:h2o-core
Published: Feb 02, 2026
Source: NVD
CVE-2024-5386 CRITICAL - 9.6

In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can exploit this vulnerability to hijack another user's account by obtaining the password reset token. The vulnerability is triggered when the &...

Published: Feb 02, 2026
Source: NVD
CVE-2024-2356 CRITICAL - 9.6

A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within the `name` parameter of the `@router.post("/reinstall_extension")` route. This vulnerability allows attackers to inject a malicio...

Published: Feb 02, 2026
Source: NVD
CVE-2025-15030 CRITICAL - 9.8

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

Vendor: Unknown
Product: User Profile Builder
Published: Feb 02, 2026
Source: NVD
CVE-2026-25202 CRITICAL - 9.8

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.

Vendor: Samsung Electronics
Product: MagicINFO 9 Server
Published: Feb 02, 2026
Source: NVD
CVE-2026-25200 CRITICAL - 9.8

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1.

Vendor: Samsung Electronics
Product: MagicINFO 9 Server
Published: Feb 02, 2026
Source: NVD
CVE-2020-37056 CRITICAL - 9.8

Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and ga...

Vendor: Crystal Shard
Product: http-protection
Published: Jan 30, 2026
Source: NVD
CVE-2020-37052 CRITICAL - 9.8

AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded J...

Vendor: Ubiquiti, Inc.
Product: AirControl
Published: Jan 30, 2026
Source: NVD
CVE-2020-37050 CRITICAL - 9.8

Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with carefully constructed payload. Attackers can trigger the vulnerability by loading a specially crafted file through the application's file loading mech...

Vendor: M.J.M Soft
Product: Quick Player
Published: Jan 30, 2026
Source: NVD
CVE-2020-37043 CRITICAL - 9.8

10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR, and DEP protections through carefully crafted input. Attackers can exploit the vulnerability by sending a malicious payload to the application's registration key input, enabli...

Vendor: 10-Strike Software
Product: Bandwidth Monitor
Published: Jan 30, 2026
Source: NVD
CVE-2020-37027 CRITICAL - 9.8

Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the extra scripts configuration. Attackers can set malicious commands in the extra scripts field and trigger processing to execute remote code on the vulnerab...

Vendor: midgetspy
Product: Sickbeard
Published: Jan 30, 2026
Source: NVD
CVE-2019-25232 CRITICAL - 9.8

NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary shellcode. Attackers can craft a malicious payload in the DNS/IP input to overwrite SEH handlers and execute shellcode when adding a new client.

Vendor: NetPCLinker
Product: NetPCLinker
Published: Jan 30, 2026
Source: NVD

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7.21.0 and 8.2.0 have an incomplete fix for CVE-2026-23947. While the jsStringEscape function properly handles single quotes ('), double quotes (&q...

Vendor: orval-labs
Product: orval
Published: Jan 30, 2026
Source: NVD
CVE-2026-25130 CRITICAL - 9.6

Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple argument injection vulnerabilities in its function tools. User-controlled input is passed directly to shell commands via `subprocess.Popen()` with `sh...

Vendor: aliasrobotics
Product: cai
Published: Jan 30, 2026
Source: NVD
CVE-2025-51958 CRITICAL - 9.8

aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system commands via lib/plugins/runcommand/postaction.php.

Published: Jan 30, 2026
Source: NVD
CVE-2026-1699 CRITICAL - 10.0

In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access...

Published: Jan 30, 2026
Source: NVD
CVE-2026-0963 CRITICAL - 9.9

An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.

Published: Jan 30, 2026
Source: NVD

deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.

Vendor: sharpred
Product: deepHas
Published: Jan 29, 2026
Source: NVD