Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,725
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,001 - 3,020 of 3,470 CVEs
CVE-2026-1340 CRITICAL - 9.8

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Published: Jan 29, 2026
Source: NVD
CVE-2026-1281 CRITICAL - 9.8

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Vendor: ivanti
Product: endpoint_manager_mobile
Published: Jan 29, 2026
Source: NVD
CVE-2026-22806 CRITICAL - 9.1

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10, when an access key is created with a limited scope, the scope can be bypassed to access resources outside of it. However, the user st...

Vendor: loft-sh
Product: loft
Published: Jan 29, 2026
Source: NVD
CVE-2025-69929 CRITICAL - 9.8

An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the password hashing on the client side using the MD5 algorithm over a predictable string format

Published: Jan 29, 2026
Source: NVD
CVE-2026-1453 CRITICAL - 9.8

A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete administrator accounts. This vulnerability can grant the attacker full administrative control over the product.

Published: Jan 29, 2026
Source: NVD
CVE-2020-37012 CRITICAL - 9.8

Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /api.php endpoint. Attackers can craft a malicious LaTeX payload with shell commands that are executed when processed by the application's tex2png A...

Vendor: ammarfaizi2
Product: Tea LaTex
Published: Jan 29, 2026
Source: NVD
CVE-2020-37010 CRITICAL - 9.8

BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite the EIP register and execute shellcode by pasting malicious content into the search keywo...

Vendor: BearshareOfficial
Product: BearShare Lite
Published: Jan 29, 2026
Source: NVD
CVE-2020-37002 CRITICAL - 9.8

Ajenti 2.1.36 contains an authentication bypass vulnerability that allows remote attackers to execute arbitrary commands after successful login. Attackers can leverage the /api/terminal/create endpoint to send a netcat reverse shell payload targeting a specified IP and port.

Vendor: Ajenti Project
Product: Ajenti
Published: Jan 29, 2026
Source: NVD
CVE-2020-37000 CRITICAL - 9.8

Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting a malicious WAV file with oversized payload. Attackers can leverage a specially crafted exploit file with shellcode, SEH bypass, and egghunter technique to achieve...

Vendor: Cleanersoft Software
Product: Free MP3 CD Ripper
Published: Jan 29, 2026
Source: NVD
CVE-2020-36997 CRITICAL - 9.8

BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Handler (SEH) chain through malicious file import. Attackers can craft a specially designed payload file to overwrite SEH addresses, potentially executing arbitrary code and gaining c...

Vendor: Dummysoftware
Product: BacklinkSpeed
Published: Jan 29, 2026
Source: NVD

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.44, AutoGPT Platform's block execution endpoints (both main web API and external API) allow executing blocks by UU...

Vendor: pip
Product: agpt
Published: Jan 29, 2026
Source: GitHub
CVE-2026-24897 CRITICAL - 10.0

Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified location due to insufficient validation of userโ€‘supplied paths when creating shares. By specifying a writable path within the public ...

Vendor: ErugoOSS
Product: Erugo
Published: Jan 28, 2026
Source: NVD
CVE-2025-69602 CRITICAL - 9.1

A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing an attacker who can ...

Published: Jan 28, 2026
Source: NVD
CVE-2025-57795 CRITICAL - 9.9

Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configurations, this flaw can be leveraged to achieve remote code execution.

Vendor: Explorance
Product: Blue
Published: Jan 28, 2026
Source: NVD
CVE-2025-57794 CRITICAL - 9.1

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restrict uploaded file types, allowing malicious files to be uploaded and executed by the server. This condition enables remot...

Vendor: Explorance
Product: Blue
Published: Jan 28, 2026
Source: NVD
CVE-2025-57792 CRITICAL - 10.0

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application endpoint. An attacker can supply crafted input that is executed as part of backend database queries. The issue is exploitable without authentication, si...

Vendor: Explorance
Product: Blue
Published: Jan 28, 2026
Source: NVD
CVE-2020-36967 CRITICAL - 9.8

Zortam Mp3 Media Studio 27.60 contains a buffer overflow vulnerability in the library creation file selection process that allows remote code execution. Attackers can craft a malicious text file with shellcode to trigger a structured exception handler (SEH) overwrite and execute arbitrary commands o...

Vendor: Zortam.com
Product: Zortam Mp3 Media Studio
Published: Jan 28, 2026
Source: NVD
CVE-2020-36964 CRITICAL - 9.8

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing space. Attackers can exploit the service by connecting and sending a malformed command that triggers a buffer overflow and service crash.

Vendor: ik80
Product: YATinyWinFTP
Published: Jan 28, 2026
Source: NVD
CVE-2020-36962 CRITICAL - 9.8

Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary comma...

Vendor: Tendenci
Product: Tendenci
Published: Jan 28, 2026
Source: NVD
CVE-2020-36961 CRITICAL - 9.8

10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbitrary code. Attackers can craft a malicious file with 209 bytes of padding and a specially constructed Structured Exception Handler to trigger code exe...

Vendor: 10-Strike Software
Product: Network Inventory Explorer
Published: Jan 28, 2026
Source: NVD