Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,535
Quick preset (or use dates below)
Clear Filters
Showing 3,021 - 3,040 of 3,601 CVEs
CVE-2020-36967 CRITICAL - 9.8

Zortam Mp3 Media Studio 27.60 contains a buffer overflow vulnerability in the library creation file selection process that allows remote code execution. Attackers can craft a malicious text file with shellcode to trigger a structured exception handler (SEH) overwrite and execute arbitrary commands o...

Vendor: Zortam.com
Product: Zortam Mp3 Media Studio
Published: Jan 28, 2026
Source: NVD
CVE-2020-36964 CRITICAL - 9.8

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing space. Attackers can exploit the service by connecting and sending a malformed command that triggers a buffer overflow and service crash.

Vendor: ik80
Product: YATinyWinFTP
Published: Jan 28, 2026
Source: NVD
CVE-2020-36962 CRITICAL - 9.8

Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary comma...

Vendor: Tendenci
Product: Tendenci
Published: Jan 28, 2026
Source: NVD
CVE-2020-36961 CRITICAL - 9.8

10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbitrary code. Attackers can craft a malicious file with 209 bytes of padding and a specially constructed Structured Exception Handler to trigger code exe...

Vendor: 10-Strike Software
Product: Network Inventory Explorer
Published: Jan 28, 2026
Source: NVD
CVE-2025-69517 CRITICAL - 9.8

An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject arbitrary HTML content during the creation of a new agent via the POST /api/v3/newagent/ endpoint. The agent_id parameter accepts up to 255 characters and is improperly sanitized usi...

Published: Jan 28, 2026
Source: NVD
CVE-2025-61140 CRITICAL - 9.8

JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js

Vendor: npm
Product: jsonpath
Published: Jan 28, 2026
Source: NVD
CVE-2026-1056 CRITICAL - 9.8

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files ...

Published: Jan 28, 2026
Source: NVD
CVE-2025-40554 CRITICAL - 9.8

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

Vendor: SolarWinds
Product: Web Help Desk
Published: Jan 28, 2026
Source: NVD
CVE-2025-40553 CRITICAL - 9.8

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

Vendor: SolarWinds
Product: Web Help Desk
Published: Jan 28, 2026
Source: NVD
CVE-2025-40552 CRITICAL - 9.8

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.

Vendor: SolarWinds
Product: Web Help Desk
Published: Jan 28, 2026
Source: NVD
CVE-2025-40551 CRITICAL - 9.8

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

Vendor: SolarWinds
Product: Web Help Desk
Published: Jan 28, 2026
Source: NVD
CVE-2026-24841 CRITICAL - 9.9

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokploy's WebSocket endpoint `/docker-container-terminal`. The `containerId` and `activeWay` parameters are directly interpolated into shell commands ...

Vendor: Dokploy
Product: dokploy
Published: Jan 28, 2026
Source: NVD
CVE-2026-24838 CRITICAL - 9.1

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0 contain a fix for the i...

Vendor: dnnsoftware
Product: Dnn.Platform
Published: Jan 28, 2026
Source: NVD
CVE-2026-24770 CRITICAL - 9.8

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allowing an attacker to overwrite arbitrary files on the server (leading to Remote Code Execution) via a malicious ...

Vendor: infiniflow
Product: ragflow
Published: Jan 27, 2026
Source: NVD
CVE-2026-24736 CRITICAL - 9.1

Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The url parameter in the webhook configuration does not appear to validate or...

Vendor: Squidex
Product: squidex
Published: Jan 27, 2026
Source: NVD
CVE-2025-21589 CRITICAL - 9.8

An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device. This issue affects Session Smart Router:ย  * from 5.6.7 before 5.6.17,ย ...

Vendor: Juniper Networks
Product: Session Smart Router, Session Smart Conductor, WAN Assurance Managed Router
Published: Jan 27, 2026
Source: NVD
CVE-2026-24858 CRITICAL - 9.8

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7...

Vendor: Fortinet
Product: FortiAnalyzer, FortiOS, FortiManager
Published: Jan 27, 2026
Source: NVD
CVE-2026-23830 CRITICAL - 10.0

SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. The library attempts to sandbox code execution by replacing the global `Function` constructor with a safe, sandboxed version (`Sa...

Vendor: npm
Product: @nyariv/sandboxjs
Published: Jan 27, 2026
Source: GitHub
CVE-2026-22039 CRITICAL - 9.9

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall. The resolved `urlPath` is executed using the Kyverno admission controller ServiceAccount, with no e...

Vendor: kyverno
Product: kyverno
Published: Jan 27, 2026
Source: NVD
CVE-2025-69564 CRITICAL - 9.8

code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password, confirm_password, Role, Branch, and Activate parameters.

Vendor: fabian
Product: mobile_shop_management_system
Published: Jan 27, 2026
Source: NVD