Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,528
Quick preset (or use dates below)
Clear Filters
Showing 3,061 - 3,080 of 3,601 CVEs
CVE-2025-70982 CRITICAL - 9.9

Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.

Published: Jan 26, 2026
Source: NVD
CVE-2016-15057 CRITICAL - 9.9

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum. This issue affects Apache Continuum: all versions. Attackers with access to the installations REST API can use this to invoke arbitrary c...

Vendor: Apache Software Foundation
Product: Apache Continuum
Published: Jan 26, 2026
Source: NVD
CVE-2025-13374 CRITICAL - 9.8

The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site&...

Vendor: irisideatechsolutions
Product: Kalrav AI Agent
Published: Jan 24, 2026
Source: NVD
CVE-2025-13952 CRITICAL - 9.8

A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device....

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jan 24, 2026
Source: NVD
CVE-2026-24399 CRITICAL - 9.3

ChatterMate is a no-code AI chatbot agent framework. In versions 1.0.8 and below, the chatbot accepts and executes malicious HTML/JavaScript payloads when supplied as chat input. Specifically, an <iframe> payload containing a javascript: URI can be processed and executed in the browser context...

Vendor: chattermate
Product: chattermate.chat
Published: Jan 24, 2026
Source: NVD
CVE-2026-22586 CRITICAL - 9.8

Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 2...

Vendor: Salesforce
Product: Marketing Cloud Engagement
Published: Jan 24, 2026
Source: NVD
CVE-2026-22585 CRITICAL - 9.8

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engageme...

Vendor: Salesforce
Product: Marketing Cloud Engagement
Published: Jan 24, 2026
Source: NVD
CVE-2026-22583 CRITICAL - 9.8

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.

Vendor: Salesforce
Product: Marketing Cloud Engagement
Published: Jan 24, 2026
Source: NVD
CVE-2026-22582 CRITICAL - 9.8

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.

Vendor: Salesforce
Product: Marketing Cloud Engagement
Published: Jan 24, 2026
Source: NVD
CVE-2025-70457 CRITICAL - 9.8

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save proc...

Vendor: n/a
Product: n/a
Published: Jan 23, 2026
Source: NVD
CVE-2025-52025 CRITICAL - 9.4

An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulnerability arises because user input is directly inserted into a dynamic SQL query syntax without proper sanitization or parameterization. This allows an ...

Vendor: n/a
Product: n/a
Published: Jan 23, 2026
Source: NVD
CVE-2025-52024 CRITICAL - 9.4

A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated users. By accessing specific URLs, an attacker is presented with a directory-style index listing all available backend services and POS web services, eac...

Vendor: n/a
Product: n/a
Published: Jan 23, 2026
Source: NVD
CVE-2025-70985 CRITICAL - 9.1

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

Vendor: n/a
Product: n/a
Published: Jan 23, 2026
Source: NVD
CVE-2025-70983 CRITICAL - 9.9

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

Vendor: n/a
Product: n/a
Published: Jan 23, 2026
Source: NVD
CVE-2025-67229 CRITICAL - 9.8

An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker to spoof backend responses by exploiting insufficient certificate validation.

Vendor: n/a
Product: n/a
Published: Jan 23, 2026
Source: NVD
CVE-2022-25369 CRITICAL - 9.8

An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new admin user they have adde...

Vendor: n/a
Product: n/a
Published: Jan 23, 2026
Source: NVD
CVE-2021-47891 CRITICAL - 9.8

Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary commands. Attackers can exploit the service by connecting to port 9512 and sending specially crafted packets to open a command prompt and download and e...

Vendor: Unified Intents AB
Product: Unified Remote
Published: Jan 23, 2026
Source: NVD
CVE-2025-66719 CRITICAL - 9.1

An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the attacker uses a crafted targetNF value. This allows attackers to obtain an access ...

Vendor: n/a
Product: n/a
Published: Jan 23, 2026
Source: NVD
CVE-2026-24531 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Prowess prowess allows PHP Local File Inclusion.This issue affects Prowess: from n/a through <= 2.3.

Vendor: Select-Themes
Product: Prowess
Published: Jan 23, 2026
Source: NVD
CVE-2025-4320 CRITICAL - 10.0

Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026.Β NOTE: The vendor was ...

Published: Jan 23, 2026
Source: NVD