Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,667
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,081 - 3,100 of 3,470 CVEs
CVE-2026-0770 CRITICAL - 9.8

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific ...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0769 CRITICAL - 9.8

Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the imple...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0768 CRITICAL - 9.8

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parame...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0764 CRITICAL - 9.8

GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not required to exploit this vulnerability. The specific flaw exists within th...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0763 CRITICAL - 9.8

GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not required to exploit this vulnerability. The specif...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0761 CRITICAL - 9.8

Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this vulnerability. The sp...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0760 CRITICAL - 9.8

Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this vulnerabili...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0759 CRITICAL - 9.8

Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Katana Network Development Starter Kit. Authentication is not required to exploit this vulner...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0756 CRITICAL - 9.8

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of github-kanban-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exist...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0755 CRITICAL - 9.8

gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of gemini-mcp-tool. Authentication is not required to exploit this vulnerability. The specific flaw exists within the imple...

Vendor: npm
Product: gemini-mcp-tool
Published: Jan 23, 2026
Source: NVD
CVE-2025-15063 CRITICAL - 9.8

Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ollama MCP Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the i...

Vendor: Ollama MCP Server
Product: Ollama MCP Server
Published: Jan 23, 2026
Source: NVD
CVE-2025-15061 CRITICAL - 9.8

Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Framelink Figma MCP Server. Authentication is not required to exploit this vulnerability. The specific f...

Vendor: Framelink
Product: Figma MCP Server
Published: Jan 23, 2026
Source: NVD
CVE-2026-24304 CRITICAL - 9.9

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

Published: Jan 23, 2026
Source: NVD
CVE-2026-24307 CRITICAL - 9.3

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Published: Jan 22, 2026
Source: NVD
CVE-2026-24306 CRITICAL - 9.8

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

Published: Jan 22, 2026
Source: NVD
CVE-2026-24305 CRITICAL - 9.3

Azure Entra ID Elevation of Privilege Vulnerability

Published: Jan 22, 2026
Source: NVD
CVE-2026-21264 CRITICAL - 9.3

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.

Published: Jan 22, 2026
Source: NVD
CVE-2025-54816 CRITICAL - 9.4

This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish connections. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that ...

Vendor: EVMAPA
Product: EVMAPA
Published: Jan 22, 2026
Source: NVD
CVE-2025-56590 CRITICAL - 9.8

An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute arbitrary operating system commands on the local server.

Vendor: n/a
Product: n/a
Published: Jan 22, 2026
Source: NVD
CVE-2026-24379 CRITICAL - 9.1

Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.3.

Vendor: wpjobportal
Product: WP Job Portal
Published: Jan 22, 2026
Source: NVD