Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,531
Quick preset (or use dates below)
Clear Filters
Showing 3,081 - 3,100 of 3,601 CVEs
CVE-2025-4319 CRITICAL - 9.4

Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Brute Force, Password Recovery Exploitation.This issue affects Sufirmam: through 23012026.Β NOTE: The vendo...

Published: Jan 23, 2026
Source: NVD
CVE-2026-1364 CRITICAL - 9.8

IAQS and I6 developed by JNC has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly operate system administrative functionalities.

Published: Jan 23, 2026
Source: NVD
CVE-2026-1363 CRITICAL - 9.8

IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticated remote attackers to gain administrator privileges by manipulating the web front-end.

Published: Jan 23, 2026
Source: NVD
CVE-2026-0773 CRITICAL - 9.8

Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Upsonic. Authentication is not required to exploit this vulnerability. The specific flaw exists within the add...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0770 CRITICAL - 9.8

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific ...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0769 CRITICAL - 9.8

Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the imple...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0768 CRITICAL - 9.8

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parame...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0764 CRITICAL - 9.8

GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not required to exploit this vulnerability. The specific flaw exists within th...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0763 CRITICAL - 9.8

GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not required to exploit this vulnerability. The specif...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0761 CRITICAL - 9.8

Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this vulnerability. The sp...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0760 CRITICAL - 9.8

Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this vulnerabili...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0759 CRITICAL - 9.8

Katana Network Development Starter Kit executeCommand Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Katana Network Development Starter Kit. Authentication is not required to exploit this vulner...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0756 CRITICAL - 9.8

github-kanban-mcp-server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of github-kanban-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exist...

Published: Jan 23, 2026
Source: NVD
CVE-2026-0755 CRITICAL - 9.8

gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of gemini-mcp-tool. Authentication is not required to exploit this vulnerability. The specific flaw exists within the imple...

Vendor: npm
Product: gemini-mcp-tool
Published: Jan 23, 2026
Source: NVD
CVE-2025-15063 CRITICAL - 9.8

Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ollama MCP Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the i...

Vendor: Ollama MCP Server
Product: Ollama MCP Server
Published: Jan 23, 2026
Source: NVD
CVE-2025-15061 CRITICAL - 9.8

Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Framelink Figma MCP Server. Authentication is not required to exploit this vulnerability. The specific f...

Vendor: Framelink
Product: Figma MCP Server
Published: Jan 23, 2026
Source: NVD
CVE-2026-24304 CRITICAL - 9.9

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

Published: Jan 23, 2026
Source: NVD
CVE-2026-24307 CRITICAL - 9.3

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Published: Jan 22, 2026
Source: NVD
CVE-2026-24306 CRITICAL - 9.8

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

Published: Jan 22, 2026
Source: NVD
CVE-2026-24305 CRITICAL - 9.3

Azure Entra ID Elevation of Privilege Vulnerability

Published: Jan 22, 2026
Source: NVD