Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,513
Quick preset (or use dates below)
Clear Filters
Showing 3,101 - 3,120 of 3,601 CVEs
CVE-2026-21264 CRITICAL - 9.3

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.

Published: Jan 22, 2026
Source: NVD
CVE-2025-54816 CRITICAL - 9.4

This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unauthorized users to establish connections. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that ...

Vendor: EVMAPA
Product: EVMAPA
Published: Jan 22, 2026
Source: NVD
CVE-2025-56590 CRITICAL - 9.8

An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute arbitrary operating system commands on the local server.

Vendor: n/a
Product: n/a
Published: Jan 22, 2026
Source: NVD
CVE-2026-24379 CRITICAL - 9.1

Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.3.

Vendor: wpjobportal
Product: WP Job Portal
Published: Jan 22, 2026
Source: NVD
CVE-2026-24371 CRITICAL - 9.8

Missing Authorization vulnerability in bookingalgorithms BA Book Everything ba-book-everything allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BA Book Everything: from n/a through <= 1.8.16.

Vendor: bookingalgorithms
Product: BA Book Everything
Published: Jan 22, 2026
Source: NVD
CVE-2026-23978 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Softwebmedia Gyan Elements gyan-elements allows PHP Local File Inclusion.This issue affects Gyan Elements: from n/a through <= 2.2.1.

Vendor: Softwebmedia
Product: Gyan Elements
Published: Jan 22, 2026
Source: NVD
CVE-2026-23975 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP Local File Inclusion.This issue affects Golo: from n/a through < 1.7.5.

Vendor: uxper
Product: Golo
Published: Jan 22, 2026
Source: NVD
CVE-2026-22482 CRITICAL - 9.1

Server-Side Request Forgery (SSRF) vulnerability in wbolt.com IMGspider imgspider allows Server Side Request Forgery.This issue affects IMGspider: from n/a through <= 2.3.12.

Vendor: wbolt.com
Product: IMGspider
Published: Jan 22, 2026
Source: NVD
CVE-2025-69828 CRITICAL - 10.0

File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker to execute arbitrary code via the Logo upload in /Customer/AddEdit

Vendor: n/a
Product: n/a
Published: Jan 22, 2026
Source: NVD
CVE-2025-69312 CRITICAL - 9.1

Unrestricted Upload of File with Dangerous Type vulnerability in Xpro Xpro Elementor Addons xpro-elementor-addons allows Upload a Web Shell to a Web Server.This issue affects Xpro Elementor Addons: from n/a through <= 1.4.19.1.

Vendor: Xpro
Product: Xpro Elementor Addons
Published: Jan 22, 2026
Source: NVD
CVE-2025-69101 CRITICAL - 9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows Authentication Abuse.This issue affects Workreap Core: from n/a through <= 3.4.0.

Vendor: AmentoTech
Product: Workreap Core
Published: Jan 22, 2026
Source: NVD
CVE-2025-69079 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue affects Sound | Musical Instruments Online Store: from n/a through <= 1.6.9.

Vendor: ThemeREX
Product: Sound | Musical Instruments Online Store
Published: Jan 22, 2026
Source: NVD
CVE-2025-69078 CRITICAL - 9.8

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Malta malta allows PHP Local File Inclusion.This issue affects Malta: from n/a through <= 1.3.3.

Vendor: AncoraThemes
Product: Malta
Published: Jan 22, 2026
Source: NVD
CVE-2025-69052 CRITICAL - 9.8

Missing Authorization vulnerability in FmeAddons Registration & Login with Mobile Phone Number for WooCommerce registration-login-with-mobile-phone-number allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registration & Login with Mobile Phone Number ...

Vendor: FmeAddons
Product: Registration & Login with Mobile Phone Number for WooCommerce
Published: Jan 22, 2026
Source: NVD
CVE-2025-68986 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Miion miion allows Upload a Web Shell to a Web Server.This issue affects Miion: from n/a through <= 1.2.7.

Vendor: zozothemes
Product: Miion
Published: Jan 22, 2026
Source: NVD
CVE-2025-68910 CRITICAL - 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious Files.This issue affects Blogzee: from n/a through <= 1.0.5.

Vendor: blazethemes
Product: Blogzee
Published: Jan 22, 2026
Source: NVD
CVE-2025-68909 CRITICAL - 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious Files.This issue affects Blogistic: from n/a through <= 1.0.5.

Vendor: blazethemes
Product: Blogistic
Published: Jan 22, 2026
Source: NVD
CVE-2025-68869 CRITICAL - 9.8

Incorrect Privilege Assignment vulnerability in LazyCoders LLC LazyTasks lazytasks-project-task-management allows Privilege Escalation.This issue affects LazyTasks: from n/a through <= 1.4.01.

Vendor: LazyCoders LLC
Product: LazyTasks
Published: Jan 22, 2026
Source: NVD
CVE-2025-68857 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Downloads paid-downloads allows Blind SQL Injection.This issue affects Paid Downloads: from n/a through <= 3.15.

Vendor: ichurakov
Product: Paid Downloads
Published: Jan 22, 2026
Source: NVD
CVE-2025-68034 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® CleverReach® WP cleverreach-wp allows SQL Injection.This issue affects CleverReach® WP: from n/a through <= 1.5.22.

Vendor: CleverReach®
Product: CleverReach® WP
Published: Jan 22, 2026
Source: NVD