Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,141 - 3,160 of 3,470 CVEs
CVE-2026-1331 CRITICAL - 9.8

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Published: Jan 22, 2026
Source: NVD
CVE-2026-0920 CRITICAL - 9.8

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.6.3. This is due to the 'ajax_register_handle' function not restricting what user roles a user can register with. This makes it possible for ...

Published: Jan 22, 2026
Source: NVD
CVE-2026-24042 CRITICAL - 9.4

Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthenticated users to execute unpublished (edit-mode) actions by sending viewMode=false (or omitting it) to POST /api/v1/actions/execute. This bypasses the expe...

Vendor: appsmithorg
Product: appsmith
Published: Jan 22, 2026
Source: NVD
CVE-2026-24002 CRITICAL - 9.0

Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases where the user may be working with untrusted spreadsheets. One such method runs them in pyodide, but pyodide on node does not have a useful sandbox barr...

Vendor: gristlabs
Product: grist-core
Published: Jan 22, 2026
Source: NVD
CVE-2026-22793 CRITICAL - 9.6

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer...

Vendor: nanbingxyz
Product: 5ire
Published: Jan 21, 2026
Source: NVD
CVE-2026-22792 CRITICAL - 9.6

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe HTML rendering permits untrusted HTML (including on* event attributes) to execute in the renderer context. An attacker can inject an `<img onerror=...>` payl...

Vendor: nanbingxyz
Product: 5ire
Published: Jan 21, 2026
Source: NVD
CVE-2025-69766 CRITICAL - 9.8

Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.

Vendor: n/a
Product: n/a
Published: Jan 21, 2026
Source: NVD
CVE-2025-69763 CRITICAL - 9.8

Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution.

Vendor: n/a
Product: n/a
Published: Jan 21, 2026
Source: NVD
CVE-2025-69762 CRITICAL - 9.8

Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote code execution.

Vendor: n/a
Product: n/a
Published: Jan 21, 2026
Source: NVD
CVE-2021-47875 CRITICAL - 9.8

GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a payload with 8000 repeated characters and paste it into the calculator's input field to trigger an applicatio...

Vendor: GeoGebra
Product: CAS Calculator
Published: Jan 21, 2026
Source: NVD
CVE-2021-47854 CRITICAL - 9.8

DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execute arbitrary code. Attackers can send crafted M-SEARCH packets with oversized UUID payloads to trigger buffer overflow conditions on the target device.

Vendor: embeDD GmbH
Product: DD-WRT
Published: Jan 21, 2026
Source: NVD
CVE-2021-47851 CRITICAL - 9.8

Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP endpoint. Attackers can leverage the /op=command endpoint to download and execute payloads by sending crafted JSON requests with malicious script comman...

Vendor: Yodinfo
Product: Mini Mouse
Published: Jan 21, 2026
Source: NVD
CVE-2021-47748 CRITICAL - 9.8

Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manipulation. Attackers can inject commands into the run_sql endpoint by crafting malicious GraphQL queries that execute system commands through PostgreSQL&...

Vendor: Hasura
Product: GraphQL
Published: Jan 21, 2026
Source: NVD
CVE-2026-20045 CRITICAL - 9.8

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unity Connection, and Cisco Webex Calling Dedica...

Vendor: cisco
Product: unified_communications_manager
Published: Jan 21, 2026
Source: NVD
CVE-2026-23966 CRITICAL - 9.1

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto prior to version 0.3.14. By interacting with the SM2 decryption interface multiple times, an attacker can full...

Vendor: npm
Product: sm-crypto
Published: Jan 21, 2026
Source: GitHub
CVE-2026-23524 CRITICAL - 9.8

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the Redis channel directly into PHPโ€™s unserialize() function without restricting which classes can be instantiated, which leaves users vulnerable to Remo...

Vendor: composer
Product: laravel/reverb
Published: Jan 21, 2026
Source: GitHub
CVE-2026-24061 CRITICAL - 9.8

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Vendor: GNU
Product: Inetutils
Published: Jan 21, 2026
Source: NVD
CVE-2025-15521 CRITICAL - 9.8

The Academy LMS โ€“ WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a user's identity prior to updating their passwor...

Vendor: kodezen
Product: Academy LMS โ€“ WordPress LMS Plugin for Complete eLearning Solution
Published: Jan 21, 2026
Source: NVD

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vulnerable to arbitrary code execution in environments consuming generated clients. This issue is similar in nature to CVE-2026-22785, but affects a diffe...

Vendor: npm
Product: @orval/core
Published: Jan 21, 2026
Source: GitHub
CVE-2026-21969 CRITICAL - 9.8

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracl...

Published: Jan 20, 2026
Source: NVD