Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
Showing 3,161 - 3,180 of 3,601 CVEs
CVE-2026-24061 CRITICAL - 9.8

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Vendor: GNU
Product: Inetutils
Published: Jan 21, 2026
Source: NVD
CVE-2025-15521 CRITICAL - 9.8

The Academy LMS โ€“ WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.5.0. This is due to the plugin not properly validating a user's identity prior to updating their passwor...

Vendor: kodezen
Product: Academy LMS โ€“ WordPress LMS Plugin for Complete eLearning Solution
Published: Jan 21, 2026
Source: NVD

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vulnerable to arbitrary code execution in environments consuming generated clients. This issue is similar in nature to CVE-2026-22785, but affects a diffe...

Vendor: npm
Product: @orval/core
Published: Jan 21, 2026
Source: GitHub
CVE-2026-21969 CRITICAL - 9.8

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracl...

Published: Jan 20, 2026
Source: NVD
CVE-2026-21962 CRITICAL - 10.0

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0...

Published: Jan 20, 2026
Source: NVD

Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2, and 4.53.3, a vulnerability in Fleet's Windows MDM enrollment flow could allow an attacker to submit forged authentication tokens that are not properly validated. Because JWT signatures were no...

Vendor: go
Product: github.com/fleetdm/fleet
Published: Jan 20, 2026
Source: GitHub
CVE-2025-56005 CRITICAL - 9.8

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because `pickle` allows executio...

Vendor: n/a
Product: n/a
Published: Jan 20, 2026
Source: NVD
CVE-2025-64087 CRITICAL - 9.8

A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execute arbitrary code via injecting crafted template expressions.

Vendor: maven
Product: fr.opensagres.xdocreport:fr.opensagres.xdocreport.template.freemarker
Published: Jan 20, 2026
Source: GitHub
CVE-2025-65482 CRITICAL - 9.8

An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.

Vendor: maven
Product: fr.opensagres.xdocreport:fr.opensagres.xdocreport.document
Published: Jan 20, 2026
Source: GitHub
CVE-2025-55423 CRITICAL - 9.8

A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation or sanitization, allowing OS command injection.

Vendor: n/a
Product: n/a
Published: Jan 20, 2026
Source: NVD
CVE-2025-53912 CRITICAL - 9.6

An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file read. An attacker can send http request to trigger this vulnerability.

Vendor: MedDream
Product: MedDream PACS Premium
Published: Jan 20, 2026
Source: NVD
CVE-2026-22844 CRITICAL - 9.9

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.

Vendor: Zoom Communications Inc.
Product: Zoom Node
Published: Jan 20, 2026
Source: NVD
CVE-2025-14533 CRITICAL - 9.8

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated atta...

Vendor: hwk-fr
Product: Advanced Custom Fields: Extended
Published: Jan 20, 2026
Source: NVD
CVE-2026-1221 CRITICAL - 9.8

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to the database using hardcoded database credentials stored in the firmware.

Published: Jan 20, 2026
Source: NVD
CVE-2026-0907 CRITICAL - 9.8

Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Published: Jan 20, 2026
Source: NVD
CVE-2026-0906 CRITICAL - 9.8

Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

Published: Jan 20, 2026
Source: NVD
CVE-2026-0905 CRITICAL - 9.8

Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)

Published: Jan 20, 2026
Source: NVD
CVE-2026-23837 CRITICAL - 9.8

MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions allows unauthenticated users to bypass the mandatory authentication check in the roleBasedAuthMiddleware. By simply not providing an authentication coo...

Vendor: franklioxygen
Product: MyTube
Published: Jan 19, 2026
Source: NVD
CVE-2026-23841 CRITICAL - 9.3

Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryCreated=`. Version 0.70.0 fixes the issue.

Vendor: leepeuker
Product: movary
Published: Jan 19, 2026
Source: NVD
CVE-2026-23840 CRITICAL - 9.3

Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryDeleted=`. Version 0.70.0 fixes the issue.

Vendor: leepeuker
Product: movary
Published: Jan 19, 2026
Source: NVD