Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
Showing 3,181 - 3,200 of 3,601 CVEs
CVE-2026-23839 CRITICAL - 9.3

Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryUpdated=`. Version 0.70.0 fixes the issue.

Vendor: leepeuker
Product: movary
Published: Jan 19, 2026
Source: NVD
CVE-2026-23836 CRITICAL - 9.9

HotCRP is conference review software. A problem introduced in April 2024 in version 3.1 led to inadequately sanitized code generation for HotCRP formulas which allowed users to trigger the execution of arbitrary PHP code. The problem is patched in release version 3.2.

Vendor: kohler
Product: hotcrp
Published: Jan 19, 2026
Source: NVD
CVE-2026-22797 CRITICAL - 9.9

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged i...

Vendor: OpenStack
Product: keystonemiddleware
Published: Jan 19, 2026
Source: NVD
CVE-2026-1162 CRITICAL - 9.8

A flaw has been found in UTT HiPER 810 1.7.4-141218. The impacted element is the function strcpy of the file /goform/setSysAdm. This manipulation of the argument passwd1 causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Published: Jan 19, 2026
Source: NVD
CVE-2026-0610 CRITICAL - 9.8

SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12

Published: Jan 19, 2026
Source: NVD
CVE-2026-1181 CRITICAL - 9.0

Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy that allowed credentialed cross-origin requests from other Altium-controlled subdomains, including forum.live.altium.com. As a result, JavaScript executing on those origins could acce...

Published: Jan 19, 2026
Source: NVD
CVE-2025-10484 CRITICAL - 9.8

The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.1. This is due to the plugin not properly verifying a users identity prior to authenticating them via the fma_lwp_set_session_ph...

Vendor: FmeAddons
Product: Registration & Login with Mobile Phone Number for WooCommerce
Published: Jan 17, 2026
Source: NVD
CVE-2025-15403 CRITICAL - 9.8

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'add_menu' function is accessible via the 'rm_user_exists' AJAX action and allows arbitrary updates to the 'admin_order' se...

Vendor: metagauss
Product: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
Published: Jan 17, 2026
Source: NVD
CVE-2026-23800 CRITICAL - 10.0

Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 before 2.6.0.

Product: Modular DS
Published: Jan 16, 2026
Source: NVD
CVE-2026-23744 CRITICAL - 9.8

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam insp...

Vendor: MCPJam
Product: inspector
Published: Jan 16, 2026
Source: NVD
CVE-2026-23722 CRITICAL - 9.1

WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the WeGIA system, specifically within the html/memorando/insere_despacho.php file. The application fails to properly sanitize or encode user-supplied input via t...

Vendor: LabRedesCefetRJ
Product: WeGIA
Published: Jan 16, 2026
Source: NVD
CVE-2026-23523 CRITICAL - 9.6

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command execution on the victim’...

Vendor: OpenAgentPlatform
Product: Dive
Published: Jan 16, 2026
Source: NVD
CVE-2025-14894 CRITICAL - 9.8

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process ...

Vendor: livewire-filemanager
Product: filemanager
Published: Jan 16, 2026
Source: NVD
CVE-2025-59870 CRITICAL - 9.8

HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introducing a security risk

Vendor: hcltech
Product: myxalytics
Published: Jan 16, 2026
Source: NVD
CVE-2025-60021 CRITICAL - 9.8

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate the user-provided extra_options parame...

Vendor: apache
Product: brpc
Published: Jan 16, 2026
Source: NVD
CVE-2026-0975 CRITICAL - 9.8

Delta Electronics DIAView has Command Injection vulnerability.

Vendor: deltaww
Product: diaview
Published: Jan 16, 2026
Source: NVD
CVE-2026-1021 CRITICAL - 9.8

Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Vendor: gotac
Product: police_statistics_database_system
Published: Jan 16, 2026
Source: NVD
CVE-2026-1019 CRITICAL - 9.8

Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.

Vendor: gotac
Product: police_statistics_database_system
Published: Jan 16, 2026
Source: NVD
CVE-2025-62582 CRITICAL - 9.8

Delta Electronics DIAView has multiple vulnerabilities.

Vendor: deltaww
Product: diaview
Published: Jan 16, 2026
Source: NVD
CVE-2025-62581 CRITICAL - 9.8

Delta Electronics DIAView has multiple vulnerabilities.

Vendor: deltaww
Product: diaview
Published: Jan 16, 2026
Source: NVD