Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,623
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,201 - 3,220 of 3,470 CVEs
CVE-2025-14234 CRITICAL - 9.8

Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and e...

Published: Jan 16, 2026
Source: NVD
CVE-2025-14233 CRITICAL - 9.8

Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02...

Published: Jan 16, 2026
Source: NVD
CVE-2025-14232 CRITICAL - 9.8

Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02...

Published: Jan 16, 2026
Source: NVD
CVE-2025-14231 CRITICAL - 9.8

Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.0...

Published: Jan 16, 2026
Source: NVD
CVE-2021-47798 CRITICAL - 9.8

NoteBurner 2.35 contains a buffer overflow vulnerability in the license code input field that allows attackers to crash the application. Attackers can generate a 6000-byte payload and paste it into the 'Name' and 'Code' fields to trigger an application crash.

Vendor: Noteburner
Product: NoteBurner
Published: Jan 16, 2026
Source: NVD
CVE-2021-47796 CRITICAL - 9.8

Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. Attackers can connect to port 23 using the default credential to execute arbitrary commands on the camera's operating system.

Vendor: Denver
Product: Smart Wifi Camera
Published: Jan 16, 2026
Source: NVD
CVE-2021-47785 CRITICAL - 9.8

Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote code execution. Attackers can craft a malicious payload to overwrite SEH handlers and execute a bind shell on port 3110 by exploiting improper input validation.

Vendor: Mp3-Avi-Mpeg-Wmv-Rm-To-Audio-Cd-Burner
Product: Ether_MP3_CD_Burner
Published: Jan 16, 2026
Source: NVD
CVE-2026-22864 CRITICAL - 9.8

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned pathโ€™s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefor...

Vendor: deno
Product: deno
Published: Jan 15, 2026
Source: NVD
CVE-2025-67822 CRITICAL - 9.4

A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to ga...

Vendor: mitel
Product: mivoice_mx-one
Published: Jan 15, 2026
Source: NVD
CVE-2023-7334 CRITICAL - 9.8

Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore ...

Vendor: chanjetvip
Product: t\+
Published: Jan 15, 2026
Source: NVD
CVE-2025-70892 CRITICAL - 9.8

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.

Vendor: phpgurukul
Product: cyber_cafe_management_system
Published: Jan 15, 2026
Source: NVD
CVE-2026-23527 CRITICAL - 9.8

H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerability. readRawBody is doing a strict case-sensitive check for the Transfer-Encoding header. It explicitly looks for "chunked", but per the RFC, t...

Vendor: h3
Product: h3
Published: Jan 15, 2026
Source: NVD
CVE-2026-23520 CRITICAL - 9.0

Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcaneโ€™s updater service supported lifecycle labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcane.lifecycle.post-update that allowed defining a command to run ...

Vendor: getarcaneapp
Product: arcane
Published: Jan 15, 2026
Source: NVD
CVE-2026-23519 CRITICAL - 9.8

RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. Prior to 0.4.4, the thumbv6m-none-eabi (Cortex M0, M0+ and M1) compiler emits non-constant time assembly when using cmovnz (p...

Vendor: rustcrypto
Product: cmov
Published: Jan 15, 2026
Source: NVD
CVE-2026-22249 CRITICAL - 9.8

Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write via Zip Import Feature (ZipSlip). In apps/server/src/integrations/import/utils/file.utils.ts, there are no validation on filename. This vulnerability i...

Vendor: docmost
Product: docmost
Published: Jan 15, 2026
Source: NVD
CVE-2025-67647 CRITICAL - 9.1

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a server side request forgery (SSRF) and denial of service (DoS) under certain conditions. From 2.44.0 through 2.49.4, the vulnerability results in a DoS when...

Vendor: svelte
Product: adapter-node
Published: Jan 15, 2026
Source: NVD
CVE-2025-66417 CRITICAL - 9.8

GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.

Vendor: glpi-project
Product: glpi
Published: Jan 15, 2026
Source: NVD
CVE-2025-62193 CRITICAL - 9.8

Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret expressions. By leveraging a SPAWN command, a remote, unauthenticated attacker can execute arbitrary OS commands. Fixed in a version of 'gov.noaa.pmel.tm...

Vendor: National Oceanic and Atmospheric Administration (NOAA)
Product: Live Access Server (LAS)
Published: Jan 15, 2026
Source: NVD
CVE-2025-67079 CRITICAL - 9.8

File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions.

Vendor: agora-project
Product: agora-project
Published: Jan 15, 2026
Source: NVD
CVE-2021-47819 CRITICAL - 9.8

ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code execution capabilities. Attackers can upload a PHP script through the profile attachment section and execute system commands by accessing the uploaded fil...

Vendor: Projeqtor
Product: ProjeQtOr Project Management
Published: Jan 15, 2026
Source: NVD