Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,623
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,221 - 3,240 of 3,470 CVEs
CVE-2021-47781 CRITICAL - 9.8

Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of service condition through a maliciously crafted .cmd file. Attackers can create a specially constructed .cmd file with repeated characters to overwhelm the console emulator's buff...

Vendor: Cmder
Product: Cmder Console Emulator
Published: Jan 15, 2026
Source: NVD
CVE-2021-47774 CRITICAL - 9.8

Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload exceeding 256 bytes to overwrite Structured Exception Handler and gain remote code execution through a bind shel...

Vendor: En
Product: Kingdia CD Extractor
Published: Jan 15, 2026
Source: NVD
CVE-2021-47772 CRITICAL - 9.8

10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code execution. Attackers can craft a malicious text file with carefully constructed payload to trigger a reverse shell and execute arbitrary code on the ta...

Vendor: 10-strike
Product: network_inventory_explorer
Published: Jan 15, 2026
Source: NVD
CVE-2021-47753 CRITICAL - 9.8

phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and execute system commands through a crafted web shell parameter.

Vendor: phpkf
Product: cms
Published: Jan 15, 2026
Source: NVD
CVE-2025-67084 CRITICAL - 9.9

File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).

Vendor: invoiceplane
Product: invoiceplane
Published: Jan 15, 2026
Source: NVD
CVE-2026-22910 CRITICAL - 9.1

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

Vendor: sick
Product: tdc-x401gl_firmware
Published: Jan 15, 2026
Source: NVD
CVE-2026-22909 CRITICAL - 9.1

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.

Vendor: sick
Product: tdc-x401gl_firmware
Published: Jan 15, 2026
Source: NVD
CVE-2026-22908 CRITICAL - 9.1

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

Vendor: sick
Product: tdc-x401gl_firmware
Published: Jan 15, 2026
Source: NVD
CVE-2026-22907 CRITICAL - 9.1

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

Vendor: sick
Product: tdc-x401gl_firmware
Published: Jan 15, 2026
Source: NVD
CVE-2026-22859 CRITICAL - 9.1

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_msconfig_setup, causing an out‑of‑bounds read. This vulnerability...

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22858 CRITICAL - 9.1

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c ...

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22857 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22855 CRITICAL - 9.1

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in 3.20.1.

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22854 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlled read length is used to read file data into an IRP output stream buffer without a hard upper bound, allowing an oversized read to overwrite heap memor...

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22853 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability...

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22852 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses callback->formats_count across multiple MSG_SNDIN_...

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2025-70968 CRITICAL - 9.8

FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().

Vendor: freeimage_project
Product: freeimage
Published: Jan 14, 2026
Source: NVD
CVE-2025-37184 CRITICAL - 9.8

A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby comprom...

Vendor: arubanetworks
Product: edgeconnect_sd-wan_orchestrator
Published: Jan 14, 2026
Source: NVD
CVE-2026-23550 CRITICAL - 10.0

Incorrect Privilege Assignment vulnerability in Modular DS allows Privilege Escalation.This issue affects Modular DS: from n/a through 2.5.1.

Published: Jan 14, 2026
Source: NVD
CVE-2025-14502 CRITICAL - 9.8

The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the template parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of...

Published: Jan 14, 2026
Source: NVD