Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
Showing 3,221 - 3,240 of 3,601 CVEs
CVE-2025-66417 CRITICAL - 9.8

GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 11.0.3.

Vendor: glpi-project
Product: glpi
Published: Jan 15, 2026
Source: NVD
CVE-2025-62193 CRITICAL - 9.8

Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret expressions. By leveraging a SPAWN command, a remote, unauthenticated attacker can execute arbitrary OS commands. Fixed in a version of 'gov.noaa.pmel.tm...

Vendor: National Oceanic and Atmospheric Administration (NOAA)
Product: Live Access Server (LAS)
Published: Jan 15, 2026
Source: NVD
CVE-2025-67079 CRITICAL - 9.8

File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library via crafted PDF file to the file upload and thumbnail functions.

Vendor: agora-project
Product: agora-project
Published: Jan 15, 2026
Source: NVD
CVE-2021-47819 CRITICAL - 9.8

ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code execution capabilities. Attackers can upload a PHP script through the profile attachment section and execute system commands by accessing the uploaded fil...

Vendor: Projeqtor
Product: ProjeQtOr Project Management
Published: Jan 15, 2026
Source: NVD
CVE-2021-47781 CRITICAL - 9.8

Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of service condition through a maliciously crafted .cmd file. Attackers can create a specially constructed .cmd file with repeated characters to overwhelm the console emulator's buff...

Vendor: Cmder
Product: Cmder Console Emulator
Published: Jan 15, 2026
Source: NVD
CVE-2021-47774 CRITICAL - 9.8

Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload exceeding 256 bytes to overwrite Structured Exception Handler and gain remote code execution through a bind shel...

Vendor: En
Product: Kingdia CD Extractor
Published: Jan 15, 2026
Source: NVD
CVE-2021-47772 CRITICAL - 9.8

10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code execution. Attackers can craft a malicious text file with carefully constructed payload to trigger a reverse shell and execute arbitrary code on the ta...

Vendor: 10-strike
Product: network_inventory_explorer
Published: Jan 15, 2026
Source: NVD
CVE-2021-47753 CRITICAL - 9.8

phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file extension checks. Attackers can upload a PHP file disguised as a PNG, rename it, and execute system commands through a crafted web shell parameter.

Vendor: phpkf
Product: cms
Published: Jan 15, 2026
Source: NVD
CVE-2025-67084 CRITICAL - 9.9

File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can later be executed remotely, leading to Remote Code Execution (RCE).

Vendor: invoiceplane
Product: invoiceplane
Published: Jan 15, 2026
Source: NVD
CVE-2026-22910 CRITICAL - 9.1

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system.

Vendor: sick
Product: tdc-x401gl_firmware
Published: Jan 15, 2026
Source: NVD
CVE-2026-22909 CRITICAL - 9.1

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations.

Vendor: sick
Product: tdc-x401gl_firmware
Published: Jan 15, 2026
Source: NVD
CVE-2026-22908 CRITICAL - 9.1

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

Vendor: sick
Product: tdc-x401gl_firmware
Published: Jan 15, 2026
Source: NVD
CVE-2026-22907 CRITICAL - 9.1

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

Vendor: sick
Product: tdc-x401gl_firmware
Published: Jan 15, 2026
Source: NVD
CVE-2026-22859 CRITICAL - 9.1

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_msconfig_setup, causing an out‑of‑bounds read. This vulnerability...

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22858 CRITICAL - 9.1

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c ...

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22857 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is freed by irp->Complete() and then accessed again on the error path. This vulnerability is fixed in 3.20.1.

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22855 CRITICAL - 9.1

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in 3.20.1.

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22854 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlled read length is used to read file data into an IRP output stream buffer without a hard upper bound, allowing an oversized read to overwrite heap memor...

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22853 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability...

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD
CVE-2026-22852 CRITICAL - 9.8

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses callback->formats_count across multiple MSG_SNDIN_...

Vendor: freerdp
Product: freerdp
Published: Jan 14, 2026
Source: NVD