Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,612
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,241 - 3,260 of 3,470 CVEs
CVE-2025-14301 CRITICAL - 9.8

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce verification, or path valida...

Published: Jan 14, 2026
Source: NVD
CVE-2026-22686 CRITICAL - 10.0

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in the host Node.js runtime. When a tool invocation fails, encla...

Published: Jan 14, 2026
Source: NVD
CVE-2023-54339 CRITICAL - 9.8

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%2...

Published: Jan 13, 2026
Source: NVD
CVE-2023-54337 CRITICAL - 9.1

Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.

Vendor: sysax
Product: multi_server
Published: Jan 13, 2026
Source: NVD
CVE-2023-54335 CRITICAL - 9.8

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

Published: Jan 13, 2026
Source: NVD
CVE-2023-54334 CRITICAL - 9.8

Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH chain and potentially e...

Published: Jan 13, 2026
Source: NVD
CVE-2023-54330 CRITICAL - 9.8

Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to ...

Published: Jan 13, 2026
Source: NVD
CVE-2023-54329 CRITICAL - 9.8

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload...

Published: Jan 13, 2026
Source: NVD
CVE-2023-54328 CRITICAL - 9.8

AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes application crashes. Attackers can generate a 7000-byte payload to trigger the denial of service and potentially exploit the software's registration mechanism.

Published: Jan 13, 2026
Source: NVD
CVE-2022-50935 CRITICAL - 9.8

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.

Published: Jan 13, 2026
Source: NVD
CVE-2022-50926 CRITICAL - 9.8

WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without...

Published: Jan 13, 2026
Source: NVD
CVE-2022-50925 CRITICAL - 9.8

Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific ...

Published: Jan 13, 2026
Source: NVD
CVE-2022-50922 CRITICAL - 9.8

Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a specially crafted registration code. Attackers can generate a payload that overwrites the application's memory stack, potentially enabling remote c...

Published: Jan 13, 2026
Source: NVD
CVE-2022-50919 CRITICAL - 9.8

Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without auth...

Published: Jan 13, 2026
Source: NVD
CVE-2022-50912 CRITICAL - 9.8

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.

Published: Jan 13, 2026
Source: NVD
CVE-2022-50893 CRITICAL - 9.8

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.

Vendor: viaviweb
Product: wallpaper_admin
Published: Jan 13, 2026
Source: NVD
CVE-2022-50892 CRITICAL - 9.8

VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating login credentials. Attackers can exploit the login page by injecting 'admin' or 1=1-- - payload to gain unauthorized access to the administrative interface.

Vendor: viaviweb
Product: wallpaper_admin
Published: Jan 13, 2026
Source: NVD
CVE-2020-36911 CRITICAL - 9.8

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.

Published: Jan 13, 2026
Source: NVD
CVE-2026-22871 CRITICAL - 9.8

GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exists in GuardDog's safe_extract() function that allows malicious PyPI packages to write arbitrary files outside the intended extraction directory, leading to Arbitrary File Over...

Vendor: datadoghq
Product: guarddog
Published: Jan 13, 2026
Source: NVD
CVE-2025-37168 CRITICAL - 9.1

Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentia...

Vendor: arubanetworks
Product: arubaos
Published: Jan 13, 2026
Source: NVD