Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
Showing 3,241 - 3,260 of 3,601 CVEs
CVE-2025-70968 CRITICAL - 9.8

FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().

Vendor: freeimage_project
Product: freeimage
Published: Jan 14, 2026
Source: NVD
CVE-2025-37184 CRITICAL - 9.8

A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby comprom...

Vendor: arubanetworks
Product: edgeconnect_sd-wan_orchestrator
Published: Jan 14, 2026
Source: NVD
CVE-2026-23550 CRITICAL - 10.0

Incorrect Privilege Assignment vulnerability in Modular DS allows Privilege Escalation.This issue affects Modular DS: from n/a through 2.5.1.

Published: Jan 14, 2026
Source: NVD
CVE-2025-14502 CRITICAL - 9.8

The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the template parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of...

Published: Jan 14, 2026
Source: NVD
CVE-2025-14301 CRITICAL - 9.8

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce verification, or path valida...

Published: Jan 14, 2026
Source: NVD
CVE-2026-22686 CRITICAL - 10.0

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in the host Node.js runtime. When a tool invocation fails, encla...

Published: Jan 14, 2026
Source: NVD
CVE-2023-54339 CRITICAL - 9.8

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%2...

Published: Jan 13, 2026
Source: NVD
CVE-2023-54337 CRITICAL - 9.1

Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.

Vendor: sysax
Product: multi_server
Published: Jan 13, 2026
Source: NVD
CVE-2023-54335 CRITICAL - 9.8

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

Published: Jan 13, 2026
Source: NVD
CVE-2023-54334 CRITICAL - 9.8

Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH chain and potentially e...

Published: Jan 13, 2026
Source: NVD
CVE-2023-54330 CRITICAL - 9.8

Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to ...

Published: Jan 13, 2026
Source: NVD
CVE-2023-54329 CRITICAL - 9.8

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload...

Published: Jan 13, 2026
Source: NVD
CVE-2023-54328 CRITICAL - 9.8

AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes application crashes. Attackers can generate a 7000-byte payload to trigger the denial of service and potentially exploit the software's registration mechanism.

Published: Jan 13, 2026
Source: NVD
CVE-2022-50935 CRITICAL - 9.8

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.

Published: Jan 13, 2026
Source: NVD
CVE-2022-50926 CRITICAL - 9.8

WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without...

Published: Jan 13, 2026
Source: NVD
CVE-2022-50925 CRITICAL - 9.8

Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific ...

Published: Jan 13, 2026
Source: NVD
CVE-2022-50922 CRITICAL - 9.8

Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a specially crafted registration code. Attackers can generate a payload that overwrites the application's memory stack, potentially enabling remote c...

Published: Jan 13, 2026
Source: NVD
CVE-2022-50919 CRITICAL - 9.8

Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without auth...

Published: Jan 13, 2026
Source: NVD
CVE-2022-50912 CRITICAL - 9.8

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.

Published: Jan 13, 2026
Source: NVD
CVE-2022-50893 CRITICAL - 9.8

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.

Vendor: viaviweb
Product: wallpaper_admin
Published: Jan 13, 2026
Source: NVD