Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,569
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,261 - 3,280 of 3,470 CVEs
CVE-2025-68271 CRITICAL - 10.0

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to 6.10.1, OpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of cert...

Published: Jan 13, 2026
Source: NVD
CVE-2025-64155 CRITICAL - 9.8

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to exec...

Vendor: fortinet
Product: fortisiem
Published: Jan 13, 2026
Source: NVD
CVE-2025-47855 CRITICAL - 9.8

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

Published: Jan 13, 2026
Source: NVD
CVE-2025-25249 CRITICAL - 9.8

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to...

Vendor: fortinet
Product: fortios
Published: Jan 13, 2026
Source: NVD
CVE-2025-25176 CRITICAL - 9.1

Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

Published: Jan 13, 2026
Source: NVD
CVE-2025-69992 CRITICAL - 9.8

phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.

Vendor: phpgurukul
Product: news_portal
Published: Jan 13, 2026
Source: NVD
CVE-2025-69991 CRITICAL - 9.8

phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.

Vendor: phpgurukul
Product: news_portal
Published: Jan 13, 2026
Source: NVD
CVE-2025-69990 CRITICAL - 9.1

phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.

Vendor: phpgurukul
Product: news_portal
Published: Jan 13, 2026
Source: NVD
CVE-2025-65783 CRITICAL - 9.8

An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

Published: Jan 13, 2026
Source: NVD
CVE-2025-12548 CRITICAL - 9.0

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3...

Published: Jan 13, 2026
Source: NVD
CVE-2026-0892 CRITICAL - 9.8

Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Thunderbird < 147.

Vendor: mozilla
Product: firefox
Published: Jan 13, 2026
Source: NVD
CVE-2026-0884 CRITICAL - 9.8

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.

Vendor: mozilla
Product: firefox
Published: Jan 13, 2026
Source: NVD
CVE-2026-0881 CRITICAL - 10.0

Sandbox escape in the Messaging System component. This vulnerability affects Firefox < 147 and Thunderbird < 147.

Vendor: mozilla
Product: firefox
Published: Jan 13, 2026
Source: NVD
CVE-2026-0879 CRITICAL - 9.8

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.

Vendor: mozilla
Product: firefox
Published: Jan 13, 2026
Source: NVD
CVE-2025-11250 CRITICAL - 9.1

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

Published: Jan 13, 2026
Source: NVD
CVE-2025-40805 CRITICAL - 10.0

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate...

Published: Jan 13, 2026
Source: NVD
CVE-2025-14829 CRITICAL - 9.1

The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

Published: Jan 13, 2026
Source: NVD
CVE-2025-10915 CRITICAL - 9.8

The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check.

Published: Jan 13, 2026
Source: NVD
CVE-2026-0501 CRITICAL - 9.9

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of ...

Published: Jan 13, 2026
Source: NVD
CVE-2026-0491 CRITICAL - 9.1

SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functi...

Published: Jan 13, 2026
Source: NVD