Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
Showing 3,281 - 3,300 of 3,615 CVEs
CVE-2025-47855 CRITICAL - 9.8

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

Published: Jan 13, 2026
Source: NVD
CVE-2025-25249 CRITICAL - 9.8

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to...

Vendor: fortinet
Product: fortios
Published: Jan 13, 2026
Source: NVD
CVE-2025-25176 CRITICAL - 9.1

Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

Published: Jan 13, 2026
Source: NVD
CVE-2025-69992 CRITICAL - 9.8

phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.

Vendor: phpgurukul
Product: news_portal
Published: Jan 13, 2026
Source: NVD
CVE-2025-69991 CRITICAL - 9.8

phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.

Vendor: phpgurukul
Product: news_portal
Published: Jan 13, 2026
Source: NVD
CVE-2025-69990 CRITICAL - 9.1

phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.

Vendor: phpgurukul
Product: news_portal
Published: Jan 13, 2026
Source: NVD
CVE-2025-65783 CRITICAL - 9.8

An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

Published: Jan 13, 2026
Source: NVD
CVE-2025-12548 CRITICAL - 9.0

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3...

Published: Jan 13, 2026
Source: NVD
CVE-2026-0892 CRITICAL - 9.8

Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Thunderbird < 147.

Vendor: mozilla
Product: firefox
Published: Jan 13, 2026
Source: NVD
CVE-2026-0884 CRITICAL - 9.8

Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.

Vendor: mozilla
Product: firefox
Published: Jan 13, 2026
Source: NVD
CVE-2026-0881 CRITICAL - 10.0

Sandbox escape in the Messaging System component. This vulnerability affects Firefox < 147 and Thunderbird < 147.

Vendor: mozilla
Product: firefox
Published: Jan 13, 2026
Source: NVD
CVE-2026-0879 CRITICAL - 9.8

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.

Vendor: mozilla
Product: firefox
Published: Jan 13, 2026
Source: NVD
CVE-2025-11250 CRITICAL - 9.1

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

Published: Jan 13, 2026
Source: NVD
CVE-2025-40805 CRITICAL - 10.0

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to circumvent authentication and impersonate a legitimate user. Successful exploitation requires that the attacker has learned the identity of a legitimate...

Published: Jan 13, 2026
Source: NVD
CVE-2025-14829 CRITICAL - 9.1

The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

Published: Jan 13, 2026
Source: NVD
CVE-2025-10915 CRITICAL - 9.8

The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check.

Published: Jan 13, 2026
Source: NVD
CVE-2026-0501 CRITICAL - 9.9

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute crafted SQL queries to read, modify, and delete backend database data. This leads to a high impact on the confidentiality, integrity, and availability of ...

Published: Jan 13, 2026
Source: NVD
CVE-2026-0491 CRITICAL - 9.1

SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functi...

Published: Jan 13, 2026
Source: NVD
CVE-2026-22214 CRITICAL - 9.8

RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds checking when processing incoming serial frame data. The vulnerability occurs in the _handle_char() function, where incoming frame bytes are appended ...

Vendor: riot-os
Product: riot
Published: Jan 12, 2026
Source: NVD
CVE-2026-22213 CRITICAL - 9.8

RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string concatenation in the devopen() function, which constructs a device path using unbounded user-controlled input. The utility ...

Vendor: riot-os
Product: riot
Published: Jan 12, 2026
Source: NVD