Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,536
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,301 - 3,320 of 3,474 CVEs
CVE-2026-0852 CRITICAL - 9.8

A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminUpdateUser.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released...

Vendor: fabian
Product: online_music_site
Published: Jan 12, 2026
Source: NVD
CVE-2026-0851 CRITICAL - 9.8

A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote exploitation of the attack is possible. The exploit is publi...

Vendor: fabian
Product: online_music_site
Published: Jan 12, 2026
Source: NVD
CVE-2026-0821 CRITICAL - 9.8

A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed a...

Vendor: quickjs-ng
Product: quickjs
Published: Jan 10, 2026
Source: NVD
CVE-2025-15503 CRITICAL - 9.8

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible...

Vendor: sangfor
Product: operation_and_maintenance_security_management_system
Published: Jan 10, 2026
Source: NVD
CVE-2025-15502 CRITICAL - 9.8

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of the argument Hostname leads to os command injection. The attack can be executed...

Vendor: sangfor
Product: operation_and_maintenance_security_management_system
Published: Jan 10, 2026
Source: NVD
CVE-2026-22687 CRITICAL - 9.8

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use promptโ€‘based bypass techn...

Vendor: tencent
Product: weknora
Published: Jan 10, 2026
Source: NVD
CVE-2025-65091 CRITICAL - 10.0

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack. This issue has been patc...

Published: Jan 10, 2026
Source: NVD
CVE-2025-61686 CRITICAL - 9.1

React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an u...

Published: Jan 10, 2026
Source: NVD
CVE-2026-22600 CRITICAL - 9.1

OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality of OpenProject prior to version 16.6.4. By uploading a specially crafted SVG file (disguised as a PNG) as a work package attachment, an atta...

Vendor: openproject
Product: openproject
Published: Jan 10, 2026
Source: NVD
CVE-2025-15501 CRITICAL - 9.8

A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack is...

Vendor: sangfor
Product: operation_and_maintenance_security_management_system
Published: Jan 09, 2026
Source: NVD
CVE-2026-22584 CRITICAL - 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.

Vendor: salesforce
Product: uni2ts
Published: Jan 09, 2026
Source: NVD
CVE-2025-15500 CRITICAL - 9.8

A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Handler. The manipulation of the argument sessionPath results in os command injectio...

Vendor: sangfor
Product: operation_and_maintenance_management_system
Published: Jan 09, 2026
Source: NVD
CVE-2025-15499 CRITICAL - 9.8

A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.java. The manipulation of the argument filename leads to os command injection. The attack may be initiated remotely. The e...

Vendor: sangfor
Product: operation_and_maintenance_management_system
Published: Jan 09, 2026
Source: NVD
CVE-2025-70161 CRITICAL - 9.8

EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName field, allowing arbitr...

Vendor: edimax
Product: br-6208ac_firmware
Published: Jan 09, 2026
Source: NVD
CVE-2025-69542 CRITICAL - 9.8

A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper sanitization. When a DHCP clien...

Published: Jan 09, 2026
Source: NVD
CVE-2025-15496 CRITICAL - 9.8

A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project wa...

Vendor: guchengwuyue
Product: yshopmall
Published: Jan 09, 2026
Source: NVD
CVE-2025-15493 CRITICAL - 9.8

A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMapper.xml. Executing a manipulation of the argument searchWord can lead to sql injection. It is possible to launch the attack remotely. The exploit has ...

Vendor: docsys_project
Product: docsys
Published: Jan 09, 2026
Source: NVD
CVE-2025-14598 CRITICAL - 9.8

BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables arbitrary SQL commands to be executed on the backend database.

Published: Jan 09, 2026
Source: NVD
CVE-2025-66050 CRITICAL - 9.8

Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all firmware versions ar...

Vendor: vivotek
Product: ip7137_firmware
Published: Jan 09, 2026
Source: NVD
CVE-2025-64093 CRITICAL - 10.0

Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

Published: Jan 09, 2026
Source: NVD