Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
Showing 3,301 - 3,320 of 3,615 CVEs
CVE-2025-67146 CRITICAL - 9.4

Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1) member_search.php, (2) trainer_search.php, and (3) gym_search.php, and via the 'id' parameter in (4) payment_search.php. An unauthenticated remote attacker can...

Published: Jan 12, 2026
Source: NVD
CVE-2025-29329 CRITICAL - 9.8

Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request.

Vendor: sagemcom
Product: f\@st_3686_firmware
Published: Jan 12, 2026
Source: NVD
CVE-2025-67147 CRITICAL - 9.8

Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key' parameters in (2) secure_login.php, and the '...

Published: Jan 12, 2026
Source: NVD
CVE-2025-66802 CRITICAL - 9.8

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.

Vendor: covid-19_contact_tracing_system_project
Product: covid-19_contact_tracing_system
Published: Jan 12, 2026
Source: NVD
CVE-2025-51567 CRITICAL - 9.1

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.

Vendor: jayesh
Product: online_exam_system
Published: Jan 12, 2026
Source: NVD
CVE-2026-22781 CRITICAL - 9.8

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query parameters. The query parameters are passed as command-line arguments to the CGI executable via Windows CreateProcess(). An una...

Vendor: ritlabs
Product: tinyweb
Published: Jan 12, 2026
Source: NVD
CVE-2026-22252 CRITICAL - 9.9

LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticated user to execute shell commands as root inside the container through a single API request. This vulnerability is f...

Vendor: librechat
Product: librechat
Published: Jan 12, 2026
Source: NVD
CVE-2025-63314 CRITICAL - 10.0

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

Vendor: ddsn
Product: cm3_acora_cms
Published: Jan 12, 2026
Source: NVD
CVE-2025-46070 CRITICAL - 9.8

An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component

Vendor: automai
Product: botmanager
Published: Jan 12, 2026
Source: NVD
CVE-2025-46066 CRITICAL - 9.9

An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

Vendor: automai
Product: director
Published: Jan 12, 2026
Source: NVD
CVE-2025-65552 CRITICAL - 9.8

D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not implement rolling codes, message authentication, or anti-replay protection, allowing an attacker within RF range to record valid alarm/control frames and r...

Vendor: d3dsecurity
Product: xz-g12_firmware
Published: Jan 12, 2026
Source: NVD
CVE-2025-69270 CRITICAL - 9.8

Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

Vendor: broadcom
Product: dx_netops_spectrum
Published: Jan 12, 2026
Source: NVD
CVE-2025-69269 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier.

Vendor: broadcom
Product: dx_netops_spectrum
Published: Jan 12, 2026
Source: NVD
CVE-2025-52694 CRITICAL - 9.8

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet.

Vendor: advantech
Product: iot_edge_linux_docker
Published: Jan 12, 2026
Source: NVD
CVE-2026-0852 CRITICAL - 9.8

A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminUpdateUser.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released...

Vendor: fabian
Product: online_music_site
Published: Jan 12, 2026
Source: NVD
CVE-2026-0851 CRITICAL - 9.8

A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote exploitation of the attack is possible. The exploit is publi...

Vendor: fabian
Product: online_music_site
Published: Jan 12, 2026
Source: NVD
CVE-2026-0821 CRITICAL - 9.8

A vulnerability was determined in quickjs-ng quickjs up to 0.11.0. This vulnerability affects the function js_typed_array_constructor of the file quickjs.c. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed a...

Vendor: quickjs-ng
Product: quickjs
Published: Jan 10, 2026
Source: NVD
CVE-2025-15503 CRITICAL - 9.8

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible...

Vendor: sangfor
Product: operation_and_maintenance_security_management_system
Published: Jan 10, 2026
Source: NVD
CVE-2025-15502 CRITICAL - 9.8

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of the argument Hostname leads to os command injection. The attack can be executed...

Vendor: sangfor
Product: operation_and_maintenance_security_management_system
Published: Jan 10, 2026
Source: NVD
CVE-2026-22687 CRITICAL - 9.8

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use prompt‑based bypass techn...

Vendor: tencent
Product: weknora
Published: Jan 10, 2026
Source: NVD