Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,535
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,321 - 3,340 of 3,474 CVEs
CVE-2025-64090 CRITICAL - 10.0

This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

Published: Jan 09, 2026
Source: NVD
CVE-2025-13761 CRITICAL - 9.6

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a special...

Vendor: gitlab
Product: gitlab
Published: Jan 09, 2026
Source: NVD
CVE-2025-14741 CRITICAL - 9.1

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for unauthenti...

Published: Jan 09, 2026
Source: NVD
CVE-2025-70974 CRITICAL - 10.0

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-sup...

Published: Jan 09, 2026
Source: NVD
CVE-2025-14736 CRITICAL - 9.8

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.25. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display...

Published: Jan 09, 2026
Source: NVD
CVE-2026-0732 CRITICAL - 9.8

A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the argument path results in command injection. The attack may be performed from remote. The exploit has been made public and could be used.

Vendor: dlink
Product: di-8200g_firmware
Published: Jan 09, 2026
Source: NVD
CVE-2025-68717 CRITICAL - 9.4

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user...

Published: Jan 08, 2026
Source: NVD
CVE-2025-68715 CRITICAL - 9.1

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading ...

Published: Jan 08, 2026
Source: NVD
CVE-2025-66916 CRITICAL - 9.4

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

Published: Jan 08, 2026
Source: NVD
CVE-2025-66913 CRITICAL - 9.8

JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than CV...

Published: Jan 08, 2026
Source: NVD
CVE-2025-67325 CRITICAL - 9.8

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

Published: Jan 08, 2026
Source: NVD
CVE-2026-22234 CRITICAL - 9.8

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

Published: Jan 08, 2026
Source: NVD
CVE-2025-67825 CRITICAL - 9.8

An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated ...

Published: Jan 08, 2026
Source: NVD
CVE-2025-61548 CRITICAL - 9.8

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is incorporated directly into SQL queries without proper parameterization or escaping. Th...

Vendor: edubusinesssolutions
Product: print_shop_pro_webdesk
Published: Jan 08, 2026
Source: NVD
CVE-2025-61546 CRITICAL - 9.1

There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 that enables remote attacker to create financial discrepancies by purchasing items with a negative quantity. This vulnerability is possible due to reliance on ...

Published: Jan 08, 2026
Source: NVD
CVE-2025-61246 CRITICAL - 9.8

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

Vendor: indieka900
Product: online_shopping_system
Published: Jan 08, 2026
Source: NVD
CVE-2025-59470 CRITICAL - 9.0

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

Vendor: veeam
Product: veeam_backup_\&_replication
Published: Jan 08, 2026
Source: NVD
CVE-2025-59469 CRITICAL - 9.0

This vulnerability allows a Backup or Tape Operator to write files as root.

Vendor: veeam
Product: veeam_backup_\&_replication
Published: Jan 08, 2026
Source: NVD
CVE-2025-59468 CRITICAL - 9.1

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

Vendor: veeam
Product: veeam_backup_\&_replication
Published: Jan 08, 2026
Source: NVD
CVE-2025-56425 CRITICAL - 9.1

An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.183 and earlier of enaio 11.0, and in the AppConnctor component version 11.10.0.183 and earlier of enaio 11.10. The vulnerability allows authenticated re...

Vendor: optimal-systems
Product: enaio
Published: Jan 08, 2026
Source: NVD