Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
Showing 3,341 - 3,360 of 3,615 CVEs
CVE-2025-68717 CRITICAL - 9.4

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers piggyback on another user...

Published: Jan 08, 2026
Source: NVD
CVE-2025-68715 CRITICAL - 9.1

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading ...

Published: Jan 08, 2026
Source: NVD
CVE-2025-66916 CRITICAL - 9.4

The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

Published: Jan 08, 2026
Source: NVD
CVE-2025-66913 CRITICAL - 9.8

JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than CV...

Published: Jan 08, 2026
Source: NVD
CVE-2025-67325 CRITICAL - 9.8

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

Published: Jan 08, 2026
Source: NVD
CVE-2026-22234 CRITICAL - 9.8

OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

Published: Jan 08, 2026
Source: NVD
CVE-2025-67825 CRITICAL - 9.8

An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated ...

Published: Jan 08, 2026
Source: NVD
CVE-2025-61548 CRITICAL - 9.8

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34. Unsanitized user input is incorporated directly into SQL queries without proper parameterization or escaping. Th...

Vendor: edubusinesssolutions
Product: print_shop_pro_webdesk
Published: Jan 08, 2026
Source: NVD
CVE-2025-61546 CRITICAL - 9.1

There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 that enables remote attacker to create financial discrepancies by purchasing items with a negative quantity. This vulnerability is possible due to reliance on ...

Published: Jan 08, 2026
Source: NVD
CVE-2025-61246 CRITICAL - 9.8

indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

Vendor: indieka900
Product: online_shopping_system
Published: Jan 08, 2026
Source: NVD
CVE-2025-59470 CRITICAL - 9.0

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

Vendor: veeam
Product: veeam_backup_\&_replication
Published: Jan 08, 2026
Source: NVD
CVE-2025-59469 CRITICAL - 9.0

This vulnerability allows a Backup or Tape Operator to write files as root.

Vendor: veeam
Product: veeam_backup_\&_replication
Published: Jan 08, 2026
Source: NVD
CVE-2025-59468 CRITICAL - 9.1

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

Vendor: veeam
Product: veeam_backup_\&_replication
Published: Jan 08, 2026
Source: NVD
CVE-2025-56425 CRITICAL - 9.1

An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.183 and earlier of enaio 11.0, and in the AppConnctor component version 11.10.0.183 and earlier of enaio 11.10. The vulnerability allows authenticated re...

Vendor: optimal-systems
Product: enaio
Published: Jan 08, 2026
Source: NVD
CVE-2025-55125 CRITICAL - 9.8

This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

Vendor: veeam
Product: veeam_backup_\&_replication
Published: Jan 08, 2026
Source: NVD
CVE-2026-22043 CRITICAL - 9.8

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in RustFS IAM allows a restricted service account or STS credential to self-issue an unrestricted service account, inheriting the parent’s full privilege...

Vendor: rustfs
Product: rustfs
Published: Jan 08, 2026
Source: NVD
CVE-2026-21891 CRITICAL - 9.8

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and including 1.5.0, the application checks the validity of the username but appears to skip, misinterpret, or incorrectly validate the password when the provided username matches a known...

Vendor: zimaspace
Product: zimaos
Published: Jan 08, 2026
Source: NVD
CVE-2026-21876 CRITICAL - 9.3

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a col...

Published: Jan 08, 2026
Source: NVD
CVE-2025-69258 CRITICAL - 9.8

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.

Vendor: trendmicro
Product: apex_central
Published: Jan 08, 2026
Source: NVD
CVE-2025-62877 CRITICAL - 9.8

Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluster. The environment is not affected if the PXE boot mechanism i...

Published: Jan 08, 2026
Source: NVD