Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,523
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 3,381 - 3,400 of 3,474 CVEs
CVE-2025-69264 CRITICAL - 9.8

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 blocks postinstall scripts via the onlyB...

Vendor: pnpm
Product: pnpm
Published: Jan 07, 2026
Source: NVD
CVE-2026-22189 CRITICAL - 9.8

Panda3D versions up to and including 1.10.16 egg-mkfont contains a stack-based buffer overflow vulnerability due to use of an unbounded sprintf() call with attacker-controlled input. When constructing glyph filenames, egg-mkfont formats a user-supplied glyph pattern (-gp) into a fixed-size stack buf...

Vendor: cmu
Product: panda3d
Published: Jan 07, 2026
Source: NVD
CVE-2026-22184 CRITICAL - 9.8

zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz comm...

Vendor: zlib
Product: zlib
Published: Jan 07, 2026
Source: NVD
CVE-2025-68705 CRITICAL - 9.8

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contains a path traversal vulnerability in the /rustfs/rpc/read_file_stream endpoint. This issue has been patched in version 1.0.0-alpha.79.

Vendor: rustfs
Product: rustfs
Published: Jan 07, 2026
Source: NVD
CVE-2026-21855 CRITICAL - 9.3

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, a reflected Cross Site Scripting (XSS) vulnerability in the toast notification system allows any attacker to execute arbitrary JavaScript in the context of a victim's browser session by crafting a malici...

Published: Jan 07, 2026
Source: NVD
CVE-2026-21854 CRITICAL - 9.8

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vulnerability in the login endpoint allows any unauthenticated user to gain full admin access to the Tarkov Data Manager admin panel by exploiting a JavaScript prototype property acce...

Published: Jan 07, 2026
Source: NVD
CVE-2026-21679 CRITICAL - 9.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap-buffer-overflow in CIccLocalizedUnicode::GetText(). This issue has been patched in version 2.3.1.2.

Vendor: color
Product: iccdev
Published: Jan 07, 2026
Source: NVD
CVE-2025-61492 CRITICAL - 10.0

A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input.

Published: Jan 07, 2026
Source: NVD
CVE-2025-12543 CRITICAL - 9.6

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without re...

Published: Jan 07, 2026
Source: NVD
CVE-2025-47552 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37.

Published: Jan 07, 2026
Source: NVD
CVE-2025-32303 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.

Published: Jan 07, 2026
Source: NVD
CVE-2026-0643 CRITICAL - 9.8

A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The explo...

Vendor: projectworlds
Product: house_rental_and_property_listing_project
Published: Jan 07, 2026
Source: NVD
CVE-2025-68637 CRITICAL - 9.1

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication between the Uniffle CLI/client and the Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks. This ...

Vendor: apache
Product: uniffle
Published: Jan 07, 2026
Source: NVD
CVE-2025-15018 CRITICAL - 9.8

The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key...

Published: Jan 07, 2026
Source: NVD
CVE-2025-15471 CRITICAL - 9.8

A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The ve...

Published: Jan 07, 2026
Source: NVD
CVE-2025-30996 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This i...

Published: Jan 06, 2026
Source: NVD
CVE-2025-14942 CRITICAL - 9.8

wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with wolfSSH version 1.4.21 and earlier. Users of wolfSSH must updat...

Vendor: wolfssh
Product: wolfssh
Published: Jan 06, 2026
Source: NVD
CVE-2025-60534 CRITICAL - 9.8

Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.

Published: Jan 06, 2026
Source: NVD
CVE-2025-39477 CRITICAL - 9.8

Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8.

Published: Jan 06, 2026
Source: NVD
CVE-2026-0640 CRITICAL - 9.8

A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be ...

Vendor: tenda
Product: ac23_firmware
Published: Jan 06, 2026
Source: NVD