Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,523
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 3,401 - 3,420 of 3,474 CVEs
CVE-2025-65212 CRITICAL - 9.8

An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker to directly request the configuration file address and download the core configuration file without logging into t...

Published: Jan 06, 2026
Source: NVD
CVE-2025-60262 CRITICAL - 9.8

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attack...

Published: Jan 06, 2026
Source: NVD
CVE-2020-36925 CRITICAL - 9.8

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without au...

Published: Jan 06, 2026
Source: NVD
CVE-2020-36923 CRITICAL - 9.8

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

Vendor: sony
Product: bravia_signage
Published: Jan 06, 2026
Source: NVD
CVE-2020-36912 CRITICAL - 9.8

Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manipulate the 'pagina' GET parameter. Attackers can craft malicious links that redirect users to arbitrary websites by exploiting impro...

Published: Jan 06, 2026
Source: NVD
CVE-2025-15001 CRITICAL - 9.8

The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthentica...

Published: Jan 06, 2026
Source: NVD
CVE-2025-14996 CRITICAL - 9.8

The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it pos...

Published: Jan 06, 2026
Source: NVD
CVE-2026-21675 CRITICAL - 9.8

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a Use After Free vulnerability in the CIccXform::Create() function, where it deletes the hint. This issue is fixed in version 2.3.1.1.

Vendor: color
Product: iccdev
Published: Jan 06, 2026
Source: NVD
CVE-2025-15385 CRITICAL - 9.8

Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects com.Afmobi.Boomplayer: 7.4.63.

Published: Jan 06, 2026
Source: NVD
CVE-2025-15444 CRITICAL - 9.8

Crypt::Sodium::XS module versions prior toΒ 0.000042,Β for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277Β  https://www.cve.org/CVERecord?id=CVE-2025-69277 . The l...

Published: Jan 06, 2026
Source: NVD
CVE-2026-0607 CRITICAL - 9.8

A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be...

Vendor: fabian
Product: online_music_site
Published: Jan 06, 2026
Source: NVD
CVE-2026-0606 CRITICAL - 9.8

A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /FrontEnd/Albums.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public...

Vendor: fabian
Product: online_music_site
Published: Jan 05, 2026
Source: NVD
CVE-2025-68456 CRITICAL - 9.1

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion or information disclosure. Users should update to...

Vendor: craftcms
Product: craft_cms
Published: Jan 05, 2026
Source: NVD
CVE-2026-0605 CRITICAL - 9.8

A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Such manipulation of the argument username/password leads to sql injection. The attack may be performed from remote. The exploit has b...

Vendor: fabian
Product: online_music_site
Published: Jan 05, 2026
Source: NVD
CVE-2025-67397 CRITICAL - 9.1

An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specific payload injection.

Vendor: passy
Product: passy
Published: Jan 05, 2026
Source: NVD
CVE-2025-27807 CRITICAL - 9.1

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes via malformed NAS packe...

Vendor: samsung
Product: exynos_990_firmware
Published: Jan 05, 2026
Source: NVD
CVE-2025-55204 CRITICAL - 9.6

muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in. An attacker can exploit this issue by embedding a specially crafted `muffon://` link on any website they control. When a victim visits the site or cli...

Vendor: muffon
Product: muffon
Published: Jan 05, 2026
Source: NVD
CVE-2025-39484 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects Entrada: from n/a through 5.7.7.

Published: Jan 05, 2026
Source: NVD
CVE-2025-14346 CRITICAL - 9.8

WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An attacker within range can pair with the device and issue movement commands, override speed restrictions, and manipulate configuration profiles without any credentials or user inte...

Published: Jan 05, 2026
Source: NVD
CVE-2026-0597 CRITICAL - 9.8

A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality of the file /retailer/edit_profile.php. This manipulation of the argument txtRetailerAddress causes sql injection. Remote exploitation of the attack is possible. The exploit has be...

Vendor: campcodes
Product: supplier_management_system
Published: Jan 05, 2026
Source: NVD