Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
Showing 3,401 - 3,420 of 3,615 CVEs
CVE-2026-21679 CRITICAL - 9.8

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap-buffer-overflow in CIccLocalizedUnicode::GetText(). This issue has been patched in version 2.3.1.2.

Vendor: color
Product: iccdev
Published: Jan 07, 2026
Source: NVD
CVE-2025-61492 CRITICAL - 10.0

A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input.

Published: Jan 07, 2026
Source: NVD
CVE-2025-12543 CRITICAL - 9.6

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without re...

Published: Jan 07, 2026
Source: NVD
CVE-2025-47552 CRITICAL - 9.8

Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37.

Published: Jan 07, 2026
Source: NVD
CVE-2025-32303 CRITICAL - 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.

Published: Jan 07, 2026
Source: NVD
CVE-2026-0643 CRITICAL - 9.8

A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The explo...

Vendor: projectworlds
Product: house_rental_and_property_listing_project
Published: Jan 07, 2026
Source: NVD
CVE-2025-68637 CRITICAL - 9.1

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication between the Uniffle CLI/client and the Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks. This ...

Vendor: apache
Product: uniffle
Published: Jan 07, 2026
Source: NVD
CVE-2025-15018 CRITICAL - 9.8

The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key...

Published: Jan 07, 2026
Source: NVD
CVE-2025-15471 CRITICAL - 9.8

A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The ve...

Published: Jan 07, 2026
Source: NVD
CVE-2025-30996 CRITICAL - 9.9

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This i...

Published: Jan 06, 2026
Source: NVD
CVE-2025-14942 CRITICAL - 9.8

wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client applications with wolfSSH version 1.4.21 and earlier. Users of wolfSSH must updat...

Vendor: wolfssh
Product: wolfssh
Published: Jan 06, 2026
Source: NVD
CVE-2025-60534 CRITICAL - 9.8

Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.

Published: Jan 06, 2026
Source: NVD
CVE-2025-39477 CRITICAL - 9.8

Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InWave Jobs: from n/a through 3.5.8.

Published: Jan 06, 2026
Source: NVD
CVE-2026-0640 CRITICAL - 9.8

A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be ...

Vendor: tenda
Product: ac23_firmware
Published: Jan 06, 2026
Source: NVD
CVE-2025-65212 CRITICAL - 9.8

An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker to directly request the configuration file address and download the core configuration file without logging into t...

Published: Jan 06, 2026
Source: NVD
CVE-2025-60262 CRITICAL - 9.8

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attack...

Published: Jan 06, 2026
Source: NVD
CVE-2020-36925 CRITICAL - 9.8

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without au...

Published: Jan 06, 2026
Source: NVD
CVE-2020-36923 CRITICAL - 9.8

Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.

Vendor: sony
Product: bravia_signage
Published: Jan 06, 2026
Source: NVD
CVE-2020-36912 CRITICAL - 9.8

Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manipulate the 'pagina' GET parameter. Attackers can craft malicious links that redirect users to arbitrary websites by exploiting impro...

Published: Jan 06, 2026
Source: NVD
CVE-2025-15001 CRITICAL - 9.8

The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthentica...

Published: Jan 06, 2026
Source: NVD