Total CVEs

111,140

Critical Severity

796

High Severity

2,523

Last 7 Days

1,237
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 41 - 60 of 2,224 CVEs
CVE-2019-25325 HIGH - 8.2

Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated attackers to bypass authentication by manipulating the 'user' POST parameter. Attackers can inject malicious SQL code like ' or 1=1# to manipulate login queries and...

Vendor: Thrive
Product: Smart Home
Published: Feb 12, 2026
Source: NVD
CVE-2019-25322 HIGH - 7.5

Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable admin login credentials. Attackers can access the device by using the hard-coded username 'admin' and password 'admin' in the hidden form input fields.

Vendor: Heatmiser
Product: Heatmiser Netmonitor
Published: Feb 12, 2026
Source: NVD
CVE-2019-25318 HIGH - 8.8

AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by manipulating the output folder text input. Attackers can craft a malicious payload that overwrites stack memory and triggers a bind shell on port 9999 when the 'Browse' ...

Vendor: Avs4You
Product: AVS Audio Converter
Published: Feb 12, 2026
Source: NVD
CVE-2026-26056 HIGH - 8.8

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. It allows users with CR create/update permissions to execute arbitrary WASM code in the ATC controller context by injecting a ma...

Vendor: yokecd
Product: yoke
Published: Feb 12, 2026
Source: NVD
CVE-2026-26055 HIGH - 7.5

Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in the Air Traffic Controller (ATC) component of Yoke. The ATC webhook endpoints lack proper authentication mechanisms, allowing any pod within the cluster network to directly send Ad...

Vendor: yokecd
Product: yoke
Published: Feb 12, 2026
Source: NVD
CVE-2026-25922 HIGH - 8.8

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not have the Encryption Certificate setting under Adva...

Vendor: goauthentik
Product: authentik
Published: Feb 12, 2026
Source: NVD
CVE-2026-25748 HIGH - 8.6

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy. When a malicious cookie...

Vendor: goauthentik
Product: authentik
Published: Feb 12, 2026
Source: NVD
CVE-2025-67432 HIGH - 7.5

A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Published: Feb 12, 2026
Source: NVD
CVE-2019-25348 HIGH - 7.1

Computrols CBAS-Web 19.0.0 contains a boolean-based blind SQL injection vulnerability in the 'id' parameter that allows authenticated attackers to manipulate database queries. Attackers can exploit the vulnerability by crafting boolean-based SQL injection payloads in the 'id' par...

Vendor: Computrols
Product: CBAS-Web
Published: Feb 12, 2026
Source: NVD
CVE-2019-25347 HIGH - 7.1

thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 to the username field to gain unauthorized access to user accounts.

Vendor: kostasmitroglou
Product: thesystem
Published: Feb 12, 2026
Source: NVD
CVE-2019-25346 HIGH - 7.1

TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL code like ' or '1=1 to retrieve unauthorized database records and potentially access sensitive syste...

Vendor: kostasmitroglou
Product: thesystem
Published: Feb 12, 2026
Source: NVD
CVE-2019-25345 HIGH - 7.8

Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service configuration to inject malicious executables and escalate privileges on the system.

Vendor: Realtek
Product: RTK IIS Codec Service
Published: Feb 12, 2026
Source: NVD
CVE-2019-25344 HIGH - 7.8

Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executable files in the application directory. Attackers can replace the original MobileGo.exe with a malicious executable to create a new user account and add it to the Administrators gr...

Vendor: Wondershare
Product: MobileGo
Published: Feb 12, 2026
Source: NVD
CVE-2019-25343 HIGH - 7.8

NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious files to gain SYSTEM or Administrator privileges through unauthorized file modification.

Vendor: Vm3Max
Product: NextVPN
Published: Feb 12, 2026
Source: NVD
CVE-2025-69807 HIGH - 7.5

p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause a denial of service via a packet sent to the server.

Published: Feb 12, 2026
Source: NVD
CVE-2025-63421 HIGH - 7.8

An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file

Published: Feb 12, 2026
Source: NVD
CVE-2025-54519 HIGH - 7.3

A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Vendor: AMD
Product: Vivadoโ„ข Documentation Navigator Installation (Windows)
Published: Feb 12, 2026
Source: NVD
CVE-2025-61880 HIGH - 8.8

In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.

Published: Feb 12, 2026
Source: NVD
CVE-2025-61879 HIGH - 7.7

In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.

Published: Feb 12, 2026
Source: NVD
CVE-2025-54756 HIGH - 8.4

BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest release fixes this issue for new installations; users of old installations are encouraged to change all...

Vendor: BrightSign
Product: BrightSign OS series 4 players, BrightSign OS series 5 players
Published: Feb 12, 2026
Source: NVD