Total CVEs

126,116

Critical Severity

2,290

High Severity

7,924

Last 7 Days

1,177
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 841 - 860 of 897 CVEs

IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to server-side enforcement of client-side security.

Vendor: IBM
Product: ApplinX
Published: Jan 20, 2026
Source: NVD
CVE-2026-1197 LOW - 3.1

A vulnerability was detected in MineAdmin 1.x/2.x. Affected by this vulnerability is an unknown functionality of the file /system/downloadById. Performing a manipulation of the argument ID results in information disclosure. The attack can be initiated remotely. The attack's complexity is rated ...

Published: Jan 20, 2026
Source: NVD
CVE-2026-1196 LOW - 3.1

A security vulnerability has been detected in MineAdmin 1.x/2.x. Affected is an unknown function of the file /system/getFileInfoById. Such manipulation of the argument ID leads to information disclosure. It is possible to launch the attack remotely. The attack requires a high level of complexity. Th...

Published: Jan 20, 2026
Source: NVD

HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting in unauthorized access

Vendor: HCL Software
Product: AION
Published: Jan 19, 2026
Source: NVD

HCL AION version 2 is affected by a Technical Error Disclosure vulnerability. This can expose sensitive technical details, potentially resulting in information disclosure or aiding further attacks.

Vendor: HCL Software
Product: AION
Published: Jan 19, 2026
Source: NVD

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

Vendor: HCL Software
Product: AION
Published: Jan 19, 2026
Source: NVD

HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-based attacks.

Vendor: HCL Software
Product: AION
Published: Jan 19, 2026
Source: NVD

HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse, potentially resulting in unauthorized access if the token is compromised.

Vendor: HCL Software
Product: AION
Published: Jan 19, 2026
Source: NVD

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

Vendor: HCL Software
Product: AION
Published: Jan 19, 2026
Source: NVD

HCL AION version 2 is affected by a Cacheable HTTP Response vulnerability. This may lead to unintended storage of sensitive or dynamic content, potentially resulting in unauthorized access or information disclosure.

Vendor: HCL Software
Product: AION
Published: Jan 19, 2026
Source: NVD
CVE-2026-1161 LOW - 3.5

A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the file /handler/recruitment.go. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.

Published: Jan 19, 2026
Source: NVD
CVE-2026-1151 LOW - 2.4

A weakness has been identified in technical-laohu mpay up to 1.2.4. The affected element is an unknown function of the component User Center. This manipulation of the argument Nickname causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the publi...

Published: Jan 19, 2026
Source: NVD
CVE-2026-1147 LOW - 3.5

A vulnerability was found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This affects an unknown part of the file /php/api_patient_schedule.php. Performing a manipulation of the argument Reason results in cross site scripting. It is possible to initiate the attack...

Published: Jan 19, 2026
Source: NVD
CVE-2026-1146 LOW - 3.5

A vulnerability has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this issue is some unknown functionality of the file /php/api_register_patient.php. Such manipulation of the argument firstName/lastName leads to cross site scripting. The at...

Published: Jan 19, 2026
Source: NVD
CVE-2026-1136 LOW - 3.5

A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the function Save of the file /blog/bContent/save of the component ContentController. This manipulation of the argument content/author/title causes cross site scripting. Remote exploitation o...

Published: Jan 19, 2026
Source: NVD

A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in the library clay.h. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit has been released to the public and may be used ...

Vendor: nicbarker
Product: clay
Published: Jan 18, 2026
Source: NVD
CVE-2026-1049 LOW - 3.5

A security vulnerability has been detected in LigeroSmart up to 6.1.26. The affected element is an unknown function of the file /otrs/index.pl. Such manipulation of the argument TicketID leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publi...

Published: Jan 17, 2026
Source: NVD
CVE-2026-1048 LOW - 3.5

A weakness has been identified in LigeroSmart up to 6.1.26. Impacted is an unknown function of the file /otrs/index.pl?Action=AgentTicketZoom. This manipulation of the argument TicketID causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available t...

Published: Jan 17, 2026
Source: NVD
CVE-2026-0682 LOW - 2.2

The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.28 due to insufficient validation of user-supplied URLs in the 'audio_url' parameter. This makes it possible for authenticated attackers, with Administrator-level ac...

Published: Jan 17, 2026
Source: NVD

Best Practical Request Tracker (RT) before 4.4.9, 5.0.9, and 6.0.2 allows CSV Injection via ticket values when TSV export is used.

Vendor: bestpractical
Product: Request Tracker
Published: Jan 16, 2026
Source: NVD