Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
Showing 141 - 160 of 417 CVEs
CVE-2025-65127 HIGH - 7.5

A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote unauthenticated attackers to access administrative information-retrieval functions intended for authenticated users. By invoking "get_*" operations, attackers can obtai...

Published: Feb 11, 2026
Source: NVD
CVE-2025-64075 CRITICAL - 10.0

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie value.

Published: Feb 11, 2026
Source: NVD
CVE-2026-1819 HIGH - 8.8

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS.This issue affects ViPort: through 23012026.

Published: Feb 04, 2026
Source: NVD
CVE-2025-63624 CRITICAL - 9.8

SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows a remote attacker to execute arbitrary code via the imei_list.aspx file.

Published: Feb 03, 2026
Source: NVD
CVE-2026-25202 CRITICAL - 9.8

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.

Vendor: Samsung Electronics
Product: MagicINFO 9 Server
Published: Feb 02, 2026
Source: NVD
CVE-2026-25201 HIGH - 8.8

An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1.

Vendor: Samsung Electronics
Product: MagicINFO 9 Server
Published: Feb 02, 2026
Source: NVD
CVE-2026-25200 CRITICAL - 9.8

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1.

Vendor: Samsung Electronics
Product: MagicINFO 9 Server
Published: Feb 02, 2026
Source: NVD
CVE-2020-37058 HIGH - 7.8

Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration. Local attackers can exploit the unquoted path to inject malicious code that will execute with elevated LocalSystem privileges during service startup.

Vendor: Andrea Electronics
Product: Andrea ST Filters Service
Published: Jan 30, 2026
Source: NVD
CVE-2025-67645 HIGH - 8.8

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the Profile Edit endpoint. An authenticated normal user can modify the request parameters (pubpid / pid) to reference another user’s record...

Vendor: openemr
Product: openemr
Published: Jan 28, 2026
Source: NVD

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes and Care Plan, where an encounter has Sensitivity...

Vendor: openemr
Product: openemr
Published: Jan 28, 2026
Source: NVD
CVE-2025-5805 HIGH - 8.8

Missing Authorization vulnerability in Ninetheme Electron electron allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Electron: from n/a through <= 1.8.2.

Published: Jan 22, 2026
Source: NVD
CVE-2026-22793 CRITICAL - 9.6

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Prior to version 0.15.3, an unsafe option parsing vulnerability in the ECharts Markdown plugin allows any user able to submit ECharts code blocks to execute arbitrary JavaScript code in the renderer...

Vendor: nanbingxyz
Product: 5ire
Published: Jan 21, 2026
Source: NVD
CVE-2026-23733 MEDIUM - 6.4

LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context. This XSS can be escalated to Remote Code Executio...

Vendor: npm
Product: @lobehub/chat
Published: Jan 20, 2026
Source: GitHub
CVE-2026-0975 CRITICAL - 9.8

Delta Electronics DIAView has Command Injection vulnerability.

Vendor: deltaww
Product: diaview
Published: Jan 16, 2026
Source: NVD
CVE-2025-62582 CRITICAL - 9.8

Delta Electronics DIAView has multiple vulnerabilities.

Vendor: deltaww
Product: diaview
Published: Jan 16, 2026
Source: NVD
CVE-2025-62581 CRITICAL - 9.8

Delta Electronics DIAView has multiple vulnerabilities.

Vendor: deltaww
Product: diaview
Published: Jan 16, 2026
Source: NVD
CVE-2019-25291 HIGH - 7.5

INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving de...

Published: Jan 08, 2026
Source: NVD

TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target sy...

Published: Dec 23, 2025
Source: NVD

Delta Electronics DVP15MC11T lacks proper validation of the modbus/tcp packets and can lead to denial of service.

Published: Dec 22, 2025
Source: NVD

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerability exists in the Mermaid diagram rendering component that allows arbitrary JavaScript execution. Due to the exposure of the Electron IPC renderer to...

Published: Dec 16, 2025
Source: NVD