Total CVEs

111,140

Critical Severity

796

High Severity

2,523

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 670 CVEs
CVE-2025-8572 CRITICAL - 9.8

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1306 CRITICAL - 9.8

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-26273 CRITICAL - 9.8

Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The application leaks the password reset token within a hidden HTML input field on the password reset page. This allows any unauthenticated attacker to retrieve th...

Vendor: idno
Product: known
Published: Feb 13, 2026
Source: NVD
CVE-2026-26190 CRITICAL - 9.8

Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a weak, predictable default authentication token derived from etcd.rootPath (defaul...

Vendor: milvus-io
Product: milvus
Published: Feb 13, 2026
Source: NVD
CVE-2025-69770 CRITICAL - 10.0

A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.

Published: Feb 13, 2026
Source: NVD
CVE-2020-37167 CRITICAL - 9.8

ClamAV ClamBC bytecode interpreter contains a vulnerability in function name processing that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation in function name encoding to potentially execute malicious bytecode or cause unexpected behavior in the...

Vendor: ClamAV
Product: ClamBC
Published: Feb 12, 2026
Source: NVD
CVE-2019-25337 CRITICAL - 9.8

OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user inform...

Vendor: OwnCloud
Product: OwnCloud
Published: Feb 12, 2026
Source: NVD
CVE-2019-25327 CRITICAL - 9.8

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.

Vendor: Mersenne Research, Inc
Product: Prime95
Published: Feb 12, 2026
Source: NVD
CVE-2019-25321 CRITICAL - 9.8

FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload that triggers a buffer overflow when pasted into the Custom Command textbox, enabling remote...

Vendor: Softpedia
Product: FTP Navigator
Published: Feb 12, 2026
Source: NVD
CVE-2019-25319 CRITICAL - 9.8

Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the 'Domain Name Keywords' input field to trigger an access ...

Vendor: Internet-Soft
Product: Domain Quester Pro
Published: Feb 12, 2026
Source: NVD
CVE-2026-1358 CRITICAL - 9.8

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could allow an unauthenticated user to potentially obtain remote code execution on the server.

Published: Feb 12, 2026
Source: NVD
CVE-2026-25227 CRITICAL - 9.1

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the authentik server containe...

Vendor: goauthentik
Product: authentik
Published: Feb 12, 2026
Source: NVD
CVE-2025-70314 CRITICAL - 9.8

webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable

Published: Feb 12, 2026
Source: NVD
CVE-2026-26219 CRITICAL - 9.1

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who obtain password hashes through database exposure, backup leakage, or other compromise vectors to rapid...

Vendor: newbee-ltd
Product: newbee-mall
Published: Feb 12, 2026
Source: NVD
CVE-2026-26218 CRITICAL - 9.8

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may ...

Vendor: newbee-ltd
Product: newbee-mall
Published: Feb 12, 2026
Source: NVD
CVE-2025-70981 CRITICAL - 9.8

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

Published: Feb 12, 2026
Source: NVD
CVE-2026-26216 CRITICAL - 10.0

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remot...

Vendor: unclecode
Product: Crawl4AI
Published: Feb 12, 2026
Source: NVD
CVE-2025-69634 CRITICAL - 9.0

Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is disputed by a third party who indicates that exploitation can only occur if an unprivileged user knows the token of an admin user...

Published: Feb 12, 2026
Source: NVD
CVE-2025-14014 CRITICAL - 9.8

Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Smart Panel: before 20251215.

Vendor: NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co.
Product: Smart Panel
Published: Feb 12, 2026
Source: NVD
CVE-2025-10969 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Blind SQL Injection.This issue affects E-Commerce Package: through 27112025.

Vendor: Farktor Software E-Commerce Services Inc.
Product: E-Commerce Package
Published: Feb 12, 2026
Source: NVD