Browse CVEs

225 CVEs analyzed. 686 pending.

All Critical High Medium Low
CVE-2026-20402 7.5

This vulnerability in MediaTek modems allows remote denial of service through improper input validation. Attackers can crash affected devices by conne...

Feb 2, 2026
CVE-2026-20403 7.5

This vulnerability in MediaTek modems allows remote denial of service via system crash when a device connects to a malicious base station. Attackers c...

Feb 2, 2026
CVE-2025-9974 8.0

CVE-2025-9974 is an OS command injection vulnerability in the unified WEBUI application of Nokia ONT/Beacon devices. Authenticated attackers with low ...

Feb 2, 2026
CVE-2026-1518 2.7

This vulnerability in Keycloak's CIBA (Client Initiated Backchannel Authentication) feature allows attackers to make blind server-side requests to int...

Feb 2, 2026
CVE-2026-20711 6.5

A cross-site scripting vulnerability in the email function of Cybozu Garoon allows attackers to inject malicious scripts that can reset arbitrary user...

Feb 2, 2026
CVE-2026-22881 5.7

A cross-site scripting vulnerability in the Message function of Cybozu Garoon allows attackers to inject malicious scripts that can reset arbitrary us...

Feb 2, 2026
CVE-2026-22888 4.9

An improper input verification vulnerability in Cybozu Garoon allows attackers to modify portal settings without proper authorization. This could bloc...

Feb 2, 2026
CVE-2026-0658 4.3

The Five Star Restaurant Reservations WordPress plugin before version 2.7.9 lacks CSRF protection on some bulk actions, allowing attackers to trick lo...

Feb 2, 2026
CVE-2025-15396 7.1

The Library Viewer WordPress plugin before version 3.2.0 contains a reflected cross-site scripting (XSS) vulnerability where unsanitized parameters ar...

Feb 2, 2026
CVE-2025-15030 9.8

The User Profile Builder WordPress plugin before version 3.15.2 has an improper password reset mechanism that allows unauthenticated attackers to rese...

Feb 2, 2026
CVE-2026-1746 6.3

This SQL injection vulnerability in JeecgBoot 3.9.0 allows remote attackers to execute arbitrary SQL commands through the Online Report API's loadDict...

Feb 2, 2026
CVE-2026-1530 8.1

A vulnerability in fog-kubevirt allows remote attackers to perform Man-in-the-Middle attacks by intercepting communications between Satellite and Open...

Feb 2, 2026
CVE-2026-1531 8.1

This vulnerability in foreman_kubevirt disables SSL certificate verification by default when connecting to OpenShift without an explicitly set CA cert...

Feb 2, 2026
CVE-2026-1745 4.3

This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against the Medical Certificate Generator App 1.0, enabling u...

Feb 2, 2026
CVE-2025-13881 2.7

This vulnerability allows Keycloak administrators with limited privileges to access sensitive custom user attributes that should be hidden by User Pro...

Feb 2, 2026
CVE-2026-25202 9.8

MagicINFO 9 Server versions below 21.1090.1 contain hardcoded database credentials, allowing attackers to authenticate and manipulate the database. Th...

Feb 2, 2026
CVE-2026-25201 8.8

An unauthenticated attacker can upload arbitrary files to MagicInfo9 Server, leading to remote code execution and privilege escalation. This affects M...

Feb 2, 2026
CVE-2026-25200 9.8

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without proper authentication, leading to stored cross-site scriptin...

Feb 2, 2026
CVE-2026-24788 8.8

CVE-2026-24788 is an OS command injection vulnerability in RaspAP raspap-webgui that allows authenticated users to execute arbitrary commands on the u...

Feb 2, 2026
CVE-2026-1744 2.4

This CVE describes a cross-site scripting (XSS) vulnerability in D-Link DSL-6641K routers running firmware version N8.TR069.20131126. Attackers can in...

Feb 2, 2026
CVE-2026-1741 6.6

This CVE describes a backdoor vulnerability in the EFM ipTIME A8004T router's debug interface. Attackers can remotely manipulate the 'cmd' parameter t...

Feb 2, 2026
CVE-2026-1742 4.7

This vulnerability allows remote attackers to upload arbitrary files to the EFM ipTIME A8004T router via the VPN service component. Attackers can expl...

Feb 2, 2026
CVE-2026-1743 3.1

This CVE describes an authentication bypass vulnerability in DJI drone models (Mavic Mini, Air, Spark, Mini SE) through capture-replay attacks on the ...

Feb 2, 2026
CVE-2026-1740 7.3

This vulnerability allows remote attackers to bypass authentication on EFM ipTIME A8004T routers via improper authentication in the Hidden Hiddenlogin...

Feb 2, 2026
CVE-2026-1737 5.3

This vulnerability in Open5GS allows remote attackers to trigger a reachable assertion in the CreateBearerRequest handler, potentially causing denial ...

Feb 2, 2026
CVE-2026-1738 5.3

CVE-2026-1738 is a reachable assertion vulnerability in Open5GS SGWC component that allows remote attackers to cause denial of service by manipulating...

Feb 2, 2026
CVE-2026-1739 5.3

A null pointer dereference vulnerability in Free5GC's Policy Control Function (PCF) allows remote attackers to cause denial of service by crashing the...

Feb 2, 2026
CVE-2025-13348 N/A

An improper access control vulnerability in ASUS Secure Delete Driver allows local users to create arbitrary files in specified paths by sending speci...

Feb 2, 2026
CVE-2026-1735 4.3

This CVE describes a command injection vulnerability in Yealink MeetingBar A30's Diagnostic Handler component. Attackers with physical access to the d...

Feb 2, 2026
CVE-2026-1736 5.3

A reachable assertion vulnerability in Open5GS SGWC component allows remote attackers to cause denial of service by sending specially crafted requests...

Feb 2, 2026
CVE-2026-1734 5.3

This vulnerability allows unauthorized remote access to the crontab endpoint in Zhong Bang CRMEB versions up to 5.6.3. Attackers can exploit this miss...

Feb 2, 2026
CVE-2026-1733 4.3

This CVE describes an improper authorization vulnerability in Zhong Bang CRMEB's store integration API endpoint. Attackers can manipulate the order_id...

Feb 1, 2026
CVE-2026-25253 8.8

OpenClaw (also known as clawdbot or Moltbot) versions before 2026.1.29 automatically establish WebSocket connections using gatewayUrl values from quer...

Feb 1, 2026
CVE-2020-37055 7.8

CVE-2020-37055 is an unquoted service path vulnerability in SpyHunter 4 that allows local attackers to execute arbitrary code with SYSTEM privileges. ...

Feb 1, 2026
CVE-2020-37061 7.8

CVE-2020-37061 is an unquoted service path vulnerability in BOOTP Turbo 2.0.1214 that allows local attackers to execute arbitrary code with SYSTEM pri...

Feb 1, 2026
CVE-2020-37062 7.8

CVE-2020-37062 is an unquoted service path vulnerability in DHCP Turbo that allows local attackers to execute arbitrary code with elevated privileges....

Feb 1, 2026
CVE-2020-37063 7.8

CVE-2020-37063 is an unquoted service path vulnerability in TFTP Turbo that allows local attackers to execute arbitrary code with elevated SYSTEM priv...

Feb 1, 2026
CVE-2020-37064 7.8

CVE-2020-37064 is an unquoted service path vulnerability in EPSON EasyMP Network Projection software that allows local attackers to execute arbitrary ...

Feb 1, 2026
CVE-2020-37045 7.8

CVE-2020-37045 is an unquoted service path vulnerability in Veritas NetBackup 7.0's INET Daemon service. This allows local attackers to place maliciou...

Feb 1, 2026
CVE-2020-37047 7.8

CVE-2020-37047 is an unquoted service path vulnerability in Deep Instinct Windows Agent that allows local attackers to execute arbitrary code with Loc...

Feb 1, 2026
CVE-2020-37048 7.8

CVE-2020-37048 is an unquoted service path vulnerability in Iskysoft Application Framework Service that allows local attackers to execute arbitrary co...

Feb 1, 2026
CVE-2020-37037 7.8

CVE-2020-37037 is an unquoted service path vulnerability in Avast SecureLine VPN client that allows local attackers to execute arbitrary code with SYS...

Feb 1, 2026
CVE-2023-54343 6.4

QWE DL 2.0.1 mobile web application has a persistent cross-site scripting (XSS) vulnerability in path parameters that allows attackers to inject malic...

Feb 1, 2026
CVE-2022-50940 6.4

Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting (XSS) vulnerability in the name parameter. Attackers can inject malicious scr...

Feb 1, 2026
CVE-2022-50941 6.4

BootCommerce 3.2.1 contains persistent cross-site scripting (XSS) vulnerabilities in guest order checkout input fields. Attackers can inject malicious...

Feb 1, 2026
CVE-2022-50942 5.4

CVE-2022-50942 is a client-side cross-site scripting vulnerability in Icinga Web 2.8.2 that allows attackers to inject malicious scripts through the i...

Feb 1, 2026
CVE-2022-50950 6.5

Webile 1.0.1 contains an unauthenticated directory traversal vulnerability that allows attackers to manipulate file paths and access sensitive system ...

Feb 1, 2026
CVE-2022-50951 6.4

WiFi File Transfer 1.0.8 has a persistent cross-site scripting vulnerability where attackers can inject malicious JavaScript through file and folder n...

Feb 1, 2026
CVE-2022-50952 6.4

Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the profile name input field. Attackers can i...

Feb 1, 2026
CVE-2021-47917 6.4

Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious scri...

Feb 1, 2026