Browse CVEs

225 CVEs analyzed. 574 pending.

All Critical High Medium Low
CVE-2025-5329 9.8

This SQL injection vulnerability in Martcode Software's Delta Course Automation allows attackers to execute arbitrary SQL commands on the database. Al...

Feb 4, 2026
CVE-2026-24465 9.8

A stack-based buffer overflow vulnerability in ELECOM wireless LAN access point devices allows remote attackers to execute arbitrary code by sending s...

Feb 3, 2026
CVE-2026-25137 9.1

The NixOS Odoo package exposes the database manager without authentication, allowing unauthorized actors to delete or download the entire database and...

Feb 2, 2026
CVE-2026-25142 10.0

CVE-2026-25142 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.27. Attackers can use the __lookupGetter__ method t...

Feb 2, 2026
CVE-2026-23515 9.9

Signal K Server versions before 1.5.0 contain a command injection vulnerability in the set-system-time plugin that allows authenticated users with wri...

Feb 2, 2026
CVE-2026-22778 9.8

This vulnerability in vLLM allows attackers to leak heap memory addresses by sending invalid images to the multimodal endpoint, which reduces ASLR ent...

Feb 2, 2026
CVE-2022-50981 9.8

CVE-2022-50981 allows unauthenticated remote attackers to gain full administrative access to affected devices because they ship without a default pass...

Feb 2, 2026
CVE-2024-5386 9.6

In lunary-ai/lunary version 1.2.2, a privilege escalation vulnerability allows users with 'viewer' role to hijack other user accounts by obtaining pas...

Feb 2, 2026
CVE-2024-5986 9.1

This vulnerability in h2o-3 allows remote attackers to write arbitrary data to any file on the server, potentially leading to remote code execution an...

Feb 2, 2026
CVE-2024-2356 9.6

This CVE describes a Local File Inclusion vulnerability in the lollms-webui application that allows attackers to execute arbitrary Python code remotel...

Feb 2, 2026
CVE-2026-20418 9.8

CVE-2026-20418 is a critical out-of-bounds write vulnerability in Thread protocol implementations that allows remote attackers to execute arbitrary co...

Feb 2, 2026
CVE-2026-20407 9.3

This CVE describes a privilege escalation vulnerability in MediaTek wlan STA drivers where missing bounds checks allow local attackers to gain elevate...

Feb 2, 2026
CVE-2025-15030 9.8

The User Profile Builder WordPress plugin before version 3.15.2 has an improper password reset mechanism that allows unauthenticated attackers to rese...

Feb 2, 2026
CVE-2026-25202 9.8

MagicINFO 9 Server versions below 21.1090.1 contain hardcoded database credentials, allowing attackers to authenticate and manipulate the database. Th...

Feb 2, 2026
CVE-2026-25200 9.8

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without proper authentication, leading to stored cross-site scriptin...

Feb 2, 2026
CVE-2025-48782 9.8

This vulnerability allows remote attackers to upload malicious files to the Soar Cloud HRD Human Resource Management System, which can lead to arbitra...

Jun 6, 2025
CVE-2025-48780 9.8

A critical deserialization vulnerability in Soar Cloud HRD Human Resource Management System allows remote attackers to execute arbitrary system comman...

Jun 6, 2025