Critical vulnerabilities, curated daily for security professionals
đ¯ SSCV Profile
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Risk scores will be adjusted based on your selected environment
đ
Archived Security Brief
Yesterday's vulnerability disclosures included 22 critical-severity CVEs (CVSS 9.0+), a substantial increase from the prior day's 3 critical issues. High-priority vulnerabilities totaled 84, up 140% from 35 the previous day. Fourteen actively exploited vulnerabilities were added to the KEV catalog, including CVE-2026-20805 affecting Microsoft Windows, CVE-2026-20045 in Cisco Unified Communications Manager, and CVE-2024-37079 targeting Broadcom VMware vCenter Server. Notable critical disclosures include CVE-2026-23830 (CVSS 10.0) in SandboxJS, CVE-2025-21589 (CVSS 9.8) an authentication bypass in Juniper Networks Session Smart Router, and multiple SolarWinds Web Help Desk deserialization vulnerabilities. Patch availability currently stands at 0%, requiring organizations to prioritize compensating controls and monitoring.
22 critical CVEs disclosed, up from 3 the prior day (633% increase)
84 high-priority vulnerabilities identified, up 140% from 35
14 actively exploited CVEs including Microsoft Windows, Cisco UCM, VMware vCenter, and Zimbra
0% patch availability for disclosed vulnerabilities
Affected vendors include SolarWinds, Juniper Networks, Microsoft, Cisco, Broadcom, and SmarterTools
Immediate action: Organizations running Microsoft Windows, Cisco Unified Communications Manager, VMware vCenter Server, SolarWinds Web Help Desk, or Juniper Session Smart Router should assess exposure to actively exploited and critical vulnerabilities immediately. With no patches currently available, implement network segmentation, enhanced monitoring, and vendor-recommended mitigations where possible.
đĄ Tip: Swipe CVE cards left to â star, right to â remove
Section Navigation
â ī¸
CISA Known Exploited Vulnerabilities
â ī¸ CISA KEVURGENT
CVE-2026-24858
9.8
An Authentication Bypass Using an Alternate Path or Channel vulnerabilityMultiple Products
â° Federal Deadline:January 29, 2026(2 days remaining)
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
CVSS Base9.8
â
CRSSelect profile
â ī¸ CISA KEVURGENT
CVE-2025-8110
9.5
GogsGogs
â° Federal Deadline:February 1, 2026(5 days remaining)
Gogs Path Traversal Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEVURGENT
CVE-2026-20805
9.5
MicrosoftWindows
â° Federal Deadline:February 2, 2026(6 days remaining)
Microsoft Windows Information Disclosure Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2026-20045
9.5đ
CiscoUnified Communications Manager
â° Federal Deadline:February 10, 2026(14 days remaining)
Cisco Unified Communications Products Code Injection Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2025-68645
9.5đ
Synacor Zimbra Collaboration Suite (ZCS)
â° Federal Deadline:February 11, 2026(15 days remaining)
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2025-34026
9.5
VersaConcerto
â° Federal Deadline:February 11, 2026(15 days remaining)
Versa Concerto Improper Authentication Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2025-31125
9.5
ViteVitejs
â° Federal Deadline:February 11, 2026(15 days remaining)
Vite Vitejs Improper Access Control Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2025-54313
9.5
Prettiereslint-config-prettier
â° Federal Deadline:February 11, 2026(15 days remaining)
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2024-37079
9.5
BroadcomVMware vCenter Server
â° Federal Deadline:February 12, 2026(16 days remaining)
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2018-14634
9.5
LinuxKernal
â° Federal Deadline:February 15, 2026(19 days remaining)
Linux Kernel Integer Overflow Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2025-52691
9.5đ
SmarterToolsSmarterMail
â° Federal Deadline:February 15, 2026(19 days remaining)
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2026-23760
9.5
SmarterToolsSmarterMail
â° Federal Deadline:February 15, 2026(19 days remaining)
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2026-24061
9.5đ
GNUInetUtils
â° Federal Deadline:February 15, 2026(19 days remaining)
GNU InetUtils Argument Injection Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
đ¨
Critical Vulnerabilities
CVE-2026-22039
9.9đ
Kyverno is a policy engine designed for cloud native platform engineeringMultiple Products
Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall. The resolved `urlPath` is executed using the Kyverno admission controller ServiceAccount, with no enforcement that the request is limited to the policyâs namespace. As a result, any authenticated user with permission to create a namespaced Policy can cause Kyverno to perform Kubernetes API requests using Kyvernoâs admission controller identity, targeting any API path allowed by that ServiceAccountâs RBAC. This breaks namespace isolation by enabling cross-namespace reads (for example, ConfigMaps and, where permitted, Secrets) and allows cluster-scoped or cross-namespace writes (for example, creating ClusterPolicies) by controlling the urlPath through context variable substitution. Versions 1.16.3 and 1.15.3 contain a patch for the vulnerability.
CVSS Base9.9
â
CRSSelect profile
CVE-2026-23830
10đ
SandboxJS is a JavaScript sandboxingMultiple Products
SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. The library attempts to sandbox code execution by replacing the global `Function` constructor with a safe, sandboxed version (`SandboxFunction`). This is handled in `utils.ts` by mapping `Function` to `sandboxFunction` within a map used for lookups. However, before version 0.8.26, the library did not include mappings for `AsyncFunction`, `GeneratorFunction`, and `AsyncGeneratorFunction`. These constructors are not global properties but can be accessed via the `.constructor` property of an instance (e.g., `(async () => {}).constructor`). In `executor.ts`, property access is handled. When code running inside the sandbox accesses `.constructor` on an async function (which the sandbox allows creating), the `executor` retrieves the property value. Since `AsyncFunction` was not in the safe-replacement map, the `executor` returns the actual native host `AsyncFunction` constructor. Constructors for functions in JavaScript (like `Function`, `AsyncFunction`) create functions that execute in the global scope. By obtaining the host `AsyncFunction` constructor, an attacker can create a new async function that executes entirely outside the sandbox context, bypassing all restrictions and gaining full access to the host environment (Remote Code Execution). Version 0.8.26 patches this vulnerability.
CVSS Base10
â
CRSSelect profile
CVE-2021-47900
9.8đ
Gila CMS versions prior toMultiple Products
Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.
CVSS Base9.8
â
CRSSelect profile
CVE-2025-21589
9.8đ
An Authentication Bypass Using an
Alternate Path or Channel vulnerability in Juniper Networks Session Smart
Router may allows aMultiple Products
An Authentication Bypass Using an
Alternate Path or Channel vulnerability in Juniper Networks Session Smart
Router may allows a network-based attacker to bypass authentication
and take administrative control of the device.
This issue affects Session Smart Router:Â
* from 5.6.7 before 5.6.17,Â
* from 6.0 before 6.0.8 (affected from 6.0.8),
* from 6.1 before 6.1.12-lts,Â
* from 6.2 before 6.2.8-lts,Â
* from 6.3 before 6.3.3-r2;Â
This issue affects Session Smart Conductor:Â
* from 5.6.7 before 5.6.17,Â
* from 6.0 before 6.0.8 (affected from 6.0.8),
* from 6.1 before 6.1.12-lts,Â
* from 6.2 before 6.2.8-lts,Â
* from 6.3 before 6.3.3-r2;Â
This issue affects WAN Assurance Managed Routers:Â
* from 5.6.7 before 5.6.17,Â
* from 6.0 before 6.0.8 (affected from 6.0.8),
* from 6.1 before 6.1.12-lts,Â
* from 6.2 before 6.2.8-lts,Â
* from 6.3 before 6.3.3-r2.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-24838
9.1đ
DNNMultiple Products
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0 contain a fix for the issue.
CVSS Base9.1
â
CRSSelect profile
CVE-2026-24841
9.9đ
Dokploy is aMultiple Products
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokploy's WebSocket endpoint `/docker-container-terminal`. The `containerId` and `activeWay` parameters are directly interpolated into shell commands without sanitization, allowing authenticated attackers to execute arbitrary commands on the host server. Version 0.26.6 fixes the issue.
CVSS Base9.9
â
CRSSelect profile
CVE-2026-1470
9.9đ
UnknownMultiple Products
n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime.
An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations.
CVSS Base9.9
â
CRSSelect profile
CVE-2026-24770
9.8đ
RAGFlow is anMultiple Products
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allowing an attacker to overwrite arbitrary files on the server (leading to Remote Code Execution) via a malicious ZIP archive. The MinerUParser class retrieves and extracts ZIP files from an external source (mineru_server_url). The extraction logic in `_extract_zip_no_root` fails to sanitize filenames within the ZIP archive. Commit 64c75d558e4a17a4a48953b4c201526431d8338f contains a patch for the issue.
CVSS Base9.8
â
CRSSelect profile
CVE-2025-40551
9.8đ
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote codeMultiple Products
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
CVSS Base9.8
â
CRSSelect profile
CVE-2025-40553
9.8đ
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote codeMultiple Products
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
CVSS Base9.8
â
CRSSelect profile
CVE-2025-68670
9.1đ
xrdp is an open source RDPMultiple Products
xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additionally, do not rely on stack canary protection on production systems.
CVSS Base9.1
â
CRSSelect profile
CVE-2020-36948
9.8đ
VestaCPMultiple Products
VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-24736
9.1đ
Squidex is an open source headless content management system and content managementMultiple Products
Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The url parameter in the webhook configuration does not appear to validate or restrict destination IP addresses. It accepts local addresses such as 127.0.0.1 or localhost. When a rule is triggered (Either manual trigger by manually calling the trigger endpoint or by a content update or any other triggers), the backend server executes an HTTP request to the user-supplied URL. Crucially, the server logs the full HTTP response in the rule execution log (lastDump field), which is accessible via the API. Which turns a "Blind" SSRF into a "Full Read" SSRF. As of time of publication, no patched versions are available.
CVSS Base9.1
â
CRSSelect profile
CVE-2020-36940
9.8đ
Easy CDMultiple Products
Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows attackers to crash the application. Attackers can generate a 6000-byte payload and paste it into the serial number field to trigger an application crash.
CVSS Base9.8
â
CRSSelect profile
CVE-2025-40552
9.8đ
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that ifMultiple Products
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
CVSS Base9.8
â
CRSSelect profile
CVE-2025-40554
9.8
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerabilityMultiple Products
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-24830
9.8
Integer Overflow or Wraparound vulnerability in RalimMultiple Products
Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.
CVSS Base9.8
â
CRSSelect profile
CVE-2020-36941
9.8
KnockpyMultiple Products
Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server headers. Attackers can manipulate server response headers to include spreadsheet formulas that will execute when the CSV is opened in spreadsheet applications.
CVSS Base9.8
â
CRSSelect profile
CVE-2021-47901
9.8
DirsearchMultiple Products
Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the generated CSV report.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-24832
9.8
UnknownMultiple Products
Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-24872
9.8
improper pointer arithmetic
vulnerability in ProjectSkyfireMultiple Products
improper pointer arithmetic
vulnerability in ProjectSkyfire SkyFire_548.This issue affects SkyFire_548: before 5.4.8-stable5.
CVSS Base9.8
â
CRSSelect profile
CVE-2026-24874
9.1
Access of Resource Using Incompatible TypeMultiple Products
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.
CVSS Base9.1
â
CRSSelect profile
â ī¸
High Priority Updates
â ī¸ CISA KEV
CVE-2026-21509
7.8đ
MicrosoftMultiple Products
â° Federal Deadline:February 15, 2026(19 days remaining)
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally
CVSS Base7.8
â
CRSSelect profile
CVE-2026-0702
7.5đ
WordPressMultiple Products
The VidShop â Shoppable Videos for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'fields' parameter in all versions up to, and including, 1
CVSS Base7.5
â
CRSSelect profile
CVE-2025-14610
7.2đ
WordPressMultiple Products
The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1
CVSS Base7.2
â
CRSSelect profile
CVE-2026-0832
7.3đ
WordPressMultiple Products
The New User Approve plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple REST API endpoints in all versions up to, and including, 3
CVSS Base7.3
â
CRSSelect profile
CVE-2020-36951
8.2đ
UnknownMultiple Products
Phpscript-sgh 0
CVSS Base8.2
â
CRSSelect profile
CVE-2026-24765
7.8đ
PHPUnitMultiple Products
PHPUnit is a testing framework for PHP
CVSS Base7.8
â
CRSSelect profile
CVE-2026-23881
7.7đ
teamsMultiple Products
Kyverno is a policy engine designed for cloud native platform engineering teams
CVSS Base7.7
â
CRSSelect profile
CVE-2026-24833
7.6đ
MicrosoftMultiple Products
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem
CVSS Base7.6
â
CRSSelect profile
CVE-2026-24836
7.6đ
MicrosoftMultiple Products
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem
CVSS Base7.6
â
CRSSelect profile
CVE-2026-24837
7.6đ
MicrosoftMultiple Products
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem
CVSS Base7.6
â
CRSSelect profile
CVE-2026-21408
7.3đ
WindowsMultiple Products
beat-access for Windows version 3
CVSS Base7.3
â
CRSSelect profile
CVE-2026-23592
7.2đ
InsecureMultiple Products
Insecure file operations in HPE Aruba Networking Fabric ComposerÃĸâŦâĸs backup functionality could allow authenticated attackers to achieve remote code execution
CVSS Base7.2
â
CRSSelect profile
CVE-2026-1400
7.2đ
WordPressMultiple Products
The AI Engine â The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `rest_helpers_update_media_metadata` function in all versions up to, and including, 3
CVSS Base7.2
â
CRSSelect profile
CVE-2026-23593
7.5đ
A vulnerability in theMultiple Products
A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files
CVSS Base7.5
â
CRSSelect profile
CVE-2025-27821
7.3đ
nativeMultiple Products
Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client
CVSS Base7.3
â
CRSSelect profile
CVE-2026-21417
7
DellMultiple Products
Dell CloudBoost Virtual Appliance, versions prior to 19
CVSS Base7
â
CRSSelect profile
CVE-2026-24747
8.8
PyTorchMultiple Products
PyTorch is a Python package that provides tensor computation
CVSS Base8.8
â
CRSSelect profile
CVE-2026-24486
8.6đ
UnknownMultiple Products
Python-Multipart is a streaming multipart parser for Python
CVSS Base8.6
â
CRSSelect profile
CVE-2026-24123
7.4đ
BentoMLMultiple Products
BentoML is a Python library for building online serving systems optimized for AI apps and model inference
CVSS Base7.4
â
CRSSelect profile
CVE-2025-59106
8.8
webMultiple Products
The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges
CVSS Base8.8
â
CRSSelect profile
CVE-2025-41726
8.8
DeviceMultiple Products
A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the Device Manager or locally via an API and can cause integer overflows which then may lead to arbitrary code execution within privileged processes
CVSS Base8.8
â
CRSSelect profile
CVE-2026-24470
8.1đ
SkipperMultiple Products
Skipper is an HTTP router and reverse proxy for service composition
CVSS Base8.1
â
CRSSelect profile
CVE-2026-21721
8.1đ
dashboardMultiple Products
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards
CVSS Base8.1
â
CRSSelect profile
CVE-2020-36949
7.5
TapinRadioMultiple Products
TapinRadio 2
CVSS Base7.5
â
CRSSelect profile
CVE-2026-1283
7.8đ
ReleaseMultiple Products
A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Release SOLIDWORKS 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file
WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated users to modify system files and executables
CVSS Base8.8
â
CRSSelect profile
CVE-2020-36942
8.8
VictorMultiple Products
Victor CMS 1
CVSS Base8.8
â
CRSSelect profile
CVE-2026-24778
8.8
GhostMultiple Products
Ghost is an open source content management system
CVSS Base8.8
â
CRSSelect profile
CVE-2025-67645
8.8
OpenEMRMultiple Products
OpenEMR is a free and open source electronic health records and medical practice management application
CVSS Base8.8
â
CRSSelect profile
CVE-2025-14459
8.5đ
flawMultiple Products
A flaw was found in KubeVirt Containerized Data Importer (CDI)
CVSS Base8.5
â
CRSSelect profile
CVE-2026-24882
8.4
GnuPGMultiple Products
In GnuPG before 2
CVSS Base8.4
â
CRSSelect profile
CVE-2021-47902
8.2
ManagementMultiple Products
Testa Online Test Management System 3
CVSS Base8.2
â
CRSSelect profile
CVE-2025-55292
8.2
MeshtasticMultiple Products
Meshtastic is an open source mesh networking solution
CVSS Base8.2
â
CRSSelect profile
CVE-2026-24842
8.2
UnknownMultiple Products
node-tar,a Tar for Node
CVSS Base8.2
â
CRSSelect profile
CVE-2026-24490
8.1
MobSFMultiple Products
MobSF is a mobile application security testing tool used
CVSS Base8.1
â
CRSSelect profile
CVE-2026-24869
8.1
UnknownMultiple Products
Use-after-free in the Layout: Scrolling and Overflow component
CVSS Base8.1
â
CRSSelect profile
CVE-2026-24881
8.1
GnuPGMultiple Products
In GnuPG before 2
CVSS Base8.1
â
CRSSelect profile
CVE-2026-24741
8.1
ConvertXisMultiple Products
ConvertXis a self-hosted online file converter
CVSS Base8.1
â
CRSSelect profile
CVE-2025-40536
8.1
SolarWindsMultiple Products
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality
CVSS Base8.1
â
CRSSelect profile
CVE-2026-24840
8
DokployMultiple Products
Dokploy is a free, self-hostable Platform as a Service (PaaS)
CVSS Base8
â
CRSSelect profile
CVE-2026-21569
7.9
ThisMultiple Products
This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7
CVSS Base7.9
â
CRSSelect profile
CVE-2026-1284
7.8
ReleaseMultiple Products
An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Release SOLIDWORKS 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36952
7.8
IObitMultiple Products
IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36953
7.8
MiniToolMultiple Products
MiniTool ShadowMaker 3
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36957
7.8
PDFMultiple Products
PDF Complete 3
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36958
7.8
KiteMultiple Products
Kite 1
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36959
7.8
IDTMultiple Products
IDT PC Audio 1
CVSS Base7.8
â
CRSSelect profile
CVE-2025-41727
7.8
DeviceMultiple Products
A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access
CVSS Base7.8
â
CRSSelect profile
CVE-2026-0648
7.8
stemsMultiple Products
The vulnerability stems from an incorrect error-checking logic in the CreateCounter()Â function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_osek
CVSS Base7.8
â
CRSSelect profile
CVE-2026-24873
7.8
RinnegatamanteMultiple Products
Out-of-bounds Read vulnerability in Rinnegatamante lpp-vita
CVSS Base7.8
â
CRSSelect profile
CVE-2026-24875
7.8
yoyofr IntegerMultiple Products
Integer Overflow or Wraparound vulnerability in yoyofr modizer
CVSS Base7.8
â
CRSSelect profile
CVE-2025-33234
7.8
NVIDIAMultiple Products
NVIDIA runx contains a vulnerability where an attacker could cause a code injection
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36974
7.8
RealtekMultiple Products
Realtek Andrea RT Filters 1
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36975
7.8
StatusMultiple Products
EPSON Status Monitor 3 version 8
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36976
7.8
RegistrationMultiple Products
Acer Global Registration Service 1
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36977
7.8
ElevationServiceMultiple Products
Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36979
7.8
ServiceMultiple Products
Atheros Coex Service Application 8
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36980
7.8
SAntivirusMultiple Products
SAntivirus IC 10
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36981
7.8
DeviceMultiple Products
Motorola Device Manager 2
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36982
7.8
DeviceMultiple Products
Motorola Device Manager 2
CVSS Base7.8
â
CRSSelect profile
CVE-2020-36983
7.8
FTPMultiple Products
Quick 'n Easy FTP Service 3
CVSS Base7.8
â
CRSSelect profile
CVE-2025-67274
7.5
issueMultiple Products
An issue in continuous
CVSS Base7.5
â
CRSSelect profile
CVE-2026-23864
7.5
ReactMultiple Products
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack
CVSS Base7.5
â
CRSSelect profile
CVE-2026-21720
7.5
EveryMultiple Products
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image
CVSS Base7.5
â
CRSSelect profile
CVE-2026-24827
7.5
gerstrongMultiple Products
Out-of-bounds Write vulnerability in gerstrong Commander-Genius
CVSS Base7.5
â
CRSSelect profile
CVE-2026-24828
7.5
Missing Release ofMultiple Products
Missing Release of Memory after Effective Lifetime vulnerability in Is-Daouda is-Engine
CVSS Base7.5
â
CRSSelect profile
CVE-2020-36939
7.5
CassandraMultiple Products
Cassandra Web 0
CVSS Base7.5
â
CRSSelect profile
CVE-2020-36946
7.5
SyncBreezeMultiple Products
SyncBreeze 10
CVSS Base7.5
â
CRSSelect profile
CVE-2026-24831
7.5
LoopMultiple Products
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1
CVSS Base7.5
â
CRSSelect profile
CVE-2026-22258
7.5
NSMMultiple Products
Suricata is a network IDS, IPS and NSM engine
CVSS Base7.5
â
CRSSelect profile
CVE-2026-22259
7.5
NSMMultiple Products
Suricata is a network IDS, IPS and NSM engine
CVSS Base7.5
â
CRSSelect profile
CVE-2026-22260
7.5
NSMMultiple Products
Suricata is a network IDS, IPS and NSM engine
CVSS Base7.5
â
CRSSelect profile
CVE-2026-24783
7.5
UnknownMultiple Products
soroban-fixed-point-math is a fixed-point math library for Soroban smart contacts
CVSS Base7.5
â
CRSSelect profile
CVE-2025-40537
7.5
SolarWindsMultiple Products
SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions
CVSS Base7.5
â
CRSSelect profile
CVE-2026-22264
7.4
NSMMultiple Products
Suricata is a network IDS, IPS and NSM engine
CVSS Base7.4
â
CRSSelect profile
CVE-2026-1443
7.3
MusicMultiple Products
A flaw has been found in code-projects Online Music Site 1
CVSS Base7.3
â
CRSSelect profile
CVE-2026-1449
7.3
flawMultiple Products
A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113
CVSS Base7.3
â
CRSSelect profile
CVE-2026-1448
7.2
D-LinkMultiple Products
A vulnerability was detected in D-Link DIR-615 up to 4
CVSS Base7.2
â
CRSSelect profile
CVE-2026-24478
7.2
AnythingLLMMultiple Products
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting
CVSS Base7.2
â
CRSSelect profile
CVE-2026-1505
7.2
D-LinkMultiple Products
A vulnerability was found in D-Link DIR-615 4
CVSS Base7.2
â
CRSSelect profile
CVE-2026-1506
7.2
D-LinkMultiple Products
A vulnerability was determined in D-Link DIR-615 4
CVSS Base7.2
â
CRSSelect profile
CVE-2020-36947
7.1
LibreNMSMultiple Products
LibreNMS 1
CVSS Base7.1
â
CRSSelect profile
CVE-2026-24779
7.1
servingMultiple Products
vLLM is an inference and serving engine for large language models (LLMs)