8341 Total CVEs
3167 AI Analyzed
136 CISA KEV
1637 Critical
All Vendors
Showing 1-50 of 8341 CVEs
IRFANVIEW-CADIMAGE-MULTIPLE
Analyzed
7.8
IrfanView CADImage Plugin

Multiple memory corruption vulnerabilities in IrfanView CADImage plugin affecting CGM, DXF, and DWG file parsing. All 139 vulnerabilities have CVSS 7....

2025-07-22
INVT-VTDESIGNER-MULTIPLE
Analyzed
7.8
Intel VT-Designer

Multiple memory corruption vulnerabilities in INVT VT-Designer affecting PM3 project file parsing. All 9 vulnerabilities have CVSS 7.8 and allow remot...

2025-07-22
CVE-2026-25615
7.2
Blesta Multiple Products

Blesta 3

2026-02-04
CVE-2026-25614
7.5
Blesta Multiple Products

Blesta 3

2026-02-04
CVE-2026-25510
Analyzed
9.9
HP CMS Skeleton

An authenticated user with file editor permissions in CI4MS can achieve Remote Code Execution (RCE) by uploading and executing arbitrary PHP code via...

2026-02-04
CVE-2026-25503
7.1
Unknown Multiple Products

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles

2026-02-04
CVE-2026-25502
7.8
Unknown Multiple Products

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles

2026-02-04
CVE-2026-25253
Analyzed
8.8
OpenClaw Multiple Products

OpenClaw (aka clawdbot or Moltbot) before 2026

2026-02-02
CVE-2026-25223
7.5
Unknown Multiple Products

Fastify is a fast and low overhead web framework, for Node

2026-02-04
CVE-2026-25202
Analyzed
9.8
Samsung Multiple Products

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects Ma...

2026-02-02
CVE-2026-25201
Analyzed
8.8
Samsung Multiple Products

An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server

2026-02-02
CVE-2026-25200
Analyzed
9.8
Samsung Multiple Products

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in a...

2026-02-02
CVE-2026-25156
7.3
HotCRP Multiple Products

HotCRP is conference review software

2026-01-31
CVE-2026-25153
7.7
Unknown Multiple Products

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node

2026-01-31
CVE-2026-25150
Analyzed
9.3
Builder.io Qwik City

A prototype pollution vulnerability in the Qwik City middleware's formToObj() function allows unauthenticated attackers to manipulate Object.prototype...

2026-02-04
CVE-2026-25142
Analyzed
10
Docker Multiple Products

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain protot...

2026-02-03
CVE-2026-25137
Analyzed
9.1
Unknown Multiple Products

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the d...

2026-02-03
CVE-2026-25130
Analyzed
9.6
F5 Multiple Products

Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple...

2026-01-31
CVE-2026-25128
7.5
Unknown Multiple Products

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback

2026-01-31
CVE-2026-25126
7.1
PolarLearn Multiple Products

PolarLearn is a free and open-source learning program

2026-01-30
CVE-2026-25116
7.6
Runtipi Multiple Products

Runtipi is a personal homeserver orchestrator

2026-01-30
CVE-2026-25060
Analyzed
8.1
OpenList Multiple Products

OpenList Frontend is a UI component for OpenList

2026-02-03
CVE-2026-25059
Analyzed
8.8
OpenList Multiple Products

OpenList Frontend is a UI component for OpenList

2026-02-03
CVE-2026-25022
8.5
Iqonic Design Multiple Products

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-managemen...

2026-02-04
CVE-2026-24954
8.8
Unknown Multiple Products

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection

2026-02-04
CVE-2026-24902
Analyzed
7.1
Unknown Multiple Products

TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0

2026-01-30
CVE-2026-24897
Analyzed
10
HP Multiple Products

Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files...

2026-01-29
CVE-2026-24882
8.4
GnuPG Multiple Products

In GnuPG before 2

2026-01-28
CVE-2026-24881
8.1
GnuPG Multiple Products

In GnuPG before 2

2026-01-28
CVE-2026-24875
7.8
Unknown Multiple Products

Integer Overflow or Wraparound vulnerability in yoyofr modizer

2026-01-28
CVE-2026-24874
9.1
Unknown Multiple Products

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2...

2026-01-28
CVE-2026-24873
7.8
Rinnegatamante Multiple Products

Out-of-bounds Read vulnerability in Rinnegatamante lpp-vita

2026-01-28
CVE-2026-24872
9.8
Unknown Multiple Products

improper pointer arithmetic vulnerability in ProjectSkyfire SkyFire_548.This issue affects SkyFire_548: before 5.4.8-stable5.

2026-01-28
CVE-2026-24869
8.1
Unknown Multiple Products

Use-after-free in the Layout: Scrolling and Overflow component

2026-01-28
CVE-2026-24868
7.5
Mitigation Multiple Products

Mitigation bypass in the Privacy: Anti-Tracking component

2026-01-29
CVE-2026-24858
KEV
9.8
Apple Multiple Products

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Forti...

2026-01-28
CVE-2026-24856
7.8
Unknown Multiple Products

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles

2026-01-29
CVE-2026-24854
Analyzed
8.8
ChurchCRM Multiple Products

ChurchCRM is an open-source church management system

2026-01-31
CVE-2026-24842
8.2
Unknown Multiple Products

node-tar,a Tar for Node

2026-01-28
CVE-2026-24841
Analyzed
9.9
Docker Multiple Products

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokpl...

2026-01-28
CVE-2026-24840
8
Dokploy Multiple Products

Dokploy is a free, self-hostable Platform as a Service (PaaS)

2026-01-28
CVE-2026-24838
Analyzed
9.1
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, m...

2026-01-28
CVE-2026-24837
Analyzed
7.6
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem

2026-01-28
CVE-2026-24836
Analyzed
7.6
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem

2026-01-28
CVE-2026-24833
Analyzed
7.6
Microsoft Multiple Products

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem

2026-01-28
CVE-2026-24832
9.8
Unknown Multiple Products

Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

2026-01-28
CVE-2026-24831
7.5
Loop Multiple Products

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ixray-team ixray-1

2026-01-28
CVE-2026-24830
9.8
Unknown Multiple Products

Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.

2026-01-28
CVE-2026-24828
7.5
Unknown Multiple Products

Missing Release of Memory after Effective Lifetime vulnerability in Is-Daouda is-Engine

2026-01-28
CVE-2026-24827
7.5
Unknown Multiple Products

Out-of-bounds Write vulnerability in gerstrong Commander-Genius

2026-01-28