| CVE-2026-22240 |
Plaintext Passwords Vulnerability in BLUVOYIX |
14.01.2026 |
10 |
| CVE-2026-22236 |
Improper Authentication Vulnerability in BLUVOYIX |
14.01.2026 |
10 |
| CVE-2026-22237 |
Exposed Internal API Documentation Vulnerability in BLUVOYIX |
14.01.2026 |
10 |
| CVE-2026-22238 |
Administrator Account Creation Vulnerability in BLUVOYIX |
14.01.2026 |
10 |
| CVE-2026-22239 |
Email Sending Vulnerability in BLUVOYIX |
14.01.2026 |
10 |
| CVE-2026-23550 |
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability |
14.01.2026 |
10 |
| CVE-2025-14301 |
Integration Opvius AI for WooCommerce <= 1.3.0 - Unauthenticated Arbitrary File Deletion/Read via Path Traversal |
14.01.2026 |
9.8 |
| CVE-2025-14502 |
News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion |
14.01.2026 |
9.8 |
| CVE-2026-22686 |
Sandbox Escape via Host Error Prototype Chain in enclave-vm |
14.01.2026 |
10 |
| CVE-2022-50893 |
VIAVIWEB Wallpaper Admin 1.0 - Code Execution via Image Upload |
14.01.2026 |
9.3 |
| CVE-2020-36911 |
Covenant 0.5 - Remote Code Execution (RCE) |
14.01.2026 |
9.3 |
| CVE-2022-50912 |
ImpressCMS 1.4.4 - Unrestricted File Upload |
14.01.2026 |
9.3 |
| CVE-2022-50919 |
Tdarr 2.00.15 - Command Injection |
14.01.2026 |
9.3 |
| CVE-2023-54329 |
Inbit Messenger 4.9.0 - Unauthenticated Remote Command Execution (RCE) |
14.01.2026 |
9.3 |
| CVE-2023-54330 |
Inbit Messenger 4.9.0 - Unauthenticated Remote SEH Overflow |
14.01.2026 |
9.3 |
| CVE-2023-54335 |
eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE) |
14.01.2026 |
9.3 |
| CVE-2023-54339 |
Webgrind 1.1 - Remote Command Execution (RCE) via dataFile Parameter |
14.01.2026 |
9.3 |
| CVE-2026-23478 |
Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback |
14.01.2026 |
10 |
| CVE-2025-68271 |
Unauthenticated Remote Code Execution in openc3-api |
13.01.2026 |
10 |
| CVE-2025-47855 |
|
14.01.2026 |
9.3 |
| CVE-2025-64155 |
|
14.01.2026 |
9.4 |
| CVE-2025-12548 |
Github.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333 |
13.01.2026 |
9 |
| CVE-2026-22755 |
Remote code injection via upload_map.cgi in Legacy Vivotek Devices |
13.01.2026 |
9.3 |
| CVE-2025-11250 |
Authentication Bypass |
13.01.2026 |
9.1 |
| CVE-2025-40805 |
|
13.01.2026 |
10 |
| CVE-2026-0491 |
Code Injection vulnerability in SAP Landscape Transformation |
14.01.2026 |
9.1 |
| CVE-2026-0498 |
Code Injection vulnerability in SAP S/4HANA (Private Cloud and On-Premise) |
14.01.2026 |
9.1 |
| CVE-2026-0500 |
Remote code execution in SAP Wily Introscope Enterprise Manager (WorkStation) |
13.01.2026 |
9.6 |
| CVE-2026-0501 |
SQL Injection Vulnerability in SAP S/4HANA Private Cloud and On-Premise (Financials � General Ledger) |
14.01.2026 |
9.9 |
| CVE-2026-22813 |
Malicious website can execute commands on the local system through XSS in the OpenCode web UI |
13.01.2026 |
9.4 |
| CVE-2026-22799 |
emlog Arbitrary File Upload Vulnerability |
13.01.2026 |
9.3 |
| CVE-2026-22794 |
Account Takeover Vulnerability in Appsmith |
13.01.2026 |
9.7 |
| CVE-2025-12420 |
Unauthenticated Privilege Escalation in ServiceNow AI Platform |
14.01.2026 |
9.3 |
| CVE-2026-22785 |
orval MCP client is vulnerable to a code injection attack. |
12.01.2026 |
9.3 |
| CVE-2026-22781 |
TinyWeb CGI Command Injection |
12.01.2026 |
10 |
| CVE-2026-22783 |
Iris Allows Arbitrary File Deletion via Mass Assignment in Datastore File Management |
12.01.2026 |
9.6 |
| CVE-2026-22252 |
LibreChat MCP Stdio Remote Command Execution |
12.01.2026 |
9.1 |
| CVE-2025-41006 |
Multiple vulnerabilities in Imaster products Open configuration options |
12.01.2026 |
9.3 |
| CVE-2025-52694 |
Execution of arbitrary SQL commands |
12.01.2026 |
10 |
| CVE-2026-22688 |
WeKnora has Command Injection in MCP stdio test |
12.01.2026 |
10 |
| CVE-2025-65091 |
XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONService |
12.01.2026 |
10 |
| CVE-2025-61686 |
React Router has Path Traversal in File Session Storage |
10.01.2026 |
9.1 |
| CVE-2026-22600 |
OpenProject is Vulnerable to Arbitrary File Read via ImageMagick SVG Coder |
13.01.2026 |
9.1 |
| CVE-2025-15501 |
Sangfor Operation and Maintenance Management System getCmd WriterHandle.getCmd os command injection |
12.01.2026 |
9.3 |
| CVE-2025-15500 |
Sangfor Operation and Maintenance Management System HTTP POST Request getHis os command injection |
09.01.2026 |
9.3 |
| CVE-2020-36875 |
AccessAlly < 3.3.2 Unauthenticated Arbitrary PHP Code Execution |
09.01.2026 |
9.3 |
| CVE-2025-69425 |
Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded Tokens RCE |
09.01.2026 |
10 |
| CVE-2025-69426 |
Ruckus vRIoT IoT Controller < 3.0.0.0 Hardcoded SSH Credentials RCE |
09.01.2026 |
10 |
| CVE-2025-66050 |
No password set for administrative account in Vivotek IP7137 cameras |
09.01.2026 |
9.3 |
| CVE-2025-7072 |
Hardcoded credentials in KAON CG3000T/CG3000CT routers |
09.01.2026 |
9.3 |
| CVE-2025-64093 |
Unauthenticated Remote Code Execution via the device hostname |
09.01.2026 |
10 |
| CVE-2025-64090 |
Authenticated Remote Code Execution in device hostname |
09.01.2026 |
10 |
| CVE-2025-14741 |
Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element |
09.01.2026 |
9.1 |
| CVE-2025-70974 |
|
09.01.2026 |
10 |
| CVE-2025-14736 |
Frontend Admin by DynamiApps <= 3.28.25 - Unauthenticated Privilege Escalation to Administrator via Role Form Field |
09.01.2026 |
9.8 |
| CVE-2026-22234 |
OPEXUS eCasePortal unauthenticated IDOR |
08.01.2026 |
9.3 |
| CVE-2025-59468 |
|
09.01.2026 |
9 |
| CVE-2025-59469 |
|
09.01.2026 |
9 |
| CVE-2025-59470 |
|
09.01.2026 |
9 |