Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

80,425 CVEs

CVEs (80,425, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 401–425 of 80,425 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-26216 CRITICAL Patched 10.0 2026-02-12 Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python…
CVE-2025-64075 CRITICAL 10.0 2026-02-11 A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perfor…
CVE-2026-25632 CRITICAL Patched 10.0 2026-02-06 EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s RES…
CVE-2026-25641 CRITICAL Patched 10.0 2026-02-06 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch between the key on which the validation is performe…
CVE-2026-25520 CRITICAL Patched 10.0 2026-02-06 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.values/Object.entries can be used to get an Array conta…
CVE-2026-25586 CRITICAL Patched 10.0 2026-02-06 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype whitel…
CVE-2026-25587 CRITICAL Patched 10.0 2026-02-06 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By overwriting Map.prototype.h…
CVE-2026-25725 CRITICAL Patched 10.0 2026-02-06 Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configurat…
CVE-2025-68121 CRITICAL Patched 10.0 2026-02-05 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the r…
CVE-2025-59818 CRITICAL Patched 10.0 2026-02-04 This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.
CVE-2026-1633 CRITICAL 10.0 2026-02-04 The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify …
CVE-2025-10878 CRITICAL Patched 10.0 2026-02-03 A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerable to …
CVE-2025-70841 CRITICAL 10.0 2026-02-03 Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /s…
CVE-2026-25142 CRITICAL Patched 10.0 2026-02-02 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can be use…
CVE-2026-1699 CRITICAL Patched 10.0 2026-01-30 In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrust…
CVE-2026-24729 NONE Patched — 2026-01-30 An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to e…
CVE-2026-24054 CRITICAL Patched 10.0 2026-01-29 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.2…
CVE-2026-24897 CRITICAL Patched 10.0 2026-01-28 Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified locat…
CVE-2025-57792 CRITICAL Patched 10.0 2026-01-28 Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application endpoint. An attacker ca…
CVE-2026-23830 CRITICAL Patched 10.0 2026-01-28 SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. T…
CVE-2025-14988 NONE — 2026-01-27 A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integ…
CVE-2026-24871 NONE Patched — 2026-01-27 Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects Minecraft-Rcon-Manage: before 3.0.
CVE-2026-24826 NONE — 2026-01-27 Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability in cadaver turso3d.This …
CVE-2026-24823 NONE — 2026-01-27 Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in FASTSHIFT X-TRACK (Software/X-Track/USER/App/Utils/lv_img_png/P…
CVE-2026-24816 NONE — 2026-01-27 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in datavane tis (tis-console/src/main/java/com/qlangtech/tis/runtime/module/action modules). This vulne…