CVEDatabase.com Logo

SearchCVE Vulnerabilities withAI-Powered Remediation Guidance

Powerful Analysis Tools

Everything you need to secure your infrastructure

CVE Trends & Highlights

Timeframe:
#1
CVE-2025-40805
CRITICAL

Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthenticated remote attacker to ci...

Jan 13
10.0CVSS
#2
CVE-2026-23478
CRITICAL

Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attacke...

Jan 13
10.0CVSS
#3
CVE-2026-22237
CRITICAL

The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit thi...

Jan 14
10.0CVSS
#4
CVE-2026-21636
CRITICAL

A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even w...

Jan 20
10.0CVSS
#5
CVE-2025-4320
CRITICAL

Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technolog...

Jan 23
10.0CVSS
#6
CVE-2026-22236
CRITICAL

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit thi...

Jan 14
10.0CVSS
#7
CVE-2026-22238
CRITICAL

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this ...

Jan 14
10.0CVSS
#8
CVE-2025-52694
CRITICAL

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vul...

Jan 12
10.0CVSS
#9
CVE-2026-22781
CRITICAL

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via C...

Jan 12
10.0CVSS
#10
CVE-2026-24841
CRITICAL

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokpl...

Jan 28
9.9CVSS
#11
CVE-2026-22907
CRITICAL

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

Jan 15
9.9CVSS
#12
CVE-2026-24304
CRITICAL

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

Jan 23
9.9CVSS
#13
CVE-2026-0501
CRITICAL

Due to insufficient input validation in SAP S/4HANA Private Cloud and On-Premise (Financials General Ledger), an authenticated user could execute craf...

Jan 13
9.9CVSS
#14
CVE-2026-21969
CRITICAL

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal). The supporte...

Jan 20
9.8CVSS
#15
CVE-2025-15403
CRITICAL

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'ad...

Jan 17
9.8CVSS
#16
CVE-2025-14301
CRITICAL

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is du...

Jan 14
9.8CVSS
#17
CVE-2025-14894
CRITICAL

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME vali...

Jan 16
9.8CVSS
#18
CVE-2025-10484
CRITICAL

The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, a...

Jan 17
9.8CVSS
#19
CVE-2025-14533
CRITICAL

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is...

Jan 20
9.8CVSS
#20
CVE-2025-15521
CRITICAL

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeover...

Jan 21
9.8CVSS

Latest from the Blog

View All
NIST NVD • CISA KEV • EPSS