Skip to main content

Year archive

CVEs published in 2026

Archive summary

43,028 CVEs published in 2026 — 4,547 Critical, 17,084 High, 17,306 Medium, 3,588 Low, 503 Unrated.

CVE-2021-47880

Published Jan 21, 2026

Realtek Wireless LAN Utility 700.1631 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attacker…

CVSS 8.5 · High

CVE-2021-47879

Published Jan 21, 2026

eBeam Interactive Suite 3.6 contains an unquoted service path vulnerability in the eBeam Stylus Driver service that allows local users to potentially execute code with elevated pr…

CVSS 8.5 · High

CVE-2021-47878

Published Jan 21, 2026

eBeam Education Suite 2.5.0.9 contains an unquoted service path vulnerability in the eBeam Device Service that allows local users to potentially execute code with elevated privile…

CVSS 8.5 · High

CVE-2021-47877

Published Jan 21, 2026

GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer. Attackers can ge…

CVSS 6.7 · Medium

CVE-2021-47876

Published Jan 21, 2026

GeoGebra Classic 5.0.631.0-d contains a denial of service vulnerability in the input field that allows attackers to crash the application by sending oversized buffer content. Atta…

CVSS 6.7 · Medium

CVE-2021-47875

Published Jan 21, 2026

GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can cr…

CVSS 4.6 · Medium

CVE-2021-47874

Published Jan 21, 2026

VFS for Git 1.0.21014.1 contains an unquoted service path vulnerability in the GVFS.Service Windows service that allows local attackers to execute code with elevated privileges. A…

CVSS 8.5 · High

CVE-2021-47873

Published Jan 21, 2026

VestaCP versions prior to 0.9.8-25 contain a cross-site scripting vulnerability in the IP interface configuration that allows attackers to inject malicious scripts. Attackers can…

CVSS 5.1 · Medium

CVE-2021-47872

Published Jan 21, 2026

SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through th…

CVSS 7.0 · High

CVE-2021-47871

Published Jan 21, 2026

Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write files to arbitrary locations using the API index.php endpoin…

CVSS 8.6 · High

CVE-2021-47870

Published Jan 21, 2026

GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47869

Published Jan 21, 2026

Brother BRAdmin Professional 3.75 contains an unquoted service path vulnerability in the BRA_Scheduler service that allows local users to potentially execute arbitrary code. Attac…

CVSS 8.5 · High

CVE-2021-47868

Published Jan 21, 2026

WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in the WPCommandFileService that allows local users to potentially execute code with elevated privileges. Attacker…

CVSS 8.5 · High

CVE-2021-47867

Published Jan 21, 2026

WIN-PACK PRO4.8 contains an unquoted service path vulnerability in the ScheduleService that allows local users to potentially execute code with elevated system privileges. Attacke…

CVSS 8.5 · High

CVE-2021-47866

Published Jan 21, 2026

WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in the GuardTourService that allows local users to potentially execute code with elevated system privileges. Attac…

CVSS 8.5 · High

CVE-2021-47865

Published Jan 21, 2026

ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly…

CVSS 8.7 · High

CVE-2021-47864

Published Jan 21, 2026

OSAS Traverse Extension 11 contains an unquoted service path vulnerability in the TravExtensionHostSvc service running with LocalSystem privileges. Attackers can exploit the unquo…

CVSS 8.5 · High

CVE-2021-47863

Published Jan 21, 2026

MacPaw Encrypto 1.0.1 contains an unquoted service path vulnerability in its Encrypto Service configuration that allows local attackers to potentially execute arbitrary code. Atta…

CVSS 8.5 · High

CVE-2021-47862

Published Jan 21, 2026

Hi-Rez Studios 5.1.6.3 contains an unquoted service path vulnerability in the HiPatchService that allows local attackers to execute code with elevated privileges. Attackers can ex…

CVSS 8.5 · High

CVE-2021-47861

Published Jan 21, 2026

Event Log Explorer 4.9.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers c…

CVSS 8.5 · High

CVE-2021-47860

Published Jan 21, 2026

GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attackers to inject arbitrary client-side code into administrato…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47859

Published Jan 21, 2026

ActivIdentity 8.2 contains an unquoted service path vulnerability in the ac.sharedstore service that allows local attackers to potentially execute arbitrary code. Attackers can ex…

CVSS 8.5 · High

CVE-2021-47858

Published Jan 21, 2026

Genexis Platinum-4410 P4410-V2-1.31A contains a stored cross-site scripting vulnerability in the 'start_addr' parameter of the Security Management interface. Attackers can inject…

CVSS 5.1 · Medium

CVE-2021-47857

Published Jan 21, 2026

Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows attackers to inject malicious scripts. Attackers can craft…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47855

Published Jan 21, 2026

Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can c…

CVSS 5.1 · Medium
Showing 40,376-40,400 of 43,028 CVEsPage 1616 of 1722