Skip to main content

Year archive

CVEs published in 2026

Archive summary

51,717 CVEs published in 2026 — 5,740 Critical, 20,749 High, 20,177 Medium, 4,050 Low, 1,001 Unrated.

CVE-2023-54334

Published Jan 13, 2026

Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploi…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-54333

Published Jan 13, 2026

Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attackers to manipulate database queries. Attackers can exploit…

CVSS 8.8 · High

CVE-2023-54332

Published Jan 13, 2026

Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers ca…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-54331

Published Jan 13, 2026

Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can expl…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-54330

Published Jan 13, 2026

Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malfo…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-54329

Published Jan 13, 2026

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-54328

Published Jan 13, 2026

AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes application crashes. Attackers can generate a 7000-byte payload…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-53985

Published Jan 13, 2026

Zstore, now referred to as Zippy CRM, 6.5.4 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts through unvalidated input par…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-53984

Published Jan 13, 2026

Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with sys…

CVSS 8.5 · High

CVE-2022-50939

Published Jan 13, 2026

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files through path traversal. The vulner…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50938

Published Jan 13, 2026

CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted…

CVSS 8.5 · High

CVE-2022-50937

Published Jan 13, 2026

Ametys CMS v4.4.1 contains a persistent cross-site scripting vulnerability in the link directory's input fields for external links. Attackers can inject malicious script code in l…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-50936

Published Jan 13, 2026

WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated atta…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50935

Published Jan 13, 2026

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\In…

CVSS 8.5 · High

CVE-2022-50933

Published Jan 13, 2026

Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploi…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50932

Published Jan 13, 2026

Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file pat…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50931

Published Jan 13, 2026

TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. Attackers can replace system e…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50930

Published Jan 13, 2026

Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows local users to potentially execute code with elevated privi…

CVSS 8.5 · High

CVE-2022-50929

Published Jan 13, 2026

Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows local attackers to potentially execute arbitrary code. Atta…

CVSS 8.5 · High

CVE-2022-50928

Published Jan 13, 2026

BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attack…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50927

Published Jan 13, 2026

Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can…

CVSS 8.5 · High

CVE-2022-50926

Published Jan 13, 2026

WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's…

CVSS 8.7 · High

CVE-2022-50925

Published Jan 13, 2026

Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attacker…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50924

Published Jan 13, 2026

Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attacker…

CVSS 8.5 · High

CVE-2022-50923

Published Jan 13, 2026

Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the unqu…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort
Showing 50,076-50,100 of 51,717 CVEsPage 2004 of 2069