🛡️ CVE Vulnerability Database
CVE vulnerabilities with bilingual AI analysis tailored for Saudi Arabia
| CVE ID | Title / Description | Severity | CVSS | Status | Published |
|---|---|---|---|---|---|
| CVE-2026-23515 |
Critical Command Injection Vulnerability in Signal K Server (CVE-…
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a comm…
|
CRITICAL |
9.9
|
⚡ ✅ AI | Feb 2, 2026 |
| CVE-2026-1281 |
Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote Code…
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability — Ivanti Endpoint Manager Mobile …
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 29, 2026 |
| CVE-2026-24897 |
Critical Path Traversal Vulnerability in Erugo File-Sharing Platf…
Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticat…
|
CRITICAL |
10.0
|
⚡ ✅ AI | Jan 28, 2026 |
| CVE-2026-24858 |
Critical Authentication Bypass Vulnerability in Fortinet Multiple…
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability — …
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 27, 2026 |
| CVE-2026-24736 |
Critical SSRF Vulnerability in Squidex CMS Webhook Configuration …
Squidex is an open source headless content management system and content management hub. Versions of…
|
CRITICAL |
9.1
|
⚡ ✅ AI | Jan 27, 2026 |
| CVE-2026-24061 |
GNU InetUtils Telnetd Argument Injection Vulnerability - Remote A…
GNU InetUtils Argument Injection Vulnerability — GNU InetUtils contains an argument injection vulner…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 26, 2026 |
| CVE-2026-23760 |
SmarterTools SmarterMail Critical Authentication Bypass Vulnerabi…
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability — Sm…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 26, 2026 |
| CVE-2026-21509 |
CVE-2026-21509: Microsoft Office Security Feature Bypass Vulnerab…
Microsoft Office Security Feature Bypass Vulnerability — Microsoft Office contains a security featur…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 26, 2026 |
| CVE-2025-52691 |
SmarterTools SmarterMail Critical Unrestricted File Upload Vulner…
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability — SmarterTool…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 26, 2026 |
| CVE-2018-14634 |
Linux Kernel Integer Overflow Privilege Escalation Vulnerability …
Linux Kernel Integer Overflow Vulnerability — Linux Kernel contains an integer overflow vulnerabilit…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 26, 2026 |
| CVE-2024-37079 |
Broadcom VMware vCenter Server Out-of-Bounds Write Vulnerability …
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability — Broadcom VMware vCenter Server co…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 23, 2026 |
| CVE-2025-68645 |
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusio…
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability — Synacor Zimbra Co…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 22, 2026 |
| CVE-2025-54313 |
Prettier eslint-config-prettier Embedded Malicious Code Vulnerabi…
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability — Prettier eslint-config-prett…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 22, 2026 |
| CVE-2025-34026 |
Versa Concerto SD-WAN Improper Authentication Vulnerability (CVE-…
Versa Concerto Improper Authentication Vulnerability — Versa Concerto SD-WAN orchestration platform …
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 22, 2026 |
| CVE-2025-31125 |
Vite Vitejs Improper Access Control Vulnerability (CVE-2025-31125…
Vite Vitejs Improper Access Control Vulnerability — Vite Vitejs contains an improper access control …
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 22, 2026 |
| CVE-2026-20045 |
Cisco Unified Communications Products Critical Code Injection Vul…
Cisco Unified Communications Products Code Injection Vulnerability — Cisco Unified Communications Ma…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 21, 2026 |
| CVE-2025-53912 |
CVE-2025-53912: Critical Arbitrary File Read Vulnerability in Med…
An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Pr…
|
CRITICAL |
9.6
|
⚡ ✅ AI | Jan 20, 2026 |
| CVE-2026-23523 |
Critical Code Injection in Dive MCP Host via Malicious Deeplink C…
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling L…
|
CRITICAL |
9.6
|
⚡ ✅ AI | Jan 16, 2026 |
| CVE-2026-23520 |
Critical Command Injection Vulnerability in Arcane Docker Managem…
Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the upd…
|
CRITICAL |
9.0
|
⚡ ✅ AI | Jan 15, 2026 |
| CVE-2026-20805 |
CVE-2026-20805: Microsoft Windows Desktop Window Manager Critical…
Microsoft Windows Information Disclosure Vulnerability — Microsoft Windows Desktop Windows Manager c…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 13, 2026 |
| CVE-2026-22794 |
CVE-2026-22794: Origin Header Injection Leading to Account Takeov…
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the ser…
|
CRITICAL |
9.6
|
⚡ ✅ AI | Jan 12, 2026 |
| CVE-2025-8110 |
Gogs Path Traversal Vulnerability Leading to Remote Code Executio…
Gogs Path Traversal Vulnerability — Gogs contains a path traversal vulnerability affecting improper …
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 12, 2026 |
| CVE-2026-22688 |
Critical Command Injection Vulnerability in Tencent WeKnora LLM F…
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval.…
|
CRITICAL |
9.9
|
⚡ ✅ AI | Jan 10, 2026 |
| CVE-2025-69222 |
LibreChat SSRF Vulnerability Allows Internal Network Access via A…
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side r…
|
CRITICAL |
9.1
|
⚡ ✅ AI | Jan 7, 2026 |
| CVE-2025-37164 |
HPE OneView Critical Code Injection Vulnerability Enabling Remote…
Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability — Hewlett Packard Enterprise (…
|
CRITICAL |
9.0
|
⚡ ✅ KEV AI | Jan 7, 2026 |