🛡️ CVE Vulnerability Database
CVE vulnerabilities with bilingual AI analysis tailored for Saudi Arabia
| CVE ID | Title / Description | Severity | CVSS | Status | Published |
|---|---|---|---|---|---|
| CVE-2026-0785 |
ALGO 8180 IP Audio Alerter API Command Injection Remote Code Exec…
ALGO 8180 IP Audio Alerter API Command Injection Remote Code Execution Vulnerability. This vulnerabi…
|
HIGH |
8.8
|
✅ | Jan 23, 2026 |
| CVE-2026-0784 |
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code E…
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulner…
|
HIGH |
8.8
|
✅ | Jan 23, 2026 |
| CVE-2026-0783 |
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code E…
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulner…
|
HIGH |
8.8
|
✅ | Jan 23, 2026 |
| CVE-2026-0782 |
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code E…
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulner…
|
HIGH |
8.8
|
✅ | Jan 23, 2026 |
| CVE-2026-0781 |
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code E…
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulner…
|
HIGH |
8.8
|
✅ | Jan 23, 2026 |
| CVE-2026-0780 |
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code E…
ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulner…
|
HIGH |
8.8
|
✅ | Jan 23, 2026 |
| CVE-2026-0779 |
ALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Exe…
ALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution Vulnerability. This vulnerab…
|
HIGH |
8.8
|
✅ | Jan 23, 2026 |
| CVE-2025-11002 |
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution …
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability a…
|
HIGH |
7.8
|
✅ | Jan 23, 2026 |
| CVE-2025-67684 |
Quick.Cart is vulnerable to Local File Inclusion and Path Travers…
Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection me…
|
HIGH |
7.2
|
✅ | Jan 22, 2026 |
| CVE-2021-47770 |
OpenPLC v3 contains an authenticated remote code execution vulner…
OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with …
|
HIGH |
8.8
|
✅ | Jan 21, 2026 |
| CVE-2025-12957 |
The All-in-One Video Gallery plugin for WordPress is vulnerable t…
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all vers…
|
HIGH |
8.8
|
✅ | Jan 16, 2026 |
| CVE-2021-47794 |
ZesleCP 3.1.9 contains an authenticated remote code execution vul…
ZesleCP 3.1.9 contains an authenticated remote code execution vulnerability that allows attackers to…
|
HIGH |
8.8
|
⚡ ✅ | Jan 16, 2026 |
| CVE-2025-13062 |
The Supreme Modules Lite plugin for WordPress is vulnerable to ar…
The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions…
|
HIGH |
8.8
|
✅ | Jan 15, 2026 |
| CVE-2021-47758 |
Chikitsa Patient Management System 2.0.2 contains an authenticate…
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerabili…
|
HIGH |
8.8
|
⚡ ✅ | Jan 15, 2026 |
| CVE-2021-47757 |
Chikitsa Patient Management System 2.0.2 contains an authenticate…
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerabili…
|
HIGH |
8.8
|
⚡ ✅ | Jan 15, 2026 |
| CVE-2022-50936 |
WBCE CMS version 1.5.2 contains an authenticated remote code exec…
WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows att…
|
HIGH |
8.8
|
⚡ ✅ | Jan 13, 2026 |
| CVE-2022-50909 |
Algo 8028 Control Panel version 3.3.3 contains a command injectio…
Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua …
|
HIGH |
8.8
|
✅ | Jan 13, 2026 |
| CVE-2022-50907 |
e107 CMS version 3.2.1 contains a file upload vulnerability that …
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative…
|
HIGH |
7.2
|
⚡ ✅ | Jan 13, 2026 |
| CVE-2026-22799 |
Emlog is an open source website building system. emlog v2.6.1 and…
Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoin…
|
HIGH |
8.8
|
⚡ ✅ | Jan 12, 2026 |
| CVE-2026-22244 |
OpenMetadata Server-Side Template Injection Enables Remote Code E…
OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code …
|
HIGH |
7.2
|
⚡ ✅ AI | Jan 8, 2026 |
| CVE-2026-22241 |
Critical File Upload Vulnerability in Open eClass Platform Enable…
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Pr…
|
HIGH |
7.2
|
⚡ ✅ AI | Jan 8, 2026 |
| CVE-2026-22187 |
Bio-Formats Unsafe Java Deserialization Vulnerability in Memoizat…
Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-contr…
|
HIGH |
7.8
|
✅ AI | Jan 7, 2026 |
| CVE-2025-69262 |
Critical Command Injection in pnpm Package Manager via Environmen…
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability wh…
|
HIGH |
7.5
|
⚡ ✅ AI | Jan 7, 2026 |
| CVE-2025-15158 |
WP Enable WebP Plugin Arbitrary File Upload Vulnerability (CVE-20…
The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file…
|
HIGH |
8.8
|
✅ AI | Jan 7, 2026 |
| CVE-2025-14997 |
Critical File Deletion Vulnerability in BuddyPress Xprofile WordP…
The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file dele…
|
HIGH |
7.2
|
✅ AI | Jan 6, 2026 |