📅 Weekly CVE Roundup

January 26 - February 1, 2026

36 Total CVEs
0 Critical
13 High
21 Medium

🔴 Critical & High Severity Vulnerabilities

These are the most dangerous vulnerabilities disclosed this week. Prioritize patching these.

CVE-2026-25253 8.8

OpenClaw (also known as clawdbot or Moltbot) versions before 2026.1.29 automatically establish WebSocket connections using gatewayUrl values from quer...

Feb 1
CVE-2021-47909 8.1

Mult-E-Cart Ultimate 2.4 contains SQL injection vulnerabilities in multiple modules (inventory, customer, vendor, order) where attackers with vendor o...

Feb 1
CVE-2021-47915 8.1

PHP Melody 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to execute arbitrary SQL com...

Feb 1
CVE-2021-47918 8.1

Simple CMS 2.1 contains a remote SQL injection vulnerability in the users module that allows authenticated attackers to execute arbitrary SQL commands...

Feb 1
CVE-2020-37037 7.8

CVE-2020-37037 is an unquoted service path vulnerability in Avast SecureLine VPN client that allows local attackers to execute arbitrary code with SYS...

Feb 1
CVE-2020-37045 7.8

CVE-2020-37045 is an unquoted service path vulnerability in Veritas NetBackup 7.0's INET Daemon service. This allows local attackers to place maliciou...

Feb 1
CVE-2020-37047 7.8

CVE-2020-37047 is an unquoted service path vulnerability in Deep Instinct Windows Agent that allows local attackers to execute arbitrary code with Loc...

Feb 1
CVE-2020-37048 7.8

CVE-2020-37048 is an unquoted service path vulnerability in Iskysoft Application Framework Service that allows local attackers to execute arbitrary co...

Feb 1
CVE-2020-37055 7.8

CVE-2020-37055 is an unquoted service path vulnerability in SpyHunter 4 that allows local attackers to execute arbitrary code with SYSTEM privileges. ...

Feb 1
CVE-2020-37061 7.8

CVE-2020-37061 is an unquoted service path vulnerability in BOOTP Turbo 2.0.1214 that allows local attackers to execute arbitrary code with SYSTEM pri...

Feb 1
CVE-2020-37062 7.8

CVE-2020-37062 is an unquoted service path vulnerability in DHCP Turbo that allows local attackers to execute arbitrary code with elevated privileges....

Feb 1
CVE-2020-37063 7.8

CVE-2020-37063 is an unquoted service path vulnerability in TFTP Turbo that allows local attackers to execute arbitrary code with elevated SYSTEM priv...

Feb 1
CVE-2020-37064 7.8

CVE-2020-37064 is an unquoted service path vulnerability in EPSON EasyMP Network Projection software that allows local attackers to execute arbitrary ...

Feb 1

🏢 Most Affected Vendors

Openjsf 1 CVEs

🐛 Common Vulnerability Types

CWE-79 17 occurrences
CWE-428 9 occurrences
CWE-89 3 occurrences
CWE-22 3 occurrences
CWE-266 1 occurrences

📋 All CVEs This Week

CVE-2026-25253 8.8

OpenClaw (also known as clawdbot or Moltbot) versions before 2026.1.29 automatically establish WebSocket connections usi...

CVE-2021-47909 8.1

Mult-E-Cart Ultimate 2.4 contains SQL injection vulnerabilities in multiple modules (inventory, customer, vendor, order)...

CVE-2021-47915 8.1

PHP Melody 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attacker...

CVE-2021-47918 8.1

Simple CMS 2.1 contains a remote SQL injection vulnerability in the users module that allows authenticated attackers to ...

CVE-2020-37037 7.8

CVE-2020-37037 is an unquoted service path vulnerability in Avast SecureLine VPN client that allows local attackers to e...

CVE-2020-37045 7.8

CVE-2020-37045 is an unquoted service path vulnerability in Veritas NetBackup 7.0's INET Daemon service. This allows loc...

CVE-2020-37047 7.8

CVE-2020-37047 is an unquoted service path vulnerability in Deep Instinct Windows Agent that allows local attackers to e...

CVE-2020-37048 7.8

CVE-2020-37048 is an unquoted service path vulnerability in Iskysoft Application Framework Service that allows local att...

CVE-2020-37055 7.8

CVE-2020-37055 is an unquoted service path vulnerability in SpyHunter 4 that allows local attackers to execute arbitrary...

CVE-2020-37061 7.8

CVE-2020-37061 is an unquoted service path vulnerability in BOOTP Turbo 2.0.1214 that allows local attackers to execute ...

CVE-2020-37062 7.8

CVE-2020-37062 is an unquoted service path vulnerability in DHCP Turbo that allows local attackers to execute arbitrary ...

CVE-2020-37063 7.8

CVE-2020-37063 is an unquoted service path vulnerability in TFTP Turbo that allows local attackers to execute arbitrary ...

CVE-2020-37064 7.8

CVE-2020-37064 is an unquoted service path vulnerability in EPSON EasyMP Network Projection software that allows local a...

CVE-2021-47921 6.5

Free Photo & Video Vault 0.0.2 contains a directory traversal vulnerability that allows remote attackers to manipulate w...

CVE-2022-50950 6.5

Webile 1.0.1 contains an unauthenticated directory traversal vulnerability that allows attackers to manipulate file path...

CVE-2021-47856 6.4

Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword...

CVE-2021-47885 6.4

Multiple payment terminal versions contain non-persistent cross-site scripting (XSS) vulnerabilities in billing and paym...

CVE-2021-47908 6.4

Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows atta...

CVE-2021-47912 6.4

PHP Melody 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user imp...

CVE-2021-47913 6.4

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor's WYSIWYG component. Privile...

CVE-2021-47914 6.4

PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that a...

CVE-2021-47917 6.4

Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote atta...

CVE-2021-47919 6.4

Simple CMS 2.1 contains a reflected cross-site scripting vulnerability in the preview.php file's id parameter. Attackers...

CVE-2022-50797 6.4

The Stripe Green Downloads WordPress plugin version 2.03 contains a persistent cross-site scripting (XSS) vulnerability ...

CVE-2022-50940 6.4

Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting (XSS) vulnerability in the name parameter. Atta...

CVE-2022-50941 6.4

BootCommerce 3.2.1 contains persistent cross-site scripting (XSS) vulnerabilities in guest order checkout input fields. ...

CVE-2022-50951 6.4

WiFi File Transfer 1.0.8 has a persistent cross-site scripting vulnerability where attackers can inject malicious JavaSc...

CVE-2022-50952 6.4

Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the profile nam...

CVE-2023-54343 6.4

QWE DL 2.0.1 mobile web application has a persistent cross-site scripting (XSS) vulnerability in path parameters that al...

CVE-2025-50537 5.5

A stack overflow vulnerability in ESLint versions before 9.26.0 allows denial of service when processing test cases with...

CVE-2021-47911 5.4

Affiliate Pro 1.7 contains reflected cross-site scripting vulnerabilities in index module input fields (fullname, userna...

CVE-2021-47920 5.4

WebMO Job Manager 20.0 contains a reflected cross-site scripting vulnerability in search parameters that allows attacker...

CVE-2022-50942 5.4

CVE-2022-50942 is a client-side cross-site scripting vulnerability in Icinga Web 2.8.2 that allows attackers to inject m...

CVE-2026-1733 4.3

This CVE describes an improper authorization vulnerability in Zhong Bang CRMEB's store integration API endpoint. Attacke...

CVE-2026-25069 N/A

SunFounder Pironman Dashboard versions 1.3.13 and earlier contain an unauthenticated path traversal vulnerability in log...

CVE-2021-47916 N/A

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority, meaning it does not represent a valid securit...

📚 Past Roundups