Vulnerability index

Browse CVEs

4,950 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Unclassified MEDIUM 6.3
CVE-2026-3680

A security flaw has been discovered in RyuzakiShinji biome-mcp-server up to 1.0.0. Affected by this issue is some unknown functionality of the file b…

Patch available
Fix from $1,600 2026-03-07
Unclassified MEDIUM 6.3
CVE-2026-3672

A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /jeecg-boot/sys/api/getDictItem…

Mitigation only
Fix from $1,600 2026-03-07
Caddy HIGH 7.5
CVE-2026-30852

Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 …

Fix: 2.11.2+
Fix from $1,950 2026-03-07
Backstage Plugin Techdocs Node CRITICAL 9.8
CVE-2026-29186

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arb…

Fix: 1.14.3+
Fix from $2,300 2026-03-07
Wl Nu516u1 Firmware HIGH 7.2
CVE-2026-3662EPSS 18%

A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the file /cgi-bin/adm.cgi. Such mani…

No fix yet
Fix from $1,950 2026-03-07
Wl Nu516u1 Firmware HIGH 7.2
CVE-2026-3661EPSS 17%

A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.cgi. This manipulation of the …

No fix yet
Fix from $1,950 2026-03-07
Tinyweb HIGH 8.2
CVE-2026-29046

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them i…

Fix: 2.04+
Fix from $1,950 2026-03-06
Unclassified MEDIUM 6.3
CVE-2026-3616

A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unknown function of the file /modu…

Patch available
Fix from $1,600 2026-03-06
Wl Nu516u1 Firmware HIGH 7.2
CVE-2026-3612EPSS 13%

A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA …

No fix yet
Fix from $1,950 2026-03-06
Ghost CRITICAL 9.8
CVE-2026-29053

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the s…

Fix: 6.19.1+
Fix from $2,300 2026-03-05
Hono MEDIUM 6.5
CVE-2026-29085

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming He…

Fix: 4.12.4+
Fix from $1,600 2026-03-04
Open Ondemand CRITICAL 9.8
CVE-2026-26002

Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible…

Fix: 3.1.16 / 4.0.9+
Fix from $2,300 2026-03-04
Langsmith HIGH 8.1
CVE-2026-25750

Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter…

Fix: 0.12.71+
Fix from $1,950 2026-03-04
College Management System HIGH 7.2
CVE-2026-3487

A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/class-result.p…

No fix yet
Fix from $1,950 2026-03-03
College Management System HIGH 7.2
CVE-2026-3486

A vulnerability has been found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /admin/student-fee.…

No fix yet
Fix from $1,950 2026-03-03
Mcp Nmap Server HIGH 8.8
CVE-2026-3484

A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function…

Fix: after 1.0.1
Fix from $1,950 2026-03-03
University Management System CRITICAL 9.8
CVE-2026-3413

A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php…

Mitigation only
Fix from $2,300 2026-03-02
Society Management System CRITICAL 9.8
CVE-2026-3410

A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mitigation only
Fix from $2,300 2026-03-02
University Management System CRITICAL 9.8
CVE-2026-3411

A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of …

Mitigation only
Fix from $2,300 2026-03-02
Unclassified HIGH 7.3
CVE-2026-3409

A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the fi…

Mitigation only
Fix from $1,950 2026-03-02
Online Art Gallery Shop CRITICAL 9.8
CVE-2026-3406

A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.p…

Mitigation only
Fix from $2,300 2026-03-02
Maxsite Cms CRITICAL 9.8
CVE-2026-3395

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/previe…

Fix: 109.2+
Fix from $2,300 2026-03-01
Youlai Mall CRITICAL 9.8
CVE-2026-3287

A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/m…

Mitigation only
Fix from $2,300 2026-02-27
Jizhicms HIGH 8.8
CVE-2026-3292

A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the compon…

Fix: after 2.5.6
Fix from $1,950 2026-02-27
School Management System CRITICAL 9.8
CVE-2026-3261

A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component…

Mitigation only
Fix from $2,300 2026-02-26
Storybook CRITICAL 9.6
CVE-2026-27148

Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10…

Fix: 7.6.23 / 8.6.17+
Fix from $2,300 2026-02-25
Unclassified HIGH 7.3
CVE-2026-3200

A vulnerability was identified in z-9527 admin 1.0/2.0. The affected element is the function checkName/register/login/getUser/getUsers of the file /s…

Mitigation only
Fix from $1,950 2026-02-25
Mchange Commons Java CRITICAL 9.8
CVE-2026-27727

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including suppo…

Fix: 0.4.0+
Fix from $2,300 2026-02-25
News Portal Project CRITICAL 9.8
CVE-2026-3164

A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The m…

Mitigation only
Fix from $2,300 2026-02-25
College Management System CRITICAL 9.8
CVE-2026-3151

A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The…

Mitigation only
Fix from $2,300 2026-02-25