Vulnerability index

Browse CVEs

4,950 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
MEDIUM 6.3 CVE-2026-3680 A security flaw has been discovered in RyuzakiShinji biome-mcp-server up to 1.0.0. Affected by this issue is some unknown functionality of the file b… Patch available Fix from $1,6002026-03-07 MEDIUM 6.3 CVE-2026-3672 A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /jeecg-boot/sys/api/getDictItem… Mitigation only Fix from $1,6002026-03-07 HIGH 7.5 CVE-2026-30852 Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_regexp matcher in vars.go:337 … Caddy 2.11.2+ Fix from $1,9502026-03-07 CRITICAL 9.8 CVE-2026-29186 Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arb… Backstage Plugin Techdocs Node 1.14.3+ Fix from $2,3002026-03-07 HIGH 7.2 CVE-2026-3662EPSS 18% A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the file /cgi-bin/adm.cgi. Such mani… Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-03-07 HIGH 7.2 CVE-2026-3661EPSS 17% A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.cgi. This manipulation of the … Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-03-07 HIGH 8.2 CVE-2026-29046 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them i… Tinyweb 2.04+ Fix from $1,9502026-03-06 MEDIUM 6.3 CVE-2026-3616 A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unknown function of the file /modu… Patch available Fix from $1,6002026-03-06 HIGH 7.2 CVE-2026-3612EPSS 13% A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/adm.cgi of the component OTA … Wl Nu516u1 Firmware No fix yet Fix from $1,9502026-03-06 CRITICAL 9.8 CVE-2026-29053 Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the s… Ghost 6.19.1+ Fix from $2,3002026-03-05 MEDIUM 6.5 CVE-2026-29085 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming He… Hono 4.12.4+ Fix from $1,6002026-03-04 CRITICAL 9.8 CVE-2026-26002 Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible… Open Ondemand 3.1.16 / 4.0.9+ Fix from $2,3002026-03-04 HIGH 8.1 CVE-2026-25750 Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter… Langsmith 0.12.71+ Fix from $1,9502026-03-04 HIGH 7.2 CVE-2026-3487 A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/class-result.p… College Management System No fix yet Fix from $1,9502026-03-03 HIGH 7.2 CVE-2026-3486 A vulnerability has been found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /admin/student-fee.… College Management System No fix yet Fix from $1,9502026-03-03 HIGH 8.8 CVE-2026-3484 A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function… Mcp Nmap Server after 1.0.1 Fix from $1,9502026-03-03 CRITICAL 9.8 CVE-2026-3413 A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php… University Management System Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3410 A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file … Society Management System Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3411 A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of … University Management System Mitigation only Fix from $2,3002026-03-02 HIGH 7.3 CVE-2026-3409 A security flaw has been discovered in eosphoros-ai db-gpt 0.7.5. Affected is the function importlib.machinery.SourceFileLoader.exec_module of the fi… Mitigation only Fix from $1,9502026-03-02 CRITICAL 9.8 CVE-2026-3406 A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.p… Online Art Gallery Shop Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3395 A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/previe… Maxsite Cms 109.2+ Fix from $2,3002026-03-01 CRITICAL 9.8 CVE-2026-3287 A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/m… Youlai Mall Mitigation only Fix from $2,3002026-02-27 HIGH 8.8 CVE-2026-3292 A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the compon… Jizhicms after 2.5.6 Fix from $1,9502026-02-27 CRITICAL 9.8 CVE-2026-3261 A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component… School Management System Mitigation only Fix from $2,3002026-02-26 CRITICAL 9.6 CVE-2026-27148 Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10… Storybook 7.6.23 / 8.6.17+ Fix from $2,3002026-02-25 HIGH 7.3 CVE-2026-3200 A vulnerability was identified in z-9527 admin 1.0/2.0. The affected element is the function checkName/register/login/getUser/getUsers of the file /s… Mitigation only Fix from $1,9502026-02-25 CRITICAL 9.8 CVE-2026-27727 mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including suppo… Mchange Commons Java 0.4.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3164 A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The m… News Portal Project Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3151 A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The… College Management System Mitigation only Fix from $2,3002026-02-25