Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-9559

A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw …

Mitigation only
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41277

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41276

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41275

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41274

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41273

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and R…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41272

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41270

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.8
CVE-2025-41269

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W…

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Wf 500 Firmware CRITICAL 9.1
CVE-2025-41268

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 …

Fix: after 7.9.1.0_r2502171040
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-9558

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox…

Mitigation only
Fix from $2,300 2026-05-29
Wave 7 Firmware CRITICAL 9.8
CVE-2026-49201

The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify…

Mitigation only
Fix from $2,300 2026-05-29
Wave 7 Firmware CRITICAL 9.8
CVE-2026-49200

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentia…

Mitigation only
Fix from $2,300 2026-05-29
Predator Connect W6x Firmware CRITICAL 9.8
CVE-2026-49199

Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device.

Mitigation only
Fix from $2,300 2026-05-29
Predator Connect W6x Firmware CRITICAL 9.8
CVE-2026-49197

Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fai…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-3655

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-8732EPSS 22%

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6…

Mitigation only
Fix from $2,300 2026-05-29
Chrome CRITICAL 9.6
CVE-2026-9967

Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted H…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome CRITICAL 9.6
CVE-2026-9918

Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome CRITICAL 9.0
CVE-2026-9891

Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome CRITICAL 9.6
CVE-2026-9886

Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafte…

Fix: 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome CRITICAL 9.0
CVE-2026-9881

Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension…

Fix: 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome CRITICAL 9.6
CVE-2026-9876

Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome CRITICAL 9.6
CVE-2026-9875

Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via…

Fix: 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome CRITICAL 9.6
CVE-2026-9874

Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Fix: 148.0.7778.215 / 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome CRITICAL 9.6
CVE-2026-9872

Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via …

Fix: 148.0.7778.216+
Fix from $2,300 2026-05-28
Unclassified CRITICAL 9.8
CVE-2026-8809

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and inclu…

Mitigation only
Fix from $2,300 2026-05-28
Portainer CRITICAL 9.9
CVE-2026-44881

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…

Fix: 2.33.8 / 2.39.2+
Fix from $2,300 2026-05-28
Scadabr CRITICAL 9.9
CVE-2026-9645

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabli…

Mitigation only
Fix from $2,300 2026-05-28
Rest Data Services CRITICAL 10.0
CVE-2026-46840

Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploit…

Fix: after 26.1.0
Fix from $2,300 2026-05-28