Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-9406

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the…

Mitigation only
Fix from $2,300 2026-05-25
Unclassified CRITICAL 9.8
CVE-2026-9405

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.c…

Mitigation only
Fix from $2,300 2026-05-25
Unclassified CRITICAL 9.8
CVE-2026-9404

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the …

Mitigation only
Fix from $2,300 2026-05-24
Unclassified CRITICAL 9.8
CVE-2026-9388

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cste…

Mitigation only
Fix from $2,300 2026-05-24
Unclassified CRITICAL 9.8
CVE-2026-9387

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/c…

Mitigation only
Fix from $2,300 2026-05-24
Unclassified CRITICAL 9.8
CVE-2026-9386

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of t…

Mitigation only
Fix from $2,300 2026-05-24
Unclassified CRITICAL 9.8
CVE-2026-9385

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $2,300 2026-05-24
Unclassified CRITICAL 9.8
CVE-2026-9384

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstec…

Mitigation only
Fix from $2,300 2026-05-24
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2018-25357

Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PH…

Fix: after 7.0.3
Fix from $2,300 2026-05-23
Unclassified CRITICAL 9.8
CVE-2018-25350

userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requ…

Mitigation only
Fix from $2,300 2026-05-23
Azure Resource Manager CRITICAL 9.8
CVE-2026-47280

Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-05-22
Entra Id CRITICAL 10.0
CVE-2026-42901

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-22
365 Copilot CRITICAL 9.3
CVE-2026-41090

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t…

Mitigation only
Fix from $2,300 2026-05-22
Azure Orbital Spatio CRITICAL 9.8
CVE-2026-40412

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-22
Entra Id CRITICAL 9.8
CVE-2026-33843

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privilege…

Mitigation only
Fix from $2,300 2026-05-22
Power Pages CRITICAL 9.8
CVE-2026-23652

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu…

Mitigation only
Fix from $2,300 2026-05-22
Unclassified CRITICAL 9.3
CVE-2026-48700

An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileMa…

Mitigation only
Fix from $2,300 2026-05-22
Unclassified CRITICAL 10.0
CVE-2026-33712

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allo…

Mitigation only
Fix from $2,300 2026-05-22
Sunshine CRITICAL 9.8
CVE-2026-32253

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed…

Fix: 2026.516.143833+
Fix from $2,300 2026-05-22
Net CRITICAL 9.6
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--exampl…

Fix: 0.55.0+
Fix from $2,300 2026-05-22
Avantra CRITICAL 9.1
CVE-2026-8673

Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avan…

Fix: 25.3.0+
Fix from $2,300 2026-05-22
Avantra CRITICAL 9.6
CVE-2026-8670

Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This…

Fix: 25.3.1+
Fix from $2,300 2026-05-22
Cxf CRITICAL 9.8
CVE-2026-44930

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi…

Fix: 3.6.11 / 4.1.6+
Fix from $2,300 2026-05-22
Unclassified CRITICAL 9.2
CVE-2026-9054

An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.

Mitigation only
Fix from $2,300 2026-05-22
Crypto CRITICAL 10.0
CVE-2026-46595

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than pu…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-42508EPSS 7%

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are check…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39834

When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the w…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39833

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign …

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39831

The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence …

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39832

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destinatio…

Fix: 0.52.0+
Fix from $2,300 2026-05-22