Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-70067

Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, w…

Mitigation only
Fix from $2,300 2026-05-04
Ollama CRITICAL 9.1
CVE-2026-7482

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied…

Fix: 0.17.1+
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.8
CVE-2026-7747

A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.8
CVE-2025-14320

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Tra…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.9
CVE-2026-29200

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows …

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.8
CVE-2026-7719

A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. The affected element is the function loginauth of the file /cgi-bin/cstec…

Mitigation only
Fix from $2,300 2026-05-04
Gv Vms Firmware CRITICAL 9.0
CVE-2026-7372

A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can l…

Fix: 21.0.0+
Fix from $2,300 2026-05-04
Gv Ip Device Utility CRITICAL 9.3
CVE-2026-7161

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broa…

Mitigation only
Fix from $2,300 2026-05-04
Gv Vms Firmware CRITICAL 9.8
CVE-2026-42370

A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can l…

Fix: 21.0.0+
Fix from $2,300 2026-05-04
Unclassified CRITICAL 10.0
CVE-2026-42369

GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other security devices. It is a native app…

Mitigation only
Fix from $2,300 2026-05-04
Gv Lpc2011 Firmware CRITICAL 9.9
CVE-2026-42368

A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request ca…

Mitigation only
Fix from $2,300 2026-05-04
Wl Wn570ha1 Firmware CRITICAL 9.8
CVE-2026-7690

A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. …

Mitigation only
Fix from $2,300 2026-05-03
Unclassified CRITICAL 9.8
CVE-2026-7458

The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This i…

Mitigation only
Fix from $2,300 2026-05-02
Unclassified CRITICAL 9.8
CVE-2026-4882

The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_A…

Mitigation only
Fix from $2,300 2026-05-02
Open Vehicle Monitoring System Firmware CRITICAL 10.0
CVE-2026-37541

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is n…

Mitigation only
Fix from $2,300 2026-05-01
Openamp CRITICAL 9.8
CVE-2026-37540

OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of tw…

Mitigation only
Fix from $2,300 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-37539

Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFr…

Mitigation only
Fix from $2,300 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-37534

Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Transport_Proto…

Mitigation only
Fix from $2,300 2026-05-01
Automotive Grade Linux CRITICAL 9.8
CVE-2026-37531

AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the …

Fix: after 17.1.12
Fix from $2,300 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-42473

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesyste…

Mitigation only
Fix from $2,300 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-42472

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the …

Mitigation only
Fix from $2,300 2026-05-01
Linux Kernel CRITICAL 9.8
CVE-2026-43039

In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix missing data copy and wrong recycle in ZC RX dispatch…

Fix: 6.19.12+
Fix from $2,300 2026-05-01
Linux Kernel CRITICAL 9.8
CVE-2026-43038

In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review …

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-05-01
Linux Kernel CRITICAL 9.8
CVE-2026-43037

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following …

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-05-01
Linux Kernel CRITICAL 9.8
CVE-2026-43011

In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-05-01
Hashcat CRITICAL 9.8
CVE-2026-42484

A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly …

Mitigation only
Fix from $2,300 2026-05-01
Hashcat CRITICAL 9.8
CVE-2026-42483

A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitr…

Mitigation only
Fix from $2,300 2026-05-01
Hashcat CRITICAL 9.8
CVE-2026-42482

A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a deni…

Mitigation only
Fix from $2,300 2026-05-01
Linux Kernel CRITICAL 9.8
CVE-2026-31718

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger When a du…

Fix: 6.7 / 6.12.84+
Fix from $2,300 2026-05-01
Linux Kernel CRITICAL 9.8
CVE-2026-31705

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment smb2_get_ea() appl…

Fix: 5.16 / 6.2+
Fix from $2,300 2026-05-01