Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-7156

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the com…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7155

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPasswordCfg of the file /cgi-bi…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7154

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cg…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.4
CVE-2024-46636

NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category …

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7153

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7152

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecg…

Mitigation only
Fix from $2,300 2026-04-27
Mipc252w Firmware CRITICAL 9.8
CVE-2026-35903

MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Dige…

Mitigation only
Fix from $2,300 2026-04-27
Ac18 Firmware CRITICAL 9.8
CVE-2026-31255

A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where i…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7140

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the c…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7139

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of th…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7138

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg of the file /cgi-bin/cstecgi.…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7137

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cste…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7136

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-41462

ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is d…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-30352

A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitr…

Mitigation only
Fix from $2,300 2026-04-27
Smartermail CRITICAL 9.1
CVE-2026-40514

SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption wi…

Fix: 100.0.9610+
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7125

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cs…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7124

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7123

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the compon…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7122

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the …

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-7121

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the compone…

Mitigation only
Fix from $2,300 2026-04-27
Camel CRITICAL 10.0
CVE-2026-33453EPSS 6%

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's ca…

Fix: after 4.14.5
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.8
CVE-2026-22337

Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Socia…

Mitigation only
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.3
CVE-2026-22336

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This i…

Mitigation only
Fix from $2,300 2026-04-27
Mina CRITICAL 9.8
CVE-2026-41409

The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized …

Fix: 2.0.28 / 2.1.11+
Fix from $2,300 2026-04-27
Camel CRITICAL 9.4
CVE-2026-33454

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt…

Fix: 4.14.6 / 4.18.1+
Fix from $2,300 2026-04-27
Mina CRITICAL 9.8
CVE-2026-41635

Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at …

Fix: 2.0.28 / 2.1.11+
Fix from $2,300 2026-04-27
Camel CRITICAL 9.8
CVE-2026-40860

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa…

Fix: 4.14.7 / 4.18.2+
Fix from $2,300 2026-04-27
Camel CRITICAL 9.9
CVE-2026-40453

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable…

Fix: 4.14.6 / 4.18.2+
Fix from $2,300 2026-04-27
Unclassified CRITICAL 9.3
CVE-2026-42363

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broa…

Mitigation only
Fix from $2,300 2026-04-27