Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dolibarr Erp\/crm CRITICAL 9.1
CVE-2019-25710

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute…

Fix: after 8.0.4
Fix from $2,300 2026-04-12
Image Hosting Script CRITICAL 9.8
CVE-2019-25709

CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the …

Mitigation only
Fix from $2,300 2026-04-12
Cmssite CRITICAL 9.8
CVE-2019-25697

CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug…

Mitigation only
Fix from $2,300 2026-04-12
Unclassified CRITICAL 9.8
CVE-2026-6116

A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin…

Mitigation only
Fix from $2,300 2026-04-12
Unclassified CRITICAL 9.8
CVE-2026-6115

A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setAppCfg of the file /cgi-bin/cstecgi.cgi of the component…

Mitigation only
Fix from $2,300 2026-04-12
Unclassified CRITICAL 9.8
CVE-2026-6114

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cste…

Mitigation only
Fix from $2,300 2026-04-12
Unclassified CRITICAL 9.8
CVE-2026-6113

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTtyServiceCfg …

Mitigation only
Fix from $2,300 2026-04-12
Unclassified CRITICAL 9.8
CVE-2026-6112

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the…

Mitigation only
Fix from $2,300 2026-04-12
Metagpt CRITICAL 9.8
CVE-2026-6110

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.…

Patch available
Fix from $2,300 2026-04-12
Unclassified CRITICAL 9.3
CVE-2026-31845

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/…

Mitigation only
Fix from $2,300 2026-04-11
Unclassified CRITICAL 9.8
CVE-2026-5059

aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

Mitigation only
Fix from $2,300 2026-04-11
Unclassified CRITICAL 9.8
CVE-2026-5058

aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte…

Mitigation only
Fix from $2,300 2026-04-11
Era 300 Firmware CRITICAL 9.8
CVE-2026-4149

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary …

Fix: 83.1-61240+
Fix from $2,300 2026-04-11
Langsmith CRITICAL 9.8
CVE-2026-40190

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith)…

Fix: 0.5.18+
Fix from $2,300 2026-04-10
Goshs CRITICAL 9.8
CVE-2026-40189

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for direct…

Fix: 2.0.0+
Fix from $2,300 2026-04-10
Chartbrew CRITICAL 9.6
CVE-2026-30232

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartb…

Fix: 4.8.5+
Fix from $2,300 2026-04-10
Chamilo Lms CRITICAL 9.8
CVE-2026-33707

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email…

Fix: 1.11.38+
Fix from $2,300 2026-04-10
Chamilo Lms CRITICAL 9.8
CVE-2026-33698

Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ director…

Fix: 1.11.38+
Fix from $2,300 2026-04-10
Openshift Ai CRITICAL 9.9
CVE-2026-5483

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows…

Fix: 2.16.4 / 2.25.4+
Fix from $2,300 2026-04-10
Openclaw CRITICAL 9.1
CVE-2026-35652

OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows non-allowlisted senders to exec…

Fix: 2026.3.22+
Fix from $2,300 2026-04-10
Vikunja CRITICAL 9.1
CVE-2026-34727

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking wh…

Fix: 2.3.0+
Fix from $2,300 2026-04-10
Control M\/managed File Transfer CRITICAL 9.8
CVE-2026-23781

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the appl…

Fix: after 9.0.22
Fix from $2,300 2026-04-10
Engineers Online Portal CRITICAL 9.8
CVE-2026-36236

SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.

Mitigation only
Fix from $2,300 2026-04-10
Online Student Enrollment System CRITICAL 9.8
CVE-2026-36235

A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this is…

Mitigation only
Fix from $2,300 2026-04-10
Online Student Enrollment System CRITICAL 9.8
CVE-2026-36234

itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter.

Mitigation only
Fix from $2,300 2026-04-10
Online Student Enrollment System CRITICAL 9.8
CVE-2026-36233

A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason fo…

Mitigation only
Fix from $2,300 2026-04-10
Online Student Enrollment System CRITICAL 9.8
CVE-2026-36232

A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this …

Mitigation only
Fix from $2,300 2026-04-10
Unclassified CRITICAL 9.8
CVE-2026-29861

PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php.

Mitigation only
Fix from $2,300 2026-04-10
Unclassified CRITICAL 9.8
CVE-2025-44560

owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.

No fix yet
Fix from $2,300 2026-04-10
Netwide Assembler CRITICAL 9.6
CVE-2026-6068

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global d…

No fix yet
Fix from $2,300 2026-04-10