Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ask Expert Script CRITICAL 9.8
CVE-2019-25676

Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code…

Mitigation only
Fix from $2,300 2026-04-05
Cmssite CRITICAL 9.8
CVE-2019-25674

CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug…

Mitigation only
Fix from $2,300 2026-04-05
Agenticseek CRITICAL 9.8
CVE-2026-5584

A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py…

Mitigation only
Fix from $2,300 2026-04-05
Hi Led Wr120 G2 Firmware CRITICAL 9.1
CVE-2026-5574

A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBr…

No fix yet
Fix from $2,300 2026-04-05
Hi Led Wr120 G2 Firmware CRITICAL 9.8
CVE-2026-5573

A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipul…

Mitigation only
Fix from $2,300 2026-04-05
Hi Led Wr120 G2 Firmware CRITICAL 9.8
CVE-2026-5570

A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginC…

Mitigation only
Fix from $2,300 2026-04-05
Hi Led Wr120 G2 Firmware CRITICAL 9.8
CVE-2026-5569

A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the componen…

Mitigation only
Fix from $2,300 2026-04-05
Ui CRITICAL 9.8
CVE-2026-5562

A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutio…

Fix: after 0.7.2
Fix from $2,300 2026-04-05
4g03 Pro Firmware CRITICAL 9.8
CVE-2026-5526

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionali…

Mitigation only
Fix from $2,300 2026-04-04
Nico Ftp CRITICAL 9.8
CVE-2018-25254

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sen…

Fix: after 3.0.1.19
Fix from $2,300 2026-04-04
Snews CRITICAL 9.8
CVE-2016-20052

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP execut…

Fix: after 1.7
Fix from $2,300 2026-04-04
Forticlientems CRITICAL 9.8
CVE-2026-35616 KEVEPSS 91%

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized …

Patch available
Fix from $2,300 2026-04-04
Praisonai CRITICAL 10.0
CVE-2026-34955

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.r…

Fix: 4.5.97+
Fix from $2,300 2026-04-04
Electron CRITICAL 9.8
CVE-2026-34775

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and…

Fix: 38.8.6 / 39.8.4+
Fix from $2,300 2026-04-04
Praisonai CRITICAL 9.1
CVE-2026-34953

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal …

Fix: 4.5.97+
Fix from $2,300 2026-04-03
Praisonai CRITICAL 9.1
CVE-2026-34952

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent …

Fix: 4.5.97+
Fix from $2,300 2026-04-03
Praisonaiagents CRITICAL 10.0
CVE-2026-34938EPSS 14%

PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-l…

Fix: 1.5.90+
Fix from $2,300 2026-04-03
Praisonaiagents CRITICAL 9.8
CVE-2026-34937

PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-c…

Fix: 1.5.90+
Fix from $2,300 2026-04-03
Praisonai CRITICAL 9.8
CVE-2026-34935

PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and…

Fix: 4.5.69+
Fix from $2,300 2026-04-03
Praisonai CRITICAL 9.8
CVE-2026-34934

PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with u…

Fix: 4.5.90+
Fix from $2,300 2026-04-03
Kestra CRITICAL 9.0
CVE-2026-34612

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Inje…

Fix: 1.3.7+
Fix from $2,300 2026-04-03
Unclassified CRITICAL 9.1
CVE-2021-4477

Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connecti…

Mitigation only
Fix from $2,300 2026-04-03
Unclassified CRITICAL 9.8
CVE-2018-25236

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the…

Mitigation only
Fix from $2,300 2026-04-03
Icx35 Hwc Firmware CRITICAL 9.8
CVE-2017-20236

ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows…

Fix: 1.3+
Fix from $2,300 2026-04-03
Icx35 Hwc Firmware CRITICAL 9.8
CVE-2017-20235

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that al…

Fix: 1.3+
Fix from $2,300 2026-04-03
Unclassified CRITICAL 9.8
CVE-2017-20234

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthoriz…

Mitigation only
Fix from $2,300 2026-04-03
Piwigo CRITICAL 9.8
CVE-2026-27634

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max…

Fix: 16.3.0+
Fix from $2,300 2026-04-03
Unclassified CRITICAL 9.8
CVE-2018-25237

Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication …

Mitigation only
Fix from $2,300 2026-04-03
Athena Odbc CRITICAL 9.8
CVE-2026-35561

Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow …

Fix: 2.1.0.0+
Fix from $2,300 2026-04-03
Unclassified CRITICAL 9.8
CVE-2017-20237

Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allow…

Mitigation only
Fix from $2,300 2026-04-03