Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dedecms CRITICAL 9.8
CVE-2026-30643

An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.

Fix: after 5.7.118
Fix from $2,300 2026-04-01
Smart Software Manager On Prem CRITICAL 9.8
CVE-2026-20160

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands o…

Fix: 9-202601+
Fix from $2,300 2026-04-01
Unclassified CRITICAL 9.8
CVE-2026-20093

A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker …

Mitigation only
Fix from $2,300 2026-04-01
Jeecg Boot CRITICAL 9.8
CVE-2024-43028

A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a cra…

Fix: after 3.5.3
Fix from $2,300 2026-04-01
Jeecg Boot CRITICAL 9.8
CVE-2024-40489

There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary…

Fix: after 3.5.3
Fix from $2,300 2026-04-01
A3600r Firmware CRITICAL 9.8
CVE-2026-31027

TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerab…

Mitigation only
Fix from $2,300 2026-04-01
Deerflow CRITICAL 9.6
CVE-2026-34430

ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arb…

Fix: 2026-03-29+
Fix from $2,300 2026-04-01
Metinfo CRITICAL 9.8
CVE-2026-29014EPSS 39%

MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary …

Mitigation only
Fix from $2,300 2026-04-01
Juju CRITICAL 10.0
CVE-2026-4370

A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster f…

Fix: 3.6.20 / 4.0.5+
Fix from $2,300 2026-04-01
Simple Laundry System CRITICAL 9.8
CVE-2026-5257

A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /delstaffinfo.php o…

Mitigation only
Fix from $2,300 2026-04-01
Simple Laundry System CRITICAL 9.8
CVE-2026-5256

A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modify.php of the component Pa…

Mitigation only
Fix from $2,300 2026-04-01
Unclassified CRITICAL 9.1
CVE-2025-15484

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthent…

Mitigation only
Fix from $2,300 2026-04-01
Chrome CRITICAL 9.6
CVE-2026-5290

Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentia…

Fix: 146.0.7680.177+
Fix from $2,300 2026-04-01
Chrome CRITICAL 9.6
CVE-2026-5289

Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potential…

Fix: 146.0.7680.177+
Fix from $2,300 2026-04-01
Chrome CRITICAL 9.6
CVE-2026-5288

Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to p…

Fix: 146.0.7680.177+
Fix from $2,300 2026-04-01
Connext Professional CRITICAL 9.1
CVE-2026-4374

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing …

Fix: 7.3.1.1 / 7.7.0+
Fix from $2,300 2026-04-01
Xenforo CRITICAL 9.8
CVE-2025-71281

XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-wor…

Fix: 2.3.7+
Fix from $2,300 2026-04-01
Xenforo CRITICAL 9.8
CVE-2025-71279

XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the se…

Fix: 2.3.7+
Fix from $2,300 2026-04-01
Siyuan CRITICAL 9.6
CVE-2026-34449

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop …

Fix: 3.6.2+
Fix from $2,300 2026-03-31
Siyuan CRITICAL 9.0
CVE-2026-34448

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field …

Fix: 3.6.2+
Fix from $2,300 2026-03-31
Alerta CRITICAL 9.8
CVE-2026-34400

Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, …

Fix: 9.1.0+
Fix from $2,300 2026-03-31
Autopilot CRITICAL 9.8
CVE-2026-1579

The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any m…

No fix yet
Fix from $2,300 2026-03-31
Lodash CRITICAL 9.8
CVE-2026-4800

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but di…

Fix: 4.18.0+
Fix from $2,300 2026-03-31
Zora CRITICAL 9.8
CVE-2026-30285

An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the fil…

Mitigation only
Fix from $2,300 2026-03-31
Unclassified CRITICAL 9.3
CVE-2026-3356

The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management…

Mitigation only
Fix from $2,300 2026-03-31
Zefiro CRITICAL 9.8
CVE-2026-30286

An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via t…

Mitigation only
Fix from $2,300 2026-03-31
Animal Sounds And Ringtones CRITICAL 9.8
CVE-2026-30283

An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal fi…

Mitigation only
Fix from $2,300 2026-03-31
Cast To Tv CRITICAL 9.0
CVE-2026-30282

An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files vi…

Mitigation only
Fix from $2,300 2026-03-31
Fly Is Fun CRITICAL 9.8
CVE-2026-30278

An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file…

Mitigation only
Fix from $2,300 2026-03-31
Hl7 Fhir Core CRITICAL 9.3
CVE-2026-34361

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator H…

Fix: 6.9.4+
Fix from $2,300 2026-03-31