Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Accounting System CRITICAL 9.8
CVE-2026-5035

A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Param…

Mitigation only
Fix from $2,300 2026-03-29
Accounting System CRITICAL 9.8
CVE-2026-5034

A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of …

Mitigation only
Fix from $2,300 2026-03-29
Accounting System CRITICAL 9.8
CVE-2026-5033

A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_cos…

Mitigation only
Fix from $2,300 2026-03-29
Nr1800x Firmware CRITICAL 9.8
CVE-2026-5030

A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecg…

Mitigation only
Fix from $2,300 2026-03-29
A3600r Firmware CRITICAL 9.8
CVE-2026-5020

A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cste…

Mitigation only
Fix from $2,300 2026-03-29
Grid\ CRITICAL 9.8
CVE-2026-4851

GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Ca…

Fix: after 0.127
Fix from $2,300 2026-03-29
Simple Food Order System CRITICAL 9.8
CVE-2026-5019

A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality …

Mitigation only
Fix from $2,300 2026-03-29
Simple Food Order System CRITICAL 9.8
CVE-2026-5018

A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the …

Mitigation only
Fix from $2,300 2026-03-28
Simple Food Order System CRITICAL 9.8
CVE-2026-5017

A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of t…

Mitigation only
Fix from $2,300 2026-03-28
Http\ CRITICAL 9.8
CVE-2026-3256

HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::S…

Fix: after 0.53
Fix from $2,300 2026-03-28
Amon2 CRITICAL 9.8
CVE-2025-15604

Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.06 through 6.16, the random_s…

Fix: 6.17+
Fix from $2,300 2026-03-28
Crashmail Ii CRITICAL 9.8
CVE-2018-25223

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input …

Fix: after 1.6
Fix from $2,300 2026-03-28
Easy Chat Server CRITICAL 9.8
CVE-2018-25221

EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplyin…

Fix: after 3.1
Fix from $2,300 2026-03-28
Bochs CRITICAL 9.8
CVE-2018-25220

Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input stri…

Mitigation only
Fix from $2,300 2026-03-28
Mawk CRITICAL 9.8
CVE-2017-20229

MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate…

Fix: after 1.3.3-17
Fix from $2,300 2026-03-28
Jad Java Decompiler CRITICAL 9.8
CVE-2017-20227

JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by s…

Mitigation only
Fix from $2,300 2026-03-28
Tiemu CRITICAL 9.8
CVE-2017-20225

TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate bo…

Fix: after 2.0.8
Fix from $2,300 2026-03-28
Jad Java Decompiler CRITICAL 9.8
CVE-2016-20049

JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversiz…

Mitigation only
Fix from $2,300 2026-03-28
Timeprovider 4100 Firmware CRITICAL 9.8
CVE-2025-9497

Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider …

Fix: 2.5.0+
Fix from $2,300 2026-03-28
Locutus CRITICAL 9.8
CVE-2026-33994

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25,…

Fix: 3.0.25+
Fix from $2,300 2026-03-27
Locutus CRITICAL 9.8
CVE-2026-33993

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function i…

Fix: 3.0.25+
Fix from $2,300 2026-03-27
Notesnook Desktop CRITICAL 9.6
CVE-2026-33976

Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can …

Fix: 3.3.11 / 3.3.17+
Fix from $2,300 2026-03-27
Happy Dom CRITICAL 9.8
CVE-2026-33943

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection …

Fix: 20.8.8+
Fix from $2,300 2026-03-27
Handlebars CRITICAL 9.8
CVE-2026-33937

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-…

Fix: 4.7.9+
Fix from $2,300 2026-03-27
Forge CRITICAL 9.1
CVE-2026-33896

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificate…

Fix: after 1.3.3
Fix from $2,300 2026-03-27
Federated Learning And Interoperability Platform CRITICAL 9.8
CVE-2026-33879

Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models…

Fix: 0.1.1+
Fix from $2,300 2026-03-27
Authenticator CRITICAL 9.3
CVE-2026-33875

Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authenticatio…

Fix: 4.16.0+
Fix from $2,300 2026-03-27
Langflow CRITICAL 9.9
CVE-2026-33873

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow exec…

Fix: 1.9.0+
Fix from $2,300 2026-03-27
Varnish Enterprise CRITICAL 9.8
CVE-2026-34475

Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/…

Fix: 8.0.1+
Fix from $2,300 2026-03-27
Unclassified CRITICAL 9.6
CVE-2026-34205

Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured w…

Mitigation only
Fix from $2,300 2026-03-27