Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-25345

Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.3
CVE-2026-25340

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-25035

Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-25032

Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.3…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-25031

Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from …

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-25030

Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-25029

Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.3
CVE-2026-24993

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Re…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-24989

Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliat…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-24971

Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-24968

Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a thro…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-24378

Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affec…

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-22507

Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through …

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.8
CVE-2026-22500

Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 …

Mitigation only
Fix from $2,300 2026-03-25
Unclassified CRITICAL 9.3
CVE-2026-22484

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL …

Mitigation only
Fix from $2,300 2026-03-25
Thumbler CRITICAL 9.8
CVE-2026-26833

thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is c…

Fix: after 1.1.2
Fix from $2,300 2026-03-25
Tesseract Ocr CRITICAL 9.8
CVE-2026-26832

node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in sr…

Fix: after 2.2.1
Fix from $2,300 2026-03-25
Textract CRITICAL 9.8
CVE-2026-26831

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious…

Fix: after 2.5.0
Fix from $2,300 2026-03-25
Pdf Image CRITICAL 9.8
CVE-2026-26830

pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructCon…

Fix: after 2.0.0
Fix from $2,300 2026-03-25
N2w CRITICAL 9.8
CVE-2025-59707

In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerabilit…

Fix: 4.3.2+
Fix from $2,300 2026-03-25
N2w CRITICAL 9.8
CVE-2025-59706

In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.

Fix: 4.3.2+
Fix from $2,300 2026-03-25
Backup\& Recovery CRITICAL 9.0
CVE-2025-32991

In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.

Fix: 4.3.2+
Fix from $2,300 2026-03-25
Simple Laundry System CRITICAL 9.8
CVE-2026-4784

A vulnerability was found in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /checkcheckout.php of the componen…

Mitigation only
Fix from $2,300 2026-03-25
Ipados CRITICAL 9.8
CVE-2026-28858

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause un…

Fix: 26.4+
Fix from $2,300 2026-03-25
macOS CRITICAL 9.3
CVE-2026-28827

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS So…

Fix: 14.8.5 / 15.7.5+
Fix from $2,300 2026-03-25
Ipados CRITICAL 9.3
CVE-2026-20688

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.…

Fix: 14.8.5 / 15.7.5+
Fix from $2,300 2026-03-25
Nemo CRITICAL 9.8
CVE-2026-24159

NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might le…

Fix: 2.6.2+
Fix from $2,300 2026-03-24
Nemo CRITICAL 9.8
CVE-2026-24157

NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of thi…

Fix: 2.6.2+
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.0
CVE-2025-33244

NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability aff…

Mitigation only
Fix from $2,300 2026-03-24
Pyload Ng CRITICAL 9.8
CVE-2026-33511

pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator i…

Fix: 0.5.0b3.dev97+
Fix from $2,300 2026-03-24