Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2025-41008

SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'client'…

Mitigation only
Fix from $2,300 2026-03-23
Nebula300plus Firmware CRITICAL 9.8
CVE-2026-31851

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication int…

Fix: after 12.01.01.37
Fix from $2,300 2026-03-23
Nebula300plus Firmware CRITICAL 9.8
CVE-2026-31848

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential…

Fix: after 12.01.01.37
Fix from $2,300 2026-03-23
Unclassified CRITICAL 9.3
CVE-2025-41007

SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'search' parameter in th…

Mitigation only
Fix from $2,300 2026-03-23
Unclassified CRITICAL 9.8
CVE-2026-4585

A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy…

Mitigation only
Fix from $2,300 2026-03-23
Unclassified CRITICAL 9.8
CVE-2026-32968

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in …

Mitigation only
Fix from $2,300 2026-03-23
Simple Laundry System CRITICAL 9.8
CVE-2026-4581

A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the compone…

Mitigation only
Fix from $2,300 2026-03-23
Simple Laundry System CRITICAL 9.8
CVE-2026-4580

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php o…

Mitigation only
Fix from $2,300 2026-03-23
Simple Laundry System CRITICAL 9.8
CVE-2026-4579

A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the compon…

Mitigation only
Fix from $2,300 2026-03-23
Unclassified CRITICAL 10.0
CVE-2026-3587

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of …

Mitigation only
Fix from $2,300 2026-03-23
Jsrsasign CRITICAL 9.1
CVE-2026-4601

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in t…

Fix: 11.1.1+
Fix from $2,300 2026-03-23
Jsrsasign CRITICAL 9.1
CVE-2026-4600

Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter valid…

Fix: 11.1.1+
Fix from $2,300 2026-03-23
Jsrsasign CRITICAL 9.1
CVE-2026-4599

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigInteg…

Fix: 11.1.1+
Fix from $2,300 2026-03-23
A15 Firmware CRITICAL 9.8
CVE-2026-4567

A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulat…

Mitigation only
Fix from $2,300 2026-03-23
Unclassified CRITICAL 10.0
CVE-2026-4606

GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full cont…

Mitigation only
Fix from $2,300 2026-03-23
Freefloat Ftp Server CRITICAL 9.8
CVE-2019-25614

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sen…

Mitigation only
Fix from $2,300 2026-03-22
Openclaw CRITICAL 9.1
CVE-2026-32064

OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthen…

Fix: 2026.2.21+
Fix from $2,300 2026-03-21
Openclaw CRITICAL 9.8
CVE-2026-32056

OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attac…

Fix: 2026.2.22+
Fix from $2,300 2026-03-21
Openclaw CRITICAL 9.8
CVE-2026-32052

OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidde…

Fix: 2026.2.24+
Fix from $2,300 2026-03-21
Openclaw CRITICAL 9.9
CVE-2026-32048

OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to …

Fix: 2026.3.1+
Fix from $2,300 2026-03-21
Openclaw CRITICAL 9.8
CVE-2026-32046

OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by explo…

Fix: 2026.2.21+
Fix from $2,300 2026-03-21
Openclaw CRITICAL 9.1
CVE-2026-32045

OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and…

Fix: 2026.2.21+
Fix from $2,300 2026-03-21
Unclassified CRITICAL 9.1
CVE-2026-24060

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker…

Mitigation only
Fix from $2,300 2026-03-21
Flatted CRITICAL 9.8
CVE-2026-33228

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed …

Fix: 3.4.2+
Fix from $2,300 2026-03-20
Json CRITICAL 9.1
CVE-2026-33210

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnera…

Fix: 2.15.2.1 / 2.17.1.2+
Fix from $2,300 2026-03-20
Grpc CRITICAL 9.1
CVE-2026-33186

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of …

Fix: 1.79.3+
Fix from $2,300 2026-03-20
Eparking.fi CRITICAL 9.8
CVE-2026-29796

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-20
Charge Portal CRITICAL 9.8
CVE-2026-25192

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-20
Ddk CRITICAL 9.6
CVE-2026-21732

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU…

Fix: after 25.1
Fix from $2,300 2026-03-20
Unclassified CRITICAL 9.8
CVE-2026-3584EPSS 7%

The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' functio…

Mitigation only
Fix from $2,300 2026-03-20