Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dir 820lw Firmware CRITICAL 9.8
CVE-2026-4499

A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can le…

Mitigation only
Fix from $2,300 2026-03-20
Wa300 Firmware CRITICAL 9.8
CVE-2026-4497

A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/c…

Mitigation only
Fix from $2,300 2026-03-20
MariaDB CRITICAL 9.9
CVE-2026-32710

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11…

Fix: 11.4.10 / 11.8.6+
Fix from $2,300 2026-03-20
Qunetswitch CRITICAL 9.8
CVE-2026-22901

A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: after 2.0.5.0906
Fix from $2,300 2026-03-20
Qunetswitch CRITICAL 9.8
CVE-2026-22900

A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gai…

Fix: 2.0.5.0906+
Fix from $2,300 2026-03-20
Qvr Pro CRITICAL 9.8
CVE-2026-22898

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerabi…

Fix: 2.7.4.1485+
Fix from $2,300 2026-03-20
Qunetswitch CRITICAL 9.8
CVE-2026-22897

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitra…

Fix: 2.0.4.0415+
Fix from $2,300 2026-03-20
Media Streaming Add On CRITICAL 9.1
CVE-2025-59383

A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify…

Fix: 500.1.1.0+
Fix from $2,300 2026-03-20
Archer Ax53 Firmware CRITICAL 9.8
CVE-2025-15608

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalid…

Mitigation only
Fix from $2,300 2026-03-20
Archer Ax53 Firmware CRITICAL 9.8
CVE-2025-15607

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbit…

Mitigation only
Fix from $2,300 2026-03-20
Openclaw CRITICAL 9.9
CVE-2026-22172

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password…

Fix: 2026.3.12+
Fix from $2,300 2026-03-20
Sysak CRITICAL 9.8
CVE-2024-44722

SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.

Fix: after 2.0
Fix from $2,300 2026-03-20
H3 CRITICAL 9.1
CVE-2026-33131

H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which exte…

No fix yet
Fix from $2,300 2026-03-20
H3 CRITICAL 10.0
CVE-2026-33128

H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent E…

Fix: 1.15.6+
Fix from $2,300 2026-03-20
Siyuan CRITICAL 9.0
CVE-2026-33067

SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template l…

Fix: 3.6.1+
Fix from $2,300 2026-03-20
Siyuan CRITICAL 9.0
CVE-2026-33066

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetS…

Fix: 3.6.1+
Fix from $2,300 2026-03-20
Mesop CRITICAL 9.8
CVE-2026-33057EPSS 5%

Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai…

Fix: 1.2.3+
Fix from $2,300 2026-03-20
Mesop CRITICAL 9.8
CVE-2026-33054

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability tha…

Fix: 1.2.3+
Fix from $2,300 2026-03-20
Online Doctor Appointment System CRITICAL 9.8
CVE-2026-4473

A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appo…

Mitigation only
Fix from $2,300 2026-03-20
Chall Manager CRITICAL 9.9
CVE-2026-32768

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, due to a miswritten NetworkPo…

Fix: 0.6.5+
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4472

A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the fi…

Mitigation only
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4471

A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_em…

Mitigation only
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4470

A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of …

Mitigation only
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4469

A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of…

Mitigation only
Fix from $2,300 2026-03-20
Avideo Encoder CRITICAL 9.1
CVE-2026-33024

AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpo…

Fix: 8.0+
Fix from $2,300 2026-03-20
Langflow CRITICAL 9.8
CVE-2026-33017 KEVEPSS 96%

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

Fix: 1.8.2+
Fix from $2,300 2026-03-20
Unclassified CRITICAL 9.8
CVE-2026-4038

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check…

Mitigation only
Fix from $2,300 2026-03-20
Pjsip CRITICAL 9.8
CVE-2026-32945

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability…

Fix: 2.17+
Fix from $2,300 2026-03-20
Anchorr CRITICAL 9.0
CVE-2026-32891

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and be…

Fix: after 1.4.1
Fix from $2,300 2026-03-20
Anchorr CRITICAL 9.6
CVE-2026-32890

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and…

Fix: after 1.4.1
Fix from $2,300 2026-03-20