Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw CRITICAL 9.9
CVE-2026-32048

OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to …

Fix: 2026.3.1+
Fix from $2,300 2026-03-21
Openclaw CRITICAL 9.8
CVE-2026-32046

OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by explo…

Fix: 2026.2.21+
Fix from $2,300 2026-03-21
Openclaw CRITICAL 9.1
CVE-2026-32045

OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and…

Fix: 2026.2.21+
Fix from $2,300 2026-03-21
Unclassified CRITICAL 9.1
CVE-2026-24060

Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker…

Mitigation only
Fix from $2,300 2026-03-21
Flatted CRITICAL 9.8
CVE-2026-33228

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed …

Fix: 3.4.2+
Fix from $2,300 2026-03-20
Json CRITICAL 9.1
CVE-2026-33210

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnera…

Fix: 2.15.2.1 / 2.17.1.2+
Fix from $2,300 2026-03-20
Grpc CRITICAL 9.1
CVE-2026-33186

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of …

Fix: 1.79.3+
Fix from $2,300 2026-03-20
Eparking.fi CRITICAL 9.8
CVE-2026-29796

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-20
Charge Portal CRITICAL 9.8
CVE-2026-25192

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-20
Ddk CRITICAL 9.6
CVE-2026-21732

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU…

Fix: after 25.1
Fix from $2,300 2026-03-20
Unclassified CRITICAL 9.8
CVE-2026-3584EPSS 7%

The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' functio…

Mitigation only
Fix from $2,300 2026-03-20
Dir 820lw Firmware CRITICAL 9.8
CVE-2026-4499

A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can le…

Mitigation only
Fix from $2,300 2026-03-20
Wa300 Firmware CRITICAL 9.8
CVE-2026-4497

A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/c…

Mitigation only
Fix from $2,300 2026-03-20
MariaDB CRITICAL 9.9
CVE-2026-32710

MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11…

Fix: 11.4.10 / 11.8.6+
Fix from $2,300 2026-03-20
Qunetswitch CRITICAL 9.8
CVE-2026-22901

A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulne…

Fix: after 2.0.5.0906
Fix from $2,300 2026-03-20
Qunetswitch CRITICAL 9.8
CVE-2026-22900

A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gai…

Fix: 2.0.5.0906+
Fix from $2,300 2026-03-20
Qvr Pro CRITICAL 9.8
CVE-2026-22898

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerabi…

Fix: 2.7.4.1485+
Fix from $2,300 2026-03-20
Qunetswitch CRITICAL 9.8
CVE-2026-22897

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitra…

Fix: 2.0.4.0415+
Fix from $2,300 2026-03-20
Media Streaming Add On CRITICAL 9.1
CVE-2025-59383

A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify…

Fix: 500.1.1.0+
Fix from $2,300 2026-03-20
Archer Ax53 Firmware CRITICAL 9.8
CVE-2025-15608

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalid…

Mitigation only
Fix from $2,300 2026-03-20
Archer Ax53 Firmware CRITICAL 9.8
CVE-2025-15607

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbit…

Mitigation only
Fix from $2,300 2026-03-20
Openclaw CRITICAL 9.9
CVE-2026-22172

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password…

Fix: 2026.3.12+
Fix from $2,300 2026-03-20
Sysak CRITICAL 9.8
CVE-2024-44722

SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.

Fix: after 2.0
Fix from $2,300 2026-03-20
H3 CRITICAL 9.1
CVE-2026-33131

H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which exte…

No fix yet
Fix from $2,300 2026-03-20
H3 CRITICAL 10.0
CVE-2026-33128

H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent E…

Fix: 1.15.6+
Fix from $2,300 2026-03-20
Siyuan CRITICAL 9.0
CVE-2026-33067

SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template l…

Fix: 3.6.1+
Fix from $2,300 2026-03-20
Siyuan CRITICAL 9.0
CVE-2026-33066

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetS…

Fix: 3.6.1+
Fix from $2,300 2026-03-20
Mesop CRITICAL 9.8
CVE-2026-33057EPSS 5%

Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai…

Fix: 1.2.3+
Fix from $2,300 2026-03-20
Mesop CRITICAL 9.8
CVE-2026-33054

Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability tha…

Fix: 1.2.3+
Fix from $2,300 2026-03-20
Online Doctor Appointment System CRITICAL 9.8
CVE-2026-4473

A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appo…

Mitigation only
Fix from $2,300 2026-03-20