Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bing Images CRITICAL 9.8
CVE-2026-32191

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t…

Mitigation only
Fix from $2,300 2026-03-19
Azure Cloud Shell CRITICAL 9.8
CVE-2026-32169

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-03-19
Qui CRITICAL 9.6
CVE-2026-30924

qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins whi…

Fix: 1.15.0+
Fix from $2,300 2026-03-19
Step Ca CRITICAL 10.0
CVE-2026-30836

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard ag…

Fix: 0.30.0+
Fix from $2,300 2026-03-19
Ormar CRITICAL 9.8
CVE-2026-27953

ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing …

Fix: 0.23.1+
Fix from $2,300 2026-03-19
Purview CRITICAL 10.0
CVE-2026-26138

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-03-19
365 Copilot Chat CRITICAL 9.9
CVE-2026-26137

Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-03-19
Azure Devops CRITICAL 9.8
CVE-2026-23658

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-03-19
Openemr CRITICAL 9.1
CVE-2026-32238

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command …

Fix: 8.0.0.2+
Fix from $2,300 2026-03-19
Wolfssl CRITICAL 9.8
CVE-2026-3548

Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when imprope…

Fix: 5.9.0+
Fix from $2,300 2026-03-19
Dedecms CRITICAL 9.8
CVE-2026-30694

An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component

Fix: after 5.7.118
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.8
CVE-2025-67114

Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG393…

Mitigation only
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.8
CVE-2025-67113

OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allo…

Mitigation only
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.8
CVE-2025-67112

Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware …

Mitigation only
Fix from $2,300 2026-03-19
Ecase Ecomplaint CRITICAL 9.8
CVE-2026-32867

OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files vi…

Fix: 10.1.0.0+
Fix from $2,300 2026-03-19
Ecase Ecomplaint CRITICAL 9.8
CVE-2026-32865

OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'F…

Fix: 10.1.0.0+
Fix from $2,300 2026-03-19
Wgcloud CRITICAL 9.8
CVE-2026-30402

An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function

Fix: after 2.3.7
Fix from $2,300 2026-03-19
Libsoup CRITICAL 9.1
CVE-2026-2369

A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overr…

Patch available
Fix from $2,300 2026-03-19
Unclassified CRITICAL 10.0
CVE-2026-22557EPSS 28%

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on t…

Mitigation only
Fix from $2,300 2026-03-19
Footprints CRITICAL 9.1
CVE-2025-71257EPSS 45%

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil…

Fix: after 20.24.01.001
Fix from $2,300 2026-03-19
Xml\ CRITICAL 9.8
CVE-2006-10003

XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the s…

Fix: 2.48+
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.1
CVE-2026-27067

Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server…

Mitigation only
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.8
CVE-2026-27065

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress build…

Mitigation only
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.8
CVE-2025-60237

Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0.

Mitigation only
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.8
CVE-2025-60233

Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2.

Mitigation only
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.8
CVE-2026-27542

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows P…

Mitigation only
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.0
CVE-2026-27540

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead…

Mitigation only
Fix from $2,300 2026-03-19
Unclassified CRITICAL 9.3
CVE-2026-27413

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL…

Mitigation only
Fix from $2,300 2026-03-19
Romeo CRITICAL 10.0
CVE-2026-32737

Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests with…

Fix: 0.2.1+
Fix from $2,300 2026-03-18
Import Export CRITICAL 9.9
CVE-2026-32731

ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `…

Fix: 3.5.3+
Fix from $2,300 2026-03-18