Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dir 816 Firmware CRITICAL 9.8
CVE-2026-4182

A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the com…

Mitigation only
Fix from $2,300 2026-03-16
Dir 816 Firmware CRITICAL 9.8
CVE-2026-4181

A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the c…

Mitigation only
Fix from $2,300 2026-03-16
Dir 816 Firmware CRITICAL 9.8
CVE-2026-4180

A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goa…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2026-4170

A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/manage…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2026-4164

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of t…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2026-4163

A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the…

Mitigation only
Fix from $2,300 2026-03-16
Angular Cli CRITICAL 9.0
CVE-2026-32635

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-n…

Fix: 19.2.0 / 21.2.4+
Fix from $2,300 2026-03-16
Anythingllm CRITICAL 9.6
CVE-2026-32626

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, An…

Fix: after 1.11.1
Fix from $2,300 2026-03-16
Simpleeval CRITICAL 9.8
CVE-2026-32640

SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modul…

Fix: 1.0.5+
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.9
CVE-2026-32621

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vul…

Mitigation only
Fix from $2,300 2026-03-16
Smart Switch CRITICAL 9.8
CVE-2026-20998

Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.

Fix: 3.7.69.15+
Fix from $2,300 2026-03-16
Smart Switch CRITICAL 9.8
CVE-2026-20997

Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authenticat…

Fix: 3.7.69.15+
Fix from $2,300 2026-03-16
Raytha CRITICAL 9.8
CVE-2025-69246

Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without tr…

Fix: 1.4.6+
Fix from $2,300 2026-03-16
Aion CRITICAL 9.8
CVE-2025-52648

HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tamp…

Fix: 2.1.2+
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2025-15060

claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $2,300 2026-03-16
Sdt Cs3b1 Firmware CRITICAL 9.8
CVE-2017-20224

Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload mal…

Mitigation only
Fix from $2,300 2026-03-16
Sdt Cs3b1 Firmware CRITICAL 9.8
CVE-2017-20223

Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2016-20030

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting pa…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2016-20026

ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manage…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2016-20024

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying exec…

Mitigation only
Fix from $2,300 2026-03-16
Realtyscript CRITICAL 9.8
CVE-2015-20121

Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by …

Mitigation only
Fix from $2,300 2026-03-16
Realtyscript CRITICAL 9.8
CVE-2015-20120

Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extra…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2026-3891EPSS 25%

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation…

Mitigation only
Fix from $2,300 2026-03-13
Inetutils CRITICAL 9.8
CVE-2026-32746EPSS 24%

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does …

Fix: after 2.7
Fix from $2,300 2026-03-13
Unclassified CRITICAL 9.1
CVE-2026-32367

Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.Th…

Mitigation only
Fix from $2,300 2026-03-13
Oneuptime CRITICAL 9.9
CVE-2026-32306

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregat…

Fix: 10.0.23+
Fix from $2,300 2026-03-13
Locutus CRITICAL 9.8
CVE-2026-32304

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) functi…

Fix: 3.0.14+
Fix from $2,300 2026-03-13
Centrifugo CRITICAL 9.3
CVE-2026-32301

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when…

Fix: 6.7.0+
Fix from $2,300 2026-03-13
Freerdp CRITICAL 9.1
CVE-2026-31897

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in freerdp_bitmap_decompress_planar …

Fix: 3.24.0+
Fix from $2,300 2026-03-13
Freerdp CRITICAL 9.4
CVE-2026-31885

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders d…

Fix: 3.24.0+
Fix from $2,300 2026-03-13