Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sdt Cs3b1 Firmware CRITICAL 9.8
CVE-2017-20223

Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2016-20030

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting pa…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2016-20026

ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manage…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2016-20024

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying exec…

Mitigation only
Fix from $2,300 2026-03-16
Realtyscript CRITICAL 9.8
CVE-2015-20121

Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by …

Mitigation only
Fix from $2,300 2026-03-16
Realtyscript CRITICAL 9.8
CVE-2015-20120

Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extra…

Mitigation only
Fix from $2,300 2026-03-16
Unclassified CRITICAL 9.8
CVE-2026-3891EPSS 25%

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation…

Mitigation only
Fix from $2,300 2026-03-13
Inetutils CRITICAL 9.8
CVE-2026-32746EPSS 24%

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does …

Fix: after 2.7
Fix from $2,300 2026-03-13
Unclassified CRITICAL 9.1
CVE-2026-32367

Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.Th…

Mitigation only
Fix from $2,300 2026-03-13
Oneuptime CRITICAL 9.9
CVE-2026-32306

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregat…

Fix: 10.0.23+
Fix from $2,300 2026-03-13
Locutus CRITICAL 9.8
CVE-2026-32304

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) functi…

Fix: 3.0.14+
Fix from $2,300 2026-03-13
Centrifugo CRITICAL 9.3
CVE-2026-32301

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when…

Fix: 6.7.0+
Fix from $2,300 2026-03-13
Freerdp CRITICAL 9.1
CVE-2026-31897

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in freerdp_bitmap_decompress_planar …

Fix: 3.24.0+
Fix from $2,300 2026-03-13
Freerdp CRITICAL 9.4
CVE-2026-31885

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders d…

Fix: 3.24.0+
Fix from $2,300 2026-03-13
Freerdp CRITICAL 9.8
CVE-2026-31883

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders lea…

Fix: 3.24.0+
Fix from $2,300 2026-03-13
Freerdp CRITICAL 9.8
CVE-2026-31806

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND mes…

Fix: 3.24.0+
Fix from $2,300 2026-03-13
Sandboxjs CRITICAL 10.0
CVE-2026-26954

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox…

Fix: 0.8.34+
Fix from $2,300 2026-03-13
Unclassified CRITICAL 9.8
CVE-2026-25823

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stac…

Mitigation only
Fix from $2,300 2026-03-13
Unclassified CRITICAL 9.1
CVE-2026-25818

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak e…

Mitigation only
Fix from $2,300 2026-03-13
Erlang\/inets CRITICAL 9.4
CVE-2026-23941

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smugglin…

Fix: 9.1.0.5 / 9.3.2.3+
Fix from $2,300 2026-03-13
Wpdiscuz CRITICAL 9.9
CVE-2026-22192

Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged m…

Fix: 7.6.47+
Fix from $2,300 2026-03-13
Omada Sg2005p Pd Firmware CRITICAL 9.8
CVE-2026-1668

The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when …

Fix: 1.0.19 / 1.20.17+
Fix from $2,300 2026-03-13
Iq4e Firmware CRITICAL 10.0
CVE-2026-3611EPSS 6%

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With n…

Fix: 3.30+
Fix from $2,300 2026-03-12
Deno CRITICAL 9.8
CVE-2026-32260

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_proces…

Fix: 2.7.2+
Fix from $2,300 2026-03-12
Parse Server CRITICAL 9.8
CVE-2026-32248

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauth…

Fix: 8.6.38 / 9.6.0+
Fix from $2,300 2026-03-12
Undici CRITICAL 9.8
CVE-2026-1525

Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-leng…

Fix: 6.24.0 / 7.24.0+
Fix from $2,300 2026-03-12
Zeptoclaw CRITICAL 9.8
CVE-2026-32232

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink A…

Fix: after 0.7.5
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26793

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attack…

Mitigation only
Fix from $2,300 2026-03-12
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70245

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode.

Mitigation only
Fix from $2,300 2026-03-12
Tracer Sc\+ Firmware CRITICAL 9.8
CVE-2026-28256

A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclo…

Fix: 6.3.2310+
Fix from $2,300 2026-03-12