Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tracer Sc Firmware CRITICAL 9.8
CVE-2026-28255

A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive info…

Fix: 6.3.2310+
Fix from $2,300 2026-03-12
Tracer Sc Firmware CRITICAL 9.8
CVE-2026-28252

A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypa…

Fix: 6.3.2310+
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26795

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. Th…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26792

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, targe…

Mitigation only
Fix from $2,300 2026-03-12
Ar300m16 Firmware CRITICAL 9.8
CVE-2026-26791

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server funct…

Mitigation only
Fix from $2,300 2026-03-12
Tinacms\/cli CRITICAL 9.6
CVE-2026-28792

Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Al…

Fix: 2.1.8+
Fix from $2,300 2026-03-12
Veeam Backup \& Replication CRITICAL 9.9
CVE-2026-21708

A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

Fix: 12.3.2.4465.+
Fix from $2,300 2026-03-12
Inout Homestay CRITICAL 9.1
CVE-2019-25528

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by…

No fix yet
Fix from $2,300 2026-03-12
Inout Homestay CRITICAL 9.1
CVE-2019-25527

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by…

No fix yet
Fix from $2,300 2026-03-12
Inout Homestay CRITICAL 9.1
CVE-2019-25526

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by…

No fix yet
Fix from $2,300 2026-03-12
Inout Homestay CRITICAL 9.1
CVE-2019-25525

Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by…

No fix yet
Fix from $2,300 2026-03-12
Xoogallery CRITICAL 9.1
CVE-2019-25524

XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

No fix yet
Fix from $2,300 2026-03-12
Xoogallery CRITICAL 9.1
CVE-2019-25523

XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

No fix yet
Fix from $2,300 2026-03-12
Xoogallery CRITICAL 9.1
CVE-2019-25522

XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQ…

No fix yet
Fix from $2,300 2026-03-12
Xoogallery CRITICAL 9.1
CVE-2019-25521

XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

No fix yet
Fix from $2,300 2026-03-12
Php Stock News Site Script CRITICAL 9.8
CVE-2019-25520

Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated att…

Mitigation only
Fix from $2,300 2026-03-12
Php Stock News Site Script CRITICAL 9.8
CVE-2019-25515

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php administration panel that allows unauthent…

Mitigation only
Fix from $2,300 2026-03-12
Php Stock News Site Script CRITICAL 9.8
CVE-2019-25514

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the …

Mitigation only
Fix from $2,300 2026-03-12
Php Stock News Site Script CRITICAL 9.8
CVE-2019-25513

Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie…

Mitigation only
Fix from $2,300 2026-03-12
Php Stock News Site Script CRITICAL 9.8
CVE-2019-25510

Jettweb PHP Hazir Haber Sitesi Scripti V2 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated att…

Mitigation only
Fix from $2,300 2026-03-12
Php Ready Rent A Car Site Script CRITICAL 9.8
CVE-2019-25488

Jettweb Hazir Rent A Car Scripti V4 contains multiple SQL injection vulnerabilities in the admin panel that allow unauthenticated attackers to manipu…

Mitigation only
Fix from $2,300 2026-03-12
Unclassified CRITICAL 9.4
CVE-2026-28384

An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as th…

Patch available
Fix from $2,300 2026-03-12
Veeam Backup \& Replication CRITICAL 9.1
CVE-2026-21671

A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) de…

Fix: after 13.0.1.1071
Fix from $2,300 2026-03-12
Veeam Backup \& Replication CRITICAL 9.9
CVE-2026-21669

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Fix: 13.0.1.2067+
Fix from $2,300 2026-03-12
Sglang CRITICAL 9.8
CVE-2026-3060

SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deseri…

Fix: after 0.5.9
Fix from $2,300 2026-03-12
Sglang CRITICAL 9.8
CVE-2026-3059

SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted dat…

Fix: after 0.5.9
Fix from $2,300 2026-03-12
Cafe Reservation System CRITICAL 9.8
CVE-2026-4014

A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. This impacts an unknown function of the file /curvus2/signup.php of …

Mitigation only
Fix from $2,300 2026-03-12
Online Doctor Appointment System CRITICAL 9.8
CVE-2026-3981

A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctor_action.php.…

Mitigation only
Fix from $2,300 2026-03-12
Online Doctor Appointment System CRITICAL 9.8
CVE-2026-3980

A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of the file /admin/patient_acti…

Mitigation only
Fix from $2,300 2026-03-12
Hyper Data Protector CRITICAL 9.8
CVE-2025-59388

A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability …

Fix: 2.3.1.455+
Fix from $2,300 2026-03-12