Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Avideo CRITICAL 9.8
CVE-2026-29093

WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 112…

Fix: 24.0+
Fix from $2,300 2026-03-06
Avideo CRITICAL 9.8
CVE-2026-28501

WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objec…

Fix: 24.0+
Fix from $2,300 2026-03-06
Tinyweb CRITICAL 9.1
CVE-2026-28497

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer …

Fix: 2.03+
Fix from $2,300 2026-03-06
Chamilo Lms CRITICAL 9.0
CVE-2025-59543

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious…

Fix: 1.11.34+
Fix from $2,300 2026-03-06
Chamilo Lms CRITICAL 9.0
CVE-2025-59542

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious…

Fix: 1.11.34+
Fix from $2,300 2026-03-06
Chamilo Lms CRITICAL 9.0
CVE-2025-55289

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an att…

Fix: 1.11.34+
Fix from $2,300 2026-03-06
Cyber Protect CRITICAL 9.8
CVE-2026-28710

Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linu…

Fix: 17.0.41186+
Fix from $2,300 2026-03-06
Epower.ie CRITICAL 9.8
CVE-2026-22552

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-06
Payment Orchestrator Service CRITICAL 9.8
CVE-2026-26125

Payment Orchestrator Service Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2026-03-05
Devices Pricing Program CRITICAL 9.8
CVE-2026-21536

Microsoft Devices Pricing Program Remote Code Execution Vulnerability

No fix yet
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.1
CVE-2026-28479

OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations, which is deprecat…

Fix: 2026.2.15+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28474

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist valid…

Fix: 2026.2.6+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28472

OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity ch…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28470

OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbit…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.9
CVE-2026-28466

OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke par…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.1
CVE-2026-28462

OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and …

Fix: 2026.2.13+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28454

OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST r…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28453

OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files out…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.3
CVE-2026-28451

OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that allow attackers to fetch attack…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.4
CVE-2026-28448

OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enfor…

Fix: 2026.2.1+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28446

OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound all…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.1
CVE-2026-28395

OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and ena…

Fix: 2026.2.12+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28393

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaSc…

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28392

OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any …

Fix: 2026.2.14+
Fix from $2,300 2026-03-05
Openclaw CRITICAL 9.8
CVE-2026-28391

OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configurat…

Fix: 2026.2.2+
Fix from $2,300 2026-03-05
Hexpm CRITICAL 9.8
CVE-2026-21622

Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover. Password …

Fix: 2026-03-05+
Fix from $2,300 2026-03-05
Openreplay CRITICAL 9.8
CVE-2026-28443

OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sor…

Fix: 1.20.0+
Fix from $2,300 2026-03-05
Nltk CRITICAL 10.0
CVE-2026-0848

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamic…

Fix: after 3.9.2
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.3
CVE-2025-70948

A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an a…

Mitigation only
Fix from $2,300 2026-03-05
Chamilo Lms CRITICAL 9.0
CVE-2025-55208

Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, …

Fix: 1.11.34+
Fix from $2,300 2026-03-05