Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 10.0
CVE-2026-28353

Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed v…

Mitigation only
Fix from $2,300 2026-03-05
Dir 1253 Firmware CRITICAL 9.8
CVE-2025-29165

An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component

Mitigation only
Fix from $2,300 2026-03-05
Nginx Ui CRITICAL 9.8
CVE-2026-27944EPSS 22%

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and …

Fix: 2.3.3+
Fix from $2,300 2026-03-05
Gogs CRITICAL 9.3
CVE-2026-25921

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack,…

Fix: 0.14.2+
Fix from $2,300 2026-03-05
Openmq CRITICAL 9.8
CVE-2026-24457

An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's…

Fix: after 6.5.1
Fix from $2,300 2026-03-05
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70233

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard.

Mitigation only
Fix from $2,300 2026-03-05
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70232

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter.

Mitigation only
Fix from $2,300 2026-03-05
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70231

D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/formLogin…

Mitigation only
Fix from $2,300 2026-03-05
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70230

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS.

Mitigation only
Fix from $2,300 2026-03-05
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70229

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule.

Mitigation only
Fix from $2,300 2026-03-05
Viber CRITICAL 9.8
CVE-2025-13476

Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking exte…

Fix: after 25.8.1.0
Fix from $2,300 2026-03-05
Rustdesk CRITICAL 9.8
CVE-2026-30793

Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter UR…

Fix: after 1.4.5
Fix from $2,300 2026-03-05
Rustdesk CRITICAL 9.8
CVE-2026-30789

Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-clie…

Fix: after 1.4.5
Fix from $2,300 2026-03-05
Rustdesk CRITICAL 9.8
CVE-2026-30783

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop…

Fix: after 1.4.5
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.8
CVE-2026-2599

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu…

Mitigation only
Fix from $2,300 2026-03-05
Astroid Framework CRITICAL 9.8
CVE-2026-21628

A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

Fix: after 3.3.10
Fix from $2,300 2026-03-05
Seppmail CRITICAL 9.8
CVE-2026-2743

Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transf…

Fix: after 15.0.2.1
Fix from $2,300 2026-03-05
Linux Enterprise Server CRITICAL 9.8
CVE-2026-25702

A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via…

Mitigation only
Fix from $2,300 2026-03-05
Zephyr CRITICAL 9.8
CVE-2026-1678

dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, a…

Fix: after 4.3.0
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.1
CVE-2026-2418

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticat…

Mitigation only
Fix from $2,300 2026-03-05
Sfx2100 Firmware CRITICAL 10.0
CVE-2026-29128

IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th…

Mitigation only
Fix from $2,300 2026-03-05
Ghost CRITICAL 9.8
CVE-2026-29053

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the s…

Fix: 6.19.1+
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.3
CVE-2026-28115

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy St…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.1
CVE-2026-28114

Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell …

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.8
CVE-2026-28105

Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a t…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.8
CVE-2026-28074

Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a t…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.8
CVE-2026-28043

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Healer - Doctor, Cl…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.0
CVE-2026-27984

Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This is…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.8
CVE-2026-27983

Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escalation.This issue affects LMS E…

Mitigation only
Fix from $2,300 2026-03-05
Unclassified CRITICAL 9.8
CVE-2026-27439

Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through <…

Mitigation only
Fix from $2,300 2026-03-05