Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Ondemand CRITICAL 9.8
CVE-2026-26002

Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible…

Fix: 3.1.16 / 4.0.9+
Fix from $2,300 2026-03-04
Unclassified CRITICAL 9.1
CVE-2026-29000EPSS 6%

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs…

Mitigation only
Fix from $2,300 2026-03-04
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70222

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuthCode.

Mitigation only
Fix from $2,300 2026-03-04
Blog Application CRITICAL 9.0
CVE-2025-66024

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vu…

Fix: 9.15.7+
Fix from $2,300 2026-03-04
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70225

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfig component

Mitigation only
Fix from $2,300 2026-03-04
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70221

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin.

Mitigation only
Fix from $2,300 2026-03-04
Dir 513 Firmware CRITICAL 9.8
CVE-2025-46108

D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup.

Mitigation only
Fix from $2,300 2026-03-04
Chrome CRITICAL 9.6
CVE-2026-3545

Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape…

Fix: 145.0.7632.159 / 145.0.7632.160+
Fix from $2,300 2026-03-04
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70219

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot.

Mitigation only
Fix from $2,300 2026-03-04
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70226

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard.

Mitigation only
Fix from $2,300 2026-03-04
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70223

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork.

Mitigation only
Fix from $2,300 2026-03-04
Secure Firewall Management Center CRITICAL 10.0
CVE-2026-20131 KEVEPSS 31%

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot…

Mitigation only
Fix from $2,300 2026-03-04
Unclassified CRITICAL 10.0
CVE-2026-20079EPSS 36%

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to byp…

Mitigation only
Fix from $2,300 2026-03-04
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70220

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4.

Mitigation only
Fix from $2,300 2026-03-04
Dir 513 Firmware CRITICAL 9.8
CVE-2025-70218

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component.

Mitigation only
Fix from $2,300 2026-03-04
Freesms CRITICAL 9.8
CVE-2019-25506

FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthenticated attackers to bypass au…

Fix: after 2.1.2
Fix from $2,300 2026-03-04
Simplejobscript CRITICAL 9.8
CVE-2019-25499

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code …

Fix: after 1.66
Fix from $2,300 2026-03-04
Craft Cms CRITICAL 9.1
CVE-2026-28783

Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerou…

Fix: 4.17.0 / 5.9.0+
Fix from $2,300 2026-03-04
Craft Cms CRITICAL 9.1
CVE-2026-28697

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution…

Fix: 4.17.0 / 5.9.0+
Fix from $2,300 2026-03-04
Pebble Prism Ultra Firmware CRITICAL 9.6
CVE-2025-69969

A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism …

Fix: 2.5.8+
Fix from $2,300 2026-03-04
Databasir CRITICAL 9.8
CVE-2025-66944

SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in t…

Fix: after 1.0.7
Fix from $2,300 2026-03-04
Hardware Read \& Write Utility CRITICAL 9.8
CVE-2025-66678

An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitr…

Fix: after 1.25.11.26
Fix from $2,300 2026-03-04
Tichome Mini Firmware CRITICAL 9.8
CVE-2026-26478

A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially craf…

Mitigation only
Fix from $2,300 2026-03-04
Access Commander CRITICAL 9.8
CVE-2025-59786

2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in…

Fix: 3.5+
Fix from $2,300 2026-03-04
Artemis CRITICAL 9.8
CVE-2026-27446EPSS 10%

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c…

Fix: after 2.44.0
Fix from $2,300 2026-03-04
Seppmail CRITICAL 9.8
CVE-2026-27441

SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.

Fix: 15.0.1+
Fix from $2,300 2026-03-04
Sfx2100 Firmware CRITICAL 9.8
CVE-2026-29119

International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admi…

Mitigation only
Fix from $2,300 2026-03-04
Sfx2100 Firmware CRITICAL 9.8
CVE-2026-28778

International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd…

Mitigation only
Fix from $2,300 2026-03-04
Sfx2100 Firmware CRITICAL 9.8
CVE-2026-28777

International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated att…

Mitigation only
Fix from $2,300 2026-03-04
Sfx2100 Firmware CRITICAL 9.8
CVE-2026-28776

International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote…

Mitigation only
Fix from $2,300 2026-03-04