Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-1492EPSS 24%

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugi…

Mitigation only
Fix from $2,300 2026-03-03
Unclassified CRITICAL 9.8
CVE-2026-2628

The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and i…

Mitigation only
Fix from $2,300 2026-03-03
Simple Food Order System CRITICAL 9.8
CVE-2026-26713

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.

Mitigation only
Fix from $2,300 2026-03-02
Simple Food Order System CRITICAL 9.8
CVE-2026-26712

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.

Mitigation only
Fix from $2,300 2026-03-02
Simple Food Order System CRITICAL 9.8
CVE-2026-26711

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.

Mitigation only
Fix from $2,300 2026-03-02
Simple Food Order System CRITICAL 9.8
CVE-2026-26710

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.

Mitigation only
Fix from $2,300 2026-03-02
Simple Gym Management System CRITICAL 9.8
CVE-2026-26709

code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.

Mitigation only
Fix from $2,300 2026-03-02
Android CRITICAL 9.8
CVE-2026-0006

In multiple locations, there is a possible out of bounds read and write due to a heap buffer overflow. This could lead to remote code execution with …

Mitigation only
Fix from $2,300 2026-03-02
Android CRITICAL 9.1
CVE-2025-48609

In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities d…

Mitigation only
Fix from $2,300 2026-03-02
Pharmacy Point Of Sale System CRITICAL 9.8
CVE-2026-26707

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.

Mitigation only
Fix from $2,300 2026-03-02
Pharmacy Point Of Sale System CRITICAL 9.8
CVE-2026-26706

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.

Mitigation only
Fix from $2,300 2026-03-02
Pharmacy Point Of Sale System CRITICAL 9.8
CVE-2026-26705

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.

Mitigation only
Fix from $2,300 2026-03-02
Pharmacy Point Of Sale System CRITICAL 9.8
CVE-2026-26704

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.

Mitigation only
Fix from $2,300 2026-03-02
Zimaos CRITICAL 9.9
CVE-2026-28286

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restr…

Mitigation only
Fix from $2,300 2026-03-02
Pharmacy Point Of Sale System CRITICAL 9.8
CVE-2026-26708

sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.

Mitigation only
Fix from $2,300 2026-03-02
Personnel Property Equipment System CRITICAL 9.8
CVE-2026-26700

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php.

Mitigation only
Fix from $2,300 2026-03-02
Ac15 Firmware CRITICAL 9.8
CVE-2026-24105

An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leading to a …

Mitigation only
Fix from $2,300 2026-03-02
Twenty CRITICAL 9.8
CVE-2026-26720

An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.

Fix: after 1.15.0
Fix from $2,300 2026-03-02
Personnel Property Equipment System CRITICAL 9.8
CVE-2026-26701

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user.php.

Mitigation only
Fix from $2,300 2026-03-02
W20e Firmware CRITICAL 9.8
CVE-2026-24112

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInf…

Mitigation only
Fix from $2,300 2026-03-02
W20e Firmware CRITICAL 9.8
CVE-2026-24110

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addDhcpRule`…

Mitigation only
Fix from $2,300 2026-03-02
Ac15 Firmware CRITICAL 9.8
CVE-2026-24101

An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, …

Mitigation only
Fix from $2,300 2026-03-02
Chamilo Lms CRITICAL 9.8
CVE-2025-52998

Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed.…

Fix: 1.11.30+
Fix from $2,300 2026-03-02
Chamilo Lms CRITICAL 9.1
CVE-2025-50199

Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url paramete…

Fix: 1.11.30+
Fix from $2,300 2026-03-02
Personnel Property Equipment System CRITICAL 9.8
CVE-2026-26703

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php.

Mitigation only
Fix from $2,300 2026-03-02
Personnel Property Equipment System CRITICAL 9.8
CVE-2026-26702

sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php.

Mitigation only
Fix from $2,300 2026-03-02
Simple Student Alumni System CRITICAL 9.8
CVE-2026-26696

code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.

Mitigation only
Fix from $2,300 2026-03-02
Simple Student Alumni System CRITICAL 9.8
CVE-2026-26695

code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.

Mitigation only
Fix from $2,300 2026-03-02
Simple Student Alumni System CRITICAL 9.8
CVE-2026-26694

code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.

Mitigation only
Fix from $2,300 2026-03-02
W20e Firmware CRITICAL 9.8
CVE-2026-24115

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before concatenating them into `gstrul…

Mitigation only
Fix from $2,300 2026-03-02