Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

W20e Firmware CRITICAL 9.8
CVE-2026-24114

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`.

Mitigation only
Fix from $2,300 2026-03-02
W20e Firmware CRITICAL 9.8
CVE-2026-24113

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value …

Mitigation only
Fix from $2,300 2026-03-02
W20e Firmware CRITICAL 9.8
CVE-2026-24111

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInf…

Mitigation only
Fix from $2,300 2026-03-02
W20e Firmware CRITICAL 9.8
CVE-2026-24109

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this val…

Mitigation only
Fix from $2,300 2026-03-02
W20e Firmware CRITICAL 9.8
CVE-2026-24108

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value …

Mitigation only
Fix from $2,300 2026-03-02
W20e Firmware CRITICAL 9.8
CVE-2026-24107

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`…

Mitigation only
Fix from $2,300 2026-03-02
Autopass License Server CRITICAL 9.8
CVE-2026-23600

A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

Fix: 9.19+
Fix from $2,300 2026-03-02
Chamilo Lms CRITICAL 9.8
CVE-2025-50192

Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soa…

Fix: 1.11.30+
Fix from $2,300 2026-03-02
Chamilo Lms CRITICAL 9.8
CVE-2025-50190

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter wi…

Fix: 1.11.30+
Fix from $2,300 2026-03-02
Chamilo Lms CRITICAL 9.8
CVE-2025-50187

Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote C…

Fix: 1.11.28+
Fix from $2,300 2026-03-02
Sim CRITICAL 9.1
CVE-2026-3432

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided …

Fix: 0.5.74+
Fix from $2,300 2026-03-02
Sim CRITICAL 9.8
CVE-2026-3431

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or hos…

Fix: 0.5.74+
Fix from $2,300 2026-03-02
Dorbycms CRITICAL 9.8
CVE-2025-14532

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which c…

Fix: after 5.0
Fix from $2,300 2026-03-02
Unclassified CRITICAL 9.3
CVE-2025-12462

A Blind SQL injection vulnerability has been identified in DobryCMS.  A remote unauthenticated attacker is able to inject SQL syntax into URL path in…

Mitigation only
Fix from $2,300 2026-03-02
Unclassified CRITICAL 9.4
CVE-2025-30044

In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlo…

Mitigation only
Fix from $2,300 2026-03-02
Unclassified CRITICAL 9.0
CVE-2025-30035

The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the…

Mitigation only
Fix from $2,300 2026-03-02
Unclassified CRITICAL 9.3
CVE-2026-2584

A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthenticated, remote attacker (AV…

Mitigation only
Fix from $2,300 2026-03-02
U Office Force CRITICAL 9.8
CVE-2026-3422

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary…

Fix: 29.50+
Fix from $2,300 2026-03-02
University Management System CRITICAL 9.8
CVE-2026-3413

A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php…

Mitigation only
Fix from $2,300 2026-03-02
Idexpert CRITICAL 9.8
CVE-2026-3000

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the …

Fix: after 2.8.4.250925
Fix from $2,300 2026-03-02
Idexpert CRITICAL 9.8
CVE-2026-2999

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the …

Fix: after 2.8.4.250925
Fix from $2,300 2026-03-02
University Management System CRITICAL 9.8
CVE-2026-3411

A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of …

Mitigation only
Fix from $2,300 2026-03-02
Society Management System CRITICAL 9.8
CVE-2026-3410

A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mitigation only
Fix from $2,300 2026-03-02
Online Art Gallery Shop CRITICAL 9.8
CVE-2026-3406

A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.p…

Mitigation only
Fix from $2,300 2026-03-02
Ac15 Firmware CRITICAL 9.8
CVE-2026-3400

A security flaw has been discovered in Tenda AC15 up to 15.13.07.13. Affected by this issue is some unknown functionality of the file /goform/TextEdi…

Fix: after 15.13.07.13
Fix from $2,300 2026-03-02
Maxsite Cms CRITICAL 9.8
CVE-2026-3395

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/previe…

Fix: 109.2+
Fix from $2,300 2026-03-01
Wpforo Forum CRITICAL 9.8
CVE-2026-28562

wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql…

Fix: 2.4.15+
Fix from $2,300 2026-02-28
Opendcim CRITICAL 9.8
CVE-2026-28517EPSS 6%

openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves …

Patch available
Fix from $2,300 2026-02-27
Wegia CRITICAL 9.8
CVE-2026-28411

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal …

Fix: 3.6.5+
Fix from $2,300 2026-02-27
Wegia CRITICAL 9.8
CVE-2026-28408

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the pr…

Fix: 3.6.5+
Fix from $2,300 2026-02-27