Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wegia CRITICAL 9.8
CVE-2026-28408

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the pr…

Fix: 3.6.5+
Fix from $2,300 2026-02-27
Vikunja CRITICAL 9.8
CVE-2026-28268

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password re…

Fix: 2.1.0+
Fix from $2,300 2026-02-27
Pillow Heif CRITICAL 9.1
CVE-2026-28231

pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path bu…

Fix: 1.3.0+
Fix from $2,300 2026-02-27
Seerr CRITICAL 9.8
CVE-2026-27707

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and prior to version 3.1.0, an au…

Fix: 3.1.0+
Fix from $2,300 2026-02-27
Fastify\/middie CRITICAL 9.1
CVE-2026-2880

A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example,…

Fix: 9.2.0+
Fix from $2,300 2026-02-27
Sl902 Swtgw124as Firmware CRITICAL 9.8
CVE-2026-27755

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge …

Fix: after 200.1.20
Fix from $2,300 2026-02-27
Sl902 Swtgw124as Firmware CRITICAL 9.8
CVE-2026-27751

SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain adminis…

Fix: after 200.1.20
Fix from $2,300 2026-02-27
Airbnb Clone Script CRITICAL 9.1
CVE-2019-25489

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug…

No fix yet
Fix from $2,300 2026-02-27
Nest CRITICAL 9.8
CVE-2026-2293

A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization optio…

Mitigation only
Fix from $2,300 2026-02-27
Web CRITICAL 9.8
CVE-2026-2750

Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affec…

Fix: 24.04.24 / 24.10.20+
Fix from $2,300 2026-02-27
Centreon Web CRITICAL 9.8
CVE-2026-2751

Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (S…

Fix: 24.04.24. / 24.10.20+
Fix from $2,300 2026-02-27
Unclassified CRITICAL 9.3
CVE-2025-15498

Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to b…

Mitigation only
Fix from $2,300 2026-02-27
Windesk.fm CRITICAL 9.8
CVE-2025-11252

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. W…

Fix: after 27022026
Fix from $2,300 2026-02-27
Pluxml CRITICAL 9.8
CVE-2026-24352

PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This…

Mitigation only
Fix from $2,300 2026-02-27
Woyio CRITICAL 9.8
CVE-2025-11251

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Comm…

Mitigation only
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21660

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD ve…

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21659

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Q…

Fix: after 10.22
Fix from $2,300 2026-02-27
Freeflow Core CRITICAL 9.8
CVE-2026-2251

Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal …

Fix: 8.1.0+
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21658

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls …

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21657

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21656

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic…

Fix: after 10.22
Fix from $2,300 2026-02-27
Frick Controls Quantum Hd Firmware CRITICAL 9.8
CVE-2026-21654

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum H…

Fix: after 10.22
Fix from $2,300 2026-02-27
Lms1000 Firmware CRITICAL 9.1
CVE-2026-1626

An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypt…

Fix: 2.4.1+
Fix from $2,300 2026-02-27
Unclassified CRITICAL 9.8
CVE-2025-12981

The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation …

Mitigation only
Fix from $2,300 2026-02-27
N300rh Firmware CRITICAL 9.8
CVE-2026-3301

A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file …

Mitigation only
Fix from $2,300 2026-02-27
Publiccms CRITICAL 9.8
CVE-2026-3289

A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the…

Mitigation only
Fix from $2,300 2026-02-27
Youlai Mall CRITICAL 9.8
CVE-2026-3287

A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/m…

Mitigation only
Fix from $2,300 2026-02-27
Vitrage CRITICAL 9.1
CVE-2026-28370

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code executi…

Fix: 12.01 / 13.0.1+
Fix from $2,300 2026-02-27
Thinkwise CRITICAL 9.8
CVE-2026-24497

Stack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue affects ThinkWise: from 7 throug…

Fix: 23+
Fix from $2,300 2026-02-27
Xweb 300d Pro Firmware CRITICAL 9.1
CVE-2026-22877

An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the…

Fix: after 1.12.1
Fix from $2,300 2026-02-27