Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Antikor Next Generation Firewall CRITICAL 9.8
CVE-2026-2624

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows…

Fix: 2.0.1301+
Fix from $2,300 2026-02-25
Octopus Server CRITICAL 9.1
CVE-2026-0704

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked va…

Fix: 2025.3.14715+
Fix from $2,300 2026-02-25
Unclassified CRITICAL 9.9
CVE-2025-62878

A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriti…

Mitigation only
Fix from $2,300 2026-02-25
News Portal Project CRITICAL 9.8
CVE-2026-3164

A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The m…

Mitigation only
Fix from $2,300 2026-02-25
Document Management System CRITICAL 9.8
CVE-2026-3153

A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipu…

Mitigation only
Fix from $2,300 2026-02-25
College Management System CRITICAL 9.8
CVE-2026-3152

A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/teacher-salary.php…

Mitigation only
Fix from $2,300 2026-02-25
College Management System CRITICAL 9.8
CVE-2026-3151

A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The…

Mitigation only
Fix from $2,300 2026-02-25
Lanscope Endpoint Manager CRITICAL 9.8
CVE-2026-25785

Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacke…

Fix: 9.4.8.0+
Fix from $2,300 2026-02-25
Simple And Nice Shopping Cart Script CRITICAL 9.8
CVE-2026-3148

A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. …

Mitigation only
Fix from $2,300 2026-02-25
Tickets CRITICAL 9.8
CVE-2026-27744

The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for publ…

Fix: 4.3.3+
Fix from $2,300 2026-02-25
Referer Spam CRITICAL 9.8
CVE-2026-27743

The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_s…

Fix: 1.3.0+
Fix from $2,300 2026-02-25
Flask Reuploaded CRITICAL 9.8
CVE-2026-27641

Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remo…

Fix: 1.5.0+
Fix from $2,300 2026-02-25
Freescout CRITICAL 9.8
CVE-2026-27637

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses …

Fix: 1.8.206+
Fix from $2,300 2026-02-25
Enclave CRITICAL 10.0
CVE-2026-27597

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boun…

Fix: 2.11.1+
Fix from $2,300 2026-02-25
Olivetin CRITICAL 9.9
CVE-2026-27626

OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety chec…

Fix: after 3000.10.0
Fix from $2,300 2026-02-25
Rustfs CRITICAL 9.1
CVE-2026-27607

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy condi…

Mitigation only
Fix from $2,300 2026-02-25
Rollup CRITICAL 9.8
CVE-2026-27606

Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present i…

Fix: 2.80.0 / 3.30.0+
Fix from $2,300 2026-02-25
News Portal Project CRITICAL 9.8
CVE-2026-3135

A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.p…

Mitigation only
Fix from $2,300 2026-02-25
News Portal Project CRITICAL 9.8
CVE-2026-3134

A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admi…

Mitigation only
Fix from $2,300 2026-02-25
Document Management System CRITICAL 9.8
CVE-2026-3133

A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of …

Mitigation only
Fix from $2,300 2026-02-25
Masterscada CRITICAL 9.8
CVE-2026-22553

All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that…

Mitigation only
Fix from $2,300 2026-02-24
Masterscada CRITICAL 9.8
CVE-2026-21410

InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potenti…

Mitigation only
Fix from $2,300 2026-02-24
Smart\+ Firmware CRITICAL 9.8
CVE-2026-26342

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficien…

Fix: after 1.181.5
Fix from $2,300 2026-02-24
Smart\+ Firmware CRITICAL 9.8
CVE-2026-26341

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed d…

Fix: after 1.181.5
Fix from $2,300 2026-02-24
Altec Doclink CRITICAL 9.8
CVE-2026-26222

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCH…

Mitigation only
Fix from $2,300 2026-02-24
Caddy CRITICAL 9.8
CVE-2026-27590

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split ind…

Fix: 2.11.1+
Fix from $2,300 2026-02-24
Caddy CRITICAL 9.1
CVE-2026-27588

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-i…

Fix: 2.11.1+
Fix from $2,300 2026-02-24
Caddy CRITICAL 9.1
CVE-2026-27587

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-…

Fix: 2.11.1+
Fix from $2,300 2026-02-24
Caddy CRITICAL 9.1
CVE-2026-27586

Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` …

Fix: 2.11.1+
Fix from $2,300 2026-02-24
10g08 0800gsm Firmware CRITICAL 9.1
CVE-2026-27515

Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web managemen…

Mitigation only
Fix from $2,300 2026-02-24