Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Imagemagick CRITICAL 9.1
CVE-2026-25898

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and …

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $2,300 2026-02-24
Imagemagick CRITICAL 9.8
CVE-2026-25897

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer O…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $2,300 2026-02-24
E Logbook With Health Monitoring System For Covid 19 CRITICAL 9.8
CVE-2026-3046

A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unkno…

Mitigation only
Fix from $2,300 2026-02-24
Event Management System CRITICAL 9.8
CVE-2026-3042

A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. P…

Mitigation only
Fix from $2,300 2026-02-24
Smolder CRITICAL 9.1
CVE-2024-58041

Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earlier for Perl uses the rand() …

Fix: after 1.51
Fix from $2,300 2026-02-24
Chrome CRITICAL 9.8
CVE-2026-3062

Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access…

Fix: 145.0.7632.116 / 145.0.7632.117+
Fix from $2,300 2026-02-23
Chrome CRITICAL 9.1
CVE-2026-3061

Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted …

Fix: 145.0.7632.116 / 145.0.7632.117+
Fix from $2,300 2026-02-23
Smart Heating Integrated Management Platform CRITICAL 9.8
CVE-2026-3025

A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of th…

Mitigation only
Fix from $2,300 2026-02-23
Unclassified CRITICAL 10.0
CVE-2026-23693

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose t…

Mitigation only
Fix from $2,300 2026-02-23
X5000r Firmware CRITICAL 9.8
CVE-2025-70327

TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executa…

Mitigation only
Fix from $2,300 2026-02-23
Unclassified CRITICAL 9.1
CVE-2025-70043

An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate v…

No fix yet
Fix from $2,300 2026-02-23
Student Result Management System CRITICAL 9.8
CVE-2026-2983

A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin…

Mitigation only
Fix from $2,300 2026-02-23
Unclassified CRITICAL 9.3
CVE-2025-41002

SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the dat…

Mitigation only
Fix from $2,300 2026-02-23
Camel CRITICAL 9.1
CVE-2026-23552

Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not v…

Fix: 4.18.0+
Fix from $2,300 2026-02-23
Webaudiorecorder.js CRITICAL 9.8
CVE-2026-2964

A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of t…

Mitigation only
Fix from $2,300 2026-02-23
Unclassified CRITICAL 9.8
CVE-2026-24494

SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attack…

Mitigation only
Fix from $2,300 2026-02-23
Crypt\ CRITICAL 9.1
CVE-2026-2588

Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems. Sodium.xs casts a STRLEN (size_t) to unsigned lo…

Fix: after 2.001
Fix from $2,300 2026-02-23
Ujcms CRITICAL 9.8
CVE-2026-2954

A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of t…

Mitigation only
Fix from $2,300 2026-02-22
Emlak CRITICAL 9.8
CVE-2019-25459

Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database querie…

Mitigation only
Fix from $2,300 2026-02-22
Firma Rehberi CRITICAL 9.8
CVE-2019-25458

Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting …

Mitigation only
Fix from $2,300 2026-02-22
Emlak CRITICAL 9.1
CVE-2019-25456

Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code…

No fix yet
Fix from $2,300 2026-02-22
Ujcms CRITICAL 9.1
CVE-2026-2953

A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete o…

No fix yet
Fix from $2,300 2026-02-22
Vaelsys CRITICAL 9.8
CVE-2026-2952EPSS 7%

A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request …

Mitigation only
Fix from $2,300 2026-02-22
Online Store Management System CRITICAL 9.8
CVE-2026-2944EPSS 6%

A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file …

Mitigation only
Fix from $2,300 2026-02-22
Online Reviewer System CRITICAL 9.8
CVE-2026-2912

A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessment…

Mitigation only
Fix from $2,300 2026-02-22
Funadmin CRITICAL 9.1
CVE-2026-2894

A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/lo…

Fix: 7.1.0+
Fix from $2,300 2026-02-21
Vehicle Management System CRITICAL 9.8
CVE-2026-2867

A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing …

Mitigation only
Fix from $2,300 2026-02-21
Oneuptime CRITICAL 9.9
CVE-2026-27574

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's n…

Fix: 10.0.5+
Fix from $2,300 2026-02-21
Agri Trading Online Shopping System CRITICAL 9.8
CVE-2026-2865

A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroll…

Mitigation only
Fix from $2,300 2026-02-21
Erpnext CRITICAL 9.1
CVE-2026-27471

ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack…

Fix: 15.98.1 / 16.6.1+
Fix from $2,300 2026-02-21