Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ruckus Network Director CRITICAL 9.8
CVE-2025-67304

In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default…

Fix: 4.5.0.56+
Fix from $2,300 2026-02-19
Skill Scanner CRITICAL 9.1
CVE-2026-26057

Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. A vulnerabilit…

Fix: 1.0.2+
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.3
CVE-2026-2409

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suite allows Argument Injection.T…

Mitigation only
Fix from $2,300 2026-02-19
Alfresco Transform Service CRITICAL 9.8
CVE-2026-26339

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability…

Fix: 4.2.3 / 5.2.4+
Fix from $2,300 2026-02-19
Alfresco Transform Service CRITICAL 9.8
CVE-2026-26338

Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing…

Fix: 4.3 / 5.3.0+
Fix from $2,300 2026-02-19
Semantic Kernel CRITICAL 9.9
CVE-2026-26030

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t…

Fix: 1.39.4+
Fix from $2,300 2026-02-19
Saisies CRITICAL 9.8
CVE-2025-71243EPSS 5%

The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. …

Fix: 5.11.1+
Fix from $2,300 2026-02-19
Webpdf CRITICAL 9.1
CVE-2025-55853

SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or externa…

Fix: 10.0.2+
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2025-9953

Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Softw…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2025-8350

Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS al…

Mitigation only
Fix from $2,300 2026-02-19
Worktime CRITICAL 9.8
CVE-2025-15559

An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and dow…

Fix: after 11.8.8
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-23549

Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: fro…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-23542

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Resta…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 10.0
CVE-2026-2731

Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers t…

Mitigation only
Fix from $2,300 2026-02-19
Event Management System CRITICAL 9.8
CVE-2026-2691

A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/m…

Mitigation only
Fix from $2,300 2026-02-19
Event Management System CRITICAL 9.8
CVE-2026-2690

A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax…

Mitigation only
Fix from $2,300 2026-02-19
Event Management System CRITICAL 9.8
CVE-2026-2689

A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The …

Mitigation only
Fix from $2,300 2026-02-19
Gogs CRITICAL 9.8
CVE-2026-25242

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global Re…

Fix: 0.14.1+
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-1994

The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is du…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-1405

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-0926EPSS 9%

The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[templ…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 10.0
CVE-2025-15586

OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in …

Patch available
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2025-13851

The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2025-13563

The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_l…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2025-12882

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin all…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-2686

A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. …

Mitigation only
Fix from $2,300 2026-02-19
Electronic Archives System CRITICAL 9.8
CVE-2026-2684

A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function o…

Fix: after 3.2.210802
Fix from $2,300 2026-02-19
Weblate CRITICAL 9.1
CVE-2026-24126

Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key…

Fix: 5.16+
Fix from $2,300 2026-02-19
Electronic Archives System CRITICAL 9.8
CVE-2026-2682

A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /…

Fix: after 3.2.210802
Fix from $2,300 2026-02-18
Invoiceplane CRITICAL 9.1
CVE-2026-25548

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerabil…

Fix: 1.7.1+
Fix from $2,300 2026-02-18