Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Majordomo CRITICAL 9.8
CVE-2026-27180

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning…

Patch available
Fix from $2,300 2026-02-18
Majordomo CRITICAL 9.8
CVE-2026-27179

MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. The commands_search.inc.php fil…

Patch available
Fix from $2,300 2026-02-18
Majordomo CRITICAL 9.8
CVE-2026-27175EPSS 7%

MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is …

Patch available
Fix from $2,300 2026-02-18
Majordomo CRITICAL 9.8
CVE-2026-27174EPSS 7%

MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in…

Patch available
Fix from $2,300 2026-02-18
Unclassified CRITICAL 9.8
CVE-2019-25365

ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by over…

Mitigation only
Fix from $2,300 2026-02-18
Mailcarrier CRITICAL 9.8
CVE-2019-25364

MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers …

Mitigation only
Fix from $2,300 2026-02-18
Wmv To Avi Mpeg Dvd Wmv Convertor CRITICAL 9.8
CVE-2019-25362

WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting th…

Mitigation only
Fix from $2,300 2026-02-18
Unclassified CRITICAL 9.8
CVE-2019-25361

Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code.…

Mitigation only
Fix from $2,300 2026-02-18
Aida64 CRITICAL 9.8
CVE-2019-25360

Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code b…

Mitigation only
Fix from $2,300 2026-02-18
Enterprise Server CRITICAL 9.0
CVE-2026-0573

An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorizatio…

Fix: 3.14.22 / 3.15.17+
Fix from $2,300 2026-02-18
Scholars Tracking System CRITICAL 9.8
CVE-2025-70152

code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.p…

Mitigation only
Fix from $2,300 2026-02-18
Membership Management System CRITICAL 9.8
CVE-2025-70150

CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attacker…

Mitigation only
Fix from $2,300 2026-02-18
Membership Management System CRITICAL 9.8
CVE-2025-70149

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.

Mitigation only
Fix from $2,300 2026-02-18
Online Time Table Generator CRITICAL 9.1
CVE-2025-70146

Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attacke…

No fix yet
Fix from $2,300 2026-02-18
Customer Support System CRITICAL 9.4
CVE-2025-70141

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authe…

No fix yet
Fix from $2,300 2026-02-18
810 Firmware CRITICAL 9.8
CVE-2025-70998

UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowin…

Mitigation only
Fix from $2,300 2026-02-18
Zoneminder CRITICAL 9.8
CVE-2025-65791

ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f…

Mitigation only
Fix from $2,300 2026-02-18
Unclassified CRITICAL 9.5
CVE-2025-15579

Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote cod…

Mitigation only
Fix from $2,300 2026-02-18
Gxp1610 Firmware CRITICAL 9.8
CVE-2026-2329EPSS 40%

An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage …

Fix: 1.0.7.81+
Fix from $2,300 2026-02-18
Smolagents CRITICAL 9.8
CVE-2026-2654

A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExec…

Fix: after 1.24.0
Fix from $2,300 2026-02-18
Graylog CRITICAL 9.8
CVE-2026-1435

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new…

Mitigation only
Fix from $2,300 2026-02-18
Unclassified CRITICAL 9.8
CVE-2026-1670

The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password…

Mitigation only
Fix from $2,300 2026-02-17
Recoverpoint For Virtual Machines CRITICAL 10.0
CVE-2026-22769 KEVEPSS 13%

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as a…

Fix: 6.0+
Fix from $2,300 2026-02-17
Concert CRITICAL 9.8
CVE-2025-33089

IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard …

Fix: 2.2.0+
Fix from $2,300 2026-02-17
Tomcat CRITICAL 9.1
CVE-2025-66614

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.…

Fix: 9.0.113 / 10.1.50+
Fix from $2,300 2026-02-17
Trufusion Enterprise CRITICAL 9.9
CVE-2025-59793

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to uploa…

Fix: 7.10.5.0+
Fix from $2,300 2026-02-17
Unclassified CRITICAL 9.8
CVE-2026-23647

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication …

Mitigation only
Fix from $2,300 2026-02-17
Unclassified CRITICAL 9.9
CVE-2025-70830

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execu…

Mitigation only
Fix from $2,300 2026-02-17
777vr1 Firmware CRITICAL 9.8
CVE-2026-2616

A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface…

Fix: after 01.00.09_55
Fix from $2,300 2026-02-17
Unclassified CRITICAL 9.6
CVE-2026-22208

OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerability via an unrestricted Lua i…

Patch available
Fix from $2,300 2026-02-17