Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-26220

LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD ma…

Mitigation only
Fix from $2,300 2026-02-17
Concierge\ CRITICAL 9.8
CVE-2026-2439

Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions:…

Fix: 0.8.5+
Fix from $2,300 2026-02-16
Maypole CRITICAL 9.8
CVE-2025-15578

Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available …

Fix: after 2.13
Fix from $2,300 2026-02-16
Unclassified CRITICAL 10.0
CVE-2026-2577

The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require …

Mitigation only
Fix from $2,300 2026-02-16
Unclassified CRITICAL 9.8
CVE-2026-2550

A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipul…

Mitigation only
Fix from $2,300 2026-02-16
Deepaudit CRITICAL 9.8
CVE-2026-2532

A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the file backend/app/api/v1/endpoint…

Fix: after 3.0.3
Fix from $2,300 2026-02-16
Wl Wn579a3 Firmware CRITICAL 9.8
CVE-2026-2529EPSS 8%

A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wirel…

Fix: after 2021-02-19
Fix from $2,300 2026-02-16
Wl Wn579a3 Firmware CRITICAL 9.8
CVE-2026-2528EPSS 8%

A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Delete_Mac_list of the file /cgi-…

Fix: after 2021-02-19
Fix from $2,300 2026-02-16
Wl Wn579a3 Firmware CRITICAL 9.8
CVE-2026-2527EPSS 8%

A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bin/login.cgi. Executing a mani…

Fix: after 2021-02-19
Fix from $2,300 2026-02-16
Open5gs CRITICAL 9.8
CVE-2026-2522

A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is an unknown function of the file /src/mme/esm-build.c of the component …

Fix: after 2.7.6
Fix from $2,300 2026-02-16
Open5gs CRITICAL 9.8
CVE-2026-2521

A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_response of the component SGW-C…

Fix: after 2.7.6
Fix from $2,300 2026-02-15
Enet Smart Home CRITICAL 9.8
CVE-2026-26366

eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissionin…

Mitigation only
Fix from $2,300 2026-02-15
Unclassified CRITICAL 9.3
CVE-2025-32058

The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface throu…

Mitigation only
Fix from $2,300 2026-02-15
Unclassified CRITICAL 9.8
CVE-2026-1490

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an auth…

Mitigation only
Fix from $2,300 2026-02-15
Unclassified CRITICAL 9.8
CVE-2025-8572

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient…

Mitigation only
Fix from $2,300 2026-02-14
Unclassified CRITICAL 9.8
CVE-2026-1306

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJ…

Mitigation only
Fix from $2,300 2026-02-14
Caido CRITICAL 9.8
CVE-2026-24853

Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the 8080 port, and shows Host/IP…

Fix: 0.55.0+
Fix from $2,300 2026-02-13
Known CRITICAL 9.8
CVE-2026-26273

Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The applicat…

Fix: 1.6.3+
Fix from $2,300 2026-02-13
Unclassified CRITICAL 9.8
CVE-2025-69633

A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7…

Mitigation only
Fix from $2,300 2026-02-13
Verasmart CRITICAL 9.8
CVE-2026-26335

Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Pr…

Fix: 2022.0+
Fix from $2,300 2026-02-13
Verasmart CRITICAL 9.8
CVE-2026-26333

Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default Objec…

Fix: 2022.0+
Fix from $2,300 2026-02-13
Milvus CRITICAL 9.8
CVE-2026-26190EPSS 37%

Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, w…

Fix: 2.5.27 / 2.6.10+
Fix from $2,300 2026-02-13
Unclassified CRITICAL 10.0
CVE-2025-69770

A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via upl…

Mitigation only
Fix from $2,300 2026-02-13
Cursor CRITICAL 9.9
CVE-2026-26268

Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicio…

Fix: 2.5+
Fix from $2,300 2026-02-13
Unclassified CRITICAL 9.8
CVE-2026-26221

Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attack…

Mitigation only
Fix from $2,300 2026-02-13
Linux Kernel CRITICAL 9.8
CVE-2026-23112

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_i…

Fix: 5.10.250 / 5.15.200+
Fix from $2,300 2026-02-13
Unclassified CRITICAL 9.8
CVE-2019-25337

OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php end…

Mitigation only
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.8
CVE-2019-25327

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary co…

Mitigation only
Fix from $2,300 2026-02-12
Ftp Navigator CRITICAL 9.8
CVE-2019-25321

FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handle…

Fix: after 8.03
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.8
CVE-2019-25319

Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exce…

Mitigation only
Fix from $2,300 2026-02-12