Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Emp3r0r CRITICAL 9.9
CVE-2026-26068

emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is ac…

Fix: 3.21.1+
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.8
CVE-2026-1358

Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could al…

Mitigation only
Fix from $2,300 2026-02-12
Nav2 CRITICAL 9.8
CVE-2026-26011

navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL'…

Fix: after 1.3.11
Fix from $2,300 2026-02-12
Inspektor Gadget CRITICAL 9.8
CVE-2026-25996

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String …

Fix: 0.49.1+
Fix from $2,300 2026-02-12
Frankenphp CRITICAL 9.8
CVE-2026-24895

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters durin…

Fix: 1.11.2+
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.2
CVE-2026-24044

Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Com…

Mitigation only
Fix from $2,300 2026-02-12
Webfsd CRITICAL 9.8
CVE-2025-70314

webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable

Mitigation only
Fix from $2,300 2026-02-12
Newbee Mall CRITICAL 9.1
CVE-2026-26219

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or com…

Fix: after 1.0.0
Fix from $2,300 2026-02-12
Newbee Mall CRITICAL 9.8
CVE-2026-26218

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable defau…

Fix: after 1.0.0
Fix from $2,300 2026-02-12
Cordys Crm CRITICAL 9.8
CVE-2025-70981

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

Mitigation only
Fix from $2,300 2026-02-12
Crawl4ai CRITICAL 10.0
CVE-2026-26216

Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks para…

Fix: 0.8.0+
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.0
CVE-2025-69634

Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.…

Mitigation only
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.8
CVE-2025-14014

Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Lt…

Mitigation only
Fix from $2,300 2026-02-12
E Commerce Package CRITICAL 9.8
CVE-2025-10969

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Com…

Fix: after 2025-11-27
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.4
CVE-2025-15573

The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.sola…

Mitigation only
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.8
CVE-2025-14892

The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the tar…

Mitigation only
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.8
CVE-2026-1729

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not p…

Mitigation only
Fix from $2,300 2026-02-12
Unclassified CRITICAL 9.3
CVE-2026-26215

manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticate…

Mitigation only
Fix from $2,300 2026-02-11
Ipados CRITICAL 9.0
CVE-2026-20677

A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.…

Fix: 14.8.4 / 18.7.5+
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2025-67135

Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.

Mitigation only
Fix from $2,300 2026-02-11
Set In CRITICAL 9.8
CVE-2026-26021

set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package …

Fix: 2.0.5+
Fix from $2,300 2026-02-11
Pjsip CRITICAL 9.8
CVE-2026-25994

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH …

Fix: after 2.16
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2020-37186

Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration ins…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2020-37184

Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attackers to execute arbitrary cod…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2020-37183

Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriti…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2020-37181

Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structured Exception Handler (SEH) th…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2020-37176

Torrent 3GP Converter 1.51 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exceptio…

Mitigation only
Fix from $2,300 2026-02-11
Avideo CRITICAL 9.8
CVE-2020-37172

AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password reco…

Mitigation only
Fix from $2,300 2026-02-11
Astpp CRITICAL 9.8
CVE-2020-37153

ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management …

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2025-69872

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can …

Mitigation only
Fix from $2,300 2026-02-11