Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opensatkit CRITICAL 9.8
CVE-2025-70085

An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Sou…

Mitigation only
Fix from $2,300 2026-02-11
Nanotar CRITICAL 9.8
CVE-2025-69874

nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outsi…

Fix: after 0.2.0
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-25084

Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-24789

An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 10.0
CVE-2025-64075

A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass au…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-2249

METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing …

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-2248

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing …

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2025-12059

Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platfor…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.4
CVE-2025-8668

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering D…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2025-8025

Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Func…

Mitigation only
Fix from $2,300 2026-02-11
Qts CRITICAL 9.8
CVE-2025-66277

A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerab…

Mitigation only
Fix from $2,300 2026-02-11
GitLab CRITICAL 9.1
CVE-2025-7659

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could …

Fix: 18.6.6 / 18.7.4+
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.8
CVE-2026-1357EPSS 33%

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions u…

Mitigation only
Fix from $2,300 2026-02-11
Unclassified CRITICAL 9.9
CVE-2026-26009

Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server te…

Patch available
Fix from $2,300 2026-02-10
Evershop CRITICAL 9.8
CVE-2026-25993

EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds path / request_path val…

Fix: after 2.1.0
Fix from $2,300 2026-02-10
Azure Conversation Authoring Client Library CRITICAL 9.8
CVE-2026-21531

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-02-10
Unclassified CRITICAL 9.8
CVE-2026-1774

CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.

Mitigation only
Fix from $2,300 2026-02-10
Fortisandbox CRITICAL 9.6
CVE-2025-52436EPSS 6%

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox…

Fix: 4.4.8 / 5.0.2+
Fix from $2,300 2026-02-10
Druid CRITICAL 9.8
CVE-2026-23906

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * d…

Fix: 36.0.0+
Fix from $2,300 2026-02-10
Unclassified CRITICAL 9.8
CVE-2025-11242

Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Si…

No fix yet
Fix from $2,300 2026-02-10
Agentflow CRITICAL 9.8
CVE-2026-2096

Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete dat…

Mitigation only
Fix from $2,300 2026-02-10
Agentflow CRITICAL 9.8
CVE-2026-2095

Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functiona…

Mitigation only
Fix from $2,300 2026-02-10
Netweaver As Abap Kernel CRITICAL 9.6
CVE-2026-0509

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls with…

Mitigation only
Fix from $2,300 2026-02-10
Netweaver Application Server Abap CRITICAL 9.9
CVE-2026-0488

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz…

Mitigation only
Fix from $2,300 2026-02-10
Fuxa CRITICAL 9.1
CVE-2026-25939EPSS 11%

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability i…

Fix: 1.2.11+
Fix from $2,300 2026-02-09
Fuxa CRITICAL 9.8
CVE-2026-25938

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA a…

Fix: 1.2.11+
Fix from $2,300 2026-02-09
Fuxa CRITICAL 9.8
CVE-2026-25895EPSS 11%

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote at…

Fix: 1.2.10+
Fix from $2,300 2026-02-09
Fuxa CRITICAL 9.8
CVE-2026-25894

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote…

Fix: 1.2.10+
Fix from $2,300 2026-02-09
Fuxa CRITICAL 9.8
CVE-2026-25893

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u…

Fix: 1.2.10+
Fix from $2,300 2026-02-09
My Little Forum CRITICAL 9.1
CVE-2026-25923

my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application f…

Fix: 20260208.1+
Fix from $2,300 2026-02-09