Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sandboxjs CRITICAL 10.0
CVE-2026-25881

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototype…

Fix: 0.8.31+
Fix from $2,300 2026-02-09
Placipy CRITICAL 9.8
CVE-2026-25875

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorization middleware trusts client-co…

Mitigation only
Fix from $2,300 2026-02-09
Placipy CRITICAL 9.8
CVE-2026-25814

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query parameters are passed directl…

Mitigation only
Fix from $2,300 2026-02-09
Placipy CRITICAL 9.1
CVE-2026-25811

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier direc…

Mitigation only
Fix from $2,300 2026-02-09
Placipy CRITICAL 9.1
CVE-2026-25876

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify aut…

Mitigation only
Fix from $2,300 2026-02-09
Placipy CRITICAL 9.1
CVE-2026-25810

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts…

Mitigation only
Fix from $2,300 2026-02-09
Placipy CRITICAL 9.8
CVE-2026-25809

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the …

Mitigation only
Fix from $2,300 2026-02-09
Markus CRITICAL 9.1
CVE-2026-25057

MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able to upload a zip file to creat…

Fix: 2.9.1+
Fix from $2,300 2026-02-09
Freerdp CRITICAL 9.1
CVE-2026-24679

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array i…

Fix: 3.22.0+
Fix from $2,300 2026-02-09
Freerdp CRITICAL 9.1
CVE-2026-24677

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts server-controlled dimensions and …

Fix: 3.22.0+
Fix from $2,300 2026-02-09
Fiber CRITICAL 9.4
CVE-2025-66630

Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can…

Fix: 2.52.11+
Fix from $2,300 2026-02-09
Unclassified CRITICAL 9.8
CVE-2025-6830

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Passw…

Mitigation only
Fix from $2,300 2026-02-09
Hub CRITICAL 9.8
CVE-2026-25848

In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

Fix: 2025.3.119807+
Fix from $2,300 2026-02-09
News Portal Project CRITICAL 9.8
CVE-2026-2225

A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component …

Mitigation only
Fix from $2,300 2026-02-09
Unclassified CRITICAL 9.1
CVE-2026-2234

C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail …

Mitigation only
Fix from $2,300 2026-02-09
Online Reviewer System CRITICAL 9.8
CVE-2026-2223

A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the f…

Mitigation only
Fix from $2,300 2026-02-09
Unclassified CRITICAL 9.8
CVE-2026-22906

User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can de…

Mitigation only
Fix from $2,300 2026-02-09
Unclassified CRITICAL 9.8
CVE-2026-22904

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie v…

Mitigation only
Fix from $2,300 2026-02-09
Unclassified CRITICAL 9.8
CVE-2026-22903

An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overfl…

Mitigation only
Fix from $2,300 2026-02-09
Online Reviewer System CRITICAL 9.8
CVE-2026-2221

A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the …

Mitigation only
Fix from $2,300 2026-02-09
Online Reviewer System CRITICAL 9.8
CVE-2026-2220

A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assess…

Mitigation only
Fix from $2,300 2026-02-09
Unclassified CRITICAL 9.9
CVE-2026-1868

GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6…

Mitigation only
Fix from $2,300 2026-02-09
Event Management System CRITICAL 9.8
CVE-2026-2217

A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php…

Mitigation only
Fix from $2,300 2026-02-09
Unclassified CRITICAL 9.8
CVE-2026-1615

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions…

Patch available
Fix from $2,300 2026-02-09
Online Music Site CRITICAL 9.8
CVE-2026-2212

A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Admini…

Mitigation only
Fix from $2,300 2026-02-09
Online Music Site CRITICAL 9.8
CVE-2026-2211

A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCate…

Mitigation only
Fix from $2,300 2026-02-09
Fast\/tools CRITICAL 9.6
CVE-2025-66606

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker co…

Mitigation only
Fix from $2,300 2026-02-09
Fast\/tools CRITICAL 9.8
CVE-2025-66603

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OPTIONS method. An attacker cou…

Mitigation only
Fix from $2,300 2026-02-09
Fast\/tools CRITICAL 9.8
CVE-2025-66602

A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access by IP address. When a worm t…

Mitigation only
Fix from $2,300 2026-02-09
Online Reviewer System CRITICAL 9.8
CVE-2026-2199

A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/sy…

Mitigation only
Fix from $2,300 2026-02-09