Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Online Class Record System CRITICAL 9.8
CVE-2026-2090

A vulnerability was determined in SourceCodester Online Class Record System 1.0. This issue affects some unknown processing of the file /admin/messag…

Mitigation only
Fix from $2,300 2026-02-07
Online Class Record System CRITICAL 9.8
CVE-2026-2089

A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of the file /admin/subject/contro…

Mitigation only
Fix from $2,300 2026-02-07
Beauty Parlour Management System CRITICAL 9.8
CVE-2026-2088

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointme…

Mitigation only
Fix from $2,300 2026-02-07
Online Class Record System CRITICAL 9.8
CVE-2026-2087

A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login…

Mitigation only
Fix from $2,300 2026-02-07
Social Networking Site CRITICAL 9.8
CVE-2026-2083

A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Perfo…

Mitigation only
Fix from $2,300 2026-02-07
School Management System CRITICAL 9.8
CVE-2026-2073

A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/user/index.php. E…

Mitigation only
Fix from $2,300 2026-02-07
Wedding Slideshow Studio CRITICAL 9.8
CVE-2020-37162

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration key input that allows attackers to execute arbitrary code …

Fix: after 1.36
Fix from $2,300 2026-02-07
Wedding Slideshow Studio CRITICAL 9.8
CVE-2020-37161

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the registratio…

Fix: after 1.36
Fix from $2,300 2026-02-07
Unclassified CRITICAL 9.8
CVE-2020-37159

Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory registers …

Mitigation only
Fix from $2,300 2026-02-07
Unclassified CRITICAL 9.8
CVE-2020-37095

Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting…

Mitigation only
Fix from $2,300 2026-02-07
Antrea CRITICAL 9.1
CVE-2026-25804

Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to versions 2.3.2 and 2.4.3, Antrea's network policy priority assi…

Fix: 2.3.2 / 2.4.3+
Fix from $2,300 2026-02-06
3dp Manager CRITICAL 9.8
CVE-2026-25803

3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an administrative account with known…

Fix: after 2.0.1
Fix from $2,300 2026-02-06
Openproject CRITICAL 9.9
CVE-2026-25763

OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary file write vulnerability exis…

Fix: 16.6.7 / 17.0.3+
Fix from $2,300 2026-02-06
Payload CRITICAL 9.8
CVE-2026-25544

Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly…

Fix: 3.73.0+
Fix from $2,300 2026-02-06
Privileged Remote Access CRITICAL 9.8
CVE-2026-1731 KEVEPSS 89%

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execut…

Fix: 25.1 / 25.3.2+
Fix from $2,300 2026-02-06
Unclassified CRITICAL 9.1
CVE-2026-1727

The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket n…

Mitigation only
Fix from $2,300 2026-02-06
Epyt Flow CRITICAL 10.0
CVE-2026-25632

EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to …

Fix: 0.16.1+
Fix from $2,300 2026-02-06
Unclassified CRITICAL 9.9
CVE-2026-25592

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerab…

Patch available
Fix from $2,300 2026-02-06
Frigate CRITICAL 9.1
CVE-2026-25643

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (…

Fix: 0.16.4+
Fix from $2,300 2026-02-06
Sandboxjs CRITICAL 9.0
CVE-2026-25641

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch between the key on which the…

Fix: 0.8.29+
Fix from $2,300 2026-02-06
Sandboxjs CRITICAL 10.0
CVE-2026-25587

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By over…

Fix: 0.8.29+
Fix from $2,300 2026-02-06
Sandboxjs CRITICAL 10.0
CVE-2026-25586

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which di…

Fix: 0.8.29+
Fix from $2,300 2026-02-06
Sandboxjs CRITICAL 10.0
CVE-2026-25520

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.values/Object.entries can be use…

Fix: 0.8.29+
Fix from $2,300 2026-02-06
Enterprise Linux CRITICAL 9.8
CVE-2026-1709EPSS 5%

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication.…

Mitigation only
Fix from $2,300 2026-02-06
Placipy CRITICAL 9.8
CVE-2026-25753

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default p…

Mitigation only
Fix from $2,300 2026-02-06
Fuxa CRITICAL 9.1
CVE-2026-25752

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An authorization bypass vulnerability in FUXA allows an unauthenticated, re…

Fix: 1.2.10+
Fix from $2,300 2026-02-06
Simple Blood Donor Management System CRITICAL 9.8
CVE-2026-2060

A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of th…

Mitigation only
Fix from $2,300 2026-02-06
Claude Code CRITICAL 10.0
CVE-2026-25725

Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/s…

Fix: 2.1.2+
Fix from $2,300 2026-02-06
Claude Code CRITICAL 9.1
CVE-2026-25722

Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write op…

Fix: 2.0.57+
Fix from $2,300 2026-02-06
Medical Center Portal Management System CRITICAL 9.8
CVE-2026-2059

A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.…

Mitigation only
Fix from $2,300 2026-02-06