Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.2
CVE-2026-25547

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a de…

Mitigation only
Fix from $2,300 2026-02-04
Jinjava CRITICAL 9.8
CVE-2026-25526

JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJav…

Fix: 2.7.6 / 2.8.3+
Fix from $2,300 2026-02-04
Openslides CRITICAL 9.8
CVE-2026-25519

OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and elections of an assembly. Prior to v…

Fix: 4.2.29+
Fix from $2,300 2026-02-04
Unclassified CRITICAL 9.8
CVE-2025-13375

IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privile…

Mitigation only
Fix from $2,300 2026-02-04
Bambuddy CRITICAL 9.8
CVE-2026-25505

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for sign…

Fix: 0.1.7+
Fix from $2,300 2026-02-04
Langroid CRITICAL 9.6
CVE-2026-25481

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-4…

Fix: 0.59.32+
Fix from $2,300 2026-02-04
Riot CRITICAL 9.1
CVE-2026-25139

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded de…

Fix: after 2025.10
Fix from $2,300 2026-02-04
Glpi CRITICAL 9.1
CVE-2026-22247

GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through …

Fix: 11.0.5+
Fix from $2,300 2026-02-04
Unstructured CRITICAL 9.8
CVE-2025-64712

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, a…

Fix: 0.18.18+
Fix from $2,300 2026-02-04
N8n CRITICAL 9.9
CVE-2026-25115

n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to bre…

Fix: 2.4.8+
Fix from $2,300 2026-02-04
N8n CRITICAL 9.9
CVE-2026-25053

n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users…

Fix: 1.123.0 / 2.5.0+
Fix from $2,300 2026-02-04
N8n CRITICAL 9.9
CVE-2026-25052

n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenti…

Fix: 1.123.18 / 2.5.0+
Fix from $2,300 2026-02-04
N8n CRITICAL 9.9
CVE-2026-25049

n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify w…

Fix: 1.123.17 / 2.5.2+
Fix from $2,300 2026-02-04
Unclassified CRITICAL 9.8
CVE-2025-5329

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation …

Mitigation only
Fix from $2,300 2026-02-04
Tcis 3 Firmware CRITICAL 9.8
CVE-2025-59818

This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.

Fix: 9.2.3.3+
Fix from $2,300 2026-02-04
Bolo Solo CRITICAL 9.8
CVE-2026-1813

A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUp…

Fix: after 2.6.4
Fix from $2,300 2026-02-04
Unclassified CRITICAL 10.0
CVE-2026-1633

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthent…

Mitigation only
Fix from $2,300 2026-02-04
Bolo Solo CRITICAL 9.8
CVE-2026-1812

A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the file src/main/java/org/b3log/so…

Fix: after 2.6.4
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.1
CVE-2026-1632

MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthen…

Mitigation only
Fix from $2,300 2026-02-03
Qwik CRITICAL 10.0
CVE-2026-25150

Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function w…

Fix: 1.19.0+
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.3
CVE-2026-1341

Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.

Mitigation only
Fix from $2,300 2026-02-03
School Erp Pro CRITICAL 9.8
CVE-2020-37090

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upl…

Mitigation only
Fix from $2,300 2026-02-03
School Erp Pro CRITICAL 9.8
CVE-2020-37089

School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries throu…

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.8
CVE-2020-37080

webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delet…

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.8
CVE-2020-37075

LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows remote attackers to execute ar…

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.8
CVE-2020-37074

Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wiza…

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.8
CVE-2020-37071

CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a …

Mitigation only
Fix from $2,300 2026-02-03
Unclassified CRITICAL 9.8
CVE-2020-37070

CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attac…

Mitigation only
Fix from $2,300 2026-02-03
Ftp Utility CRITICAL 9.8
CVE-2020-37069

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Atta…

Mitigation only
Fix from $2,300 2026-02-03
Ftp Utility CRITICAL 9.8
CVE-2020-37068

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Atta…

Mitigation only
Fix from $2,300 2026-02-03