Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-1432

SQL injection vulnerability in the Buroweb platform version 2505.0.12, specifically in the 'tablon' component. This vulnerability is present in sever…

Mitigation only
Fix from $2,300 2026-02-03
Moodle CRITICAL 9.8
CVE-2025-67856

A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges…

Fix: 4.1.22 / 4.4.12+
Fix from $2,300 2026-02-03
Wab S300iw Pd Firmware CRITICAL 9.8
CVE-2026-24465

Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code execution.

Fix: 1.13 / 5.5.02+
Fix from $2,300 2026-02-03
Data Master CRITICAL 9.8
CVE-2026-24936

When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr…

Fix: 5.1.2.re51+
Fix from $2,300 2026-02-03
Mediawiki CRITICAL 9.8
CVE-2025-67484

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php. This issue affec…

Fix: 1.39.16 / 1.43.6+
Fix from $2,300 2026-02-03
Sandboxjs CRITICAL 10.0
CVE-2026-25142

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain proto…

Fix: 0.8.27+
Fix from $2,300 2026-02-02
Unclassified CRITICAL 9.1
CVE-2026-25137EPSS 10%

The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the …

Patch available
Fix from $2,300 2026-02-02
Unclassified CRITICAL 9.3
CVE-2026-24471

continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote server to cause the local server t…

No fix yet
Fix from $2,300 2026-02-02
Facturascripts CRITICAL 9.0
CVE-2026-23997

FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulne…

Fix: 2025.71+
Fix from $2,300 2026-02-02
Vllm CRITICAL 9.8
CVE-2026-22778

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multim…

Fix: 0.14.1+
Fix from $2,300 2026-02-02
Im Server CRITICAL 9.8
CVE-2025-66480

Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component re…

Fix: 1.4.3+
Fix from $2,300 2026-02-02
Unclassified CRITICAL 9.8
CVE-2022-50981

An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is …

Mitigation only
Fix from $2,300 2026-02-02
Skspro CRITICAL 9.8
CVE-2025-8587

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Technology R&D Industry and Trade…

Fix: after 2026-07-01
Fix from $2,300 2026-02-02
Unclassified CRITICAL 9.1
CVE-2024-5986

A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploi…

Mitigation only
Fix from $2,300 2026-02-02
Unclassified CRITICAL 9.6
CVE-2024-2356

A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically withi…

Patch available
Fix from $2,300 2026-02-02
Matter CRITICAL 9.8
CVE-2026-20418

In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additiona…

Fix: after 1.4
Fix from $2,300 2026-02-02
Nbiot Sdk CRITICAL 9.3
CVE-2026-20407

In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with …

Fix: after 3.8
Fix from $2,300 2026-02-02
Unclassified CRITICAL 9.8
CVE-2025-15030

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to re…

Mitigation only
Fix from $2,300 2026-02-02
Magicinfo 9 Server CRITICAL 9.8
CVE-2026-25202

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects M…

Fix: 21.1090.1+
Fix from $2,300 2026-02-02
Magicinfo 9 Server CRITICAL 9.8
CVE-2026-25200

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in …

Fix: 21.1090.1+
Fix from $2,300 2026-02-02
A8004t Firmware CRITICAL 9.8
CVE-2026-1740

A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the compo…

Mitigation only
Fix from $2,300 2026-02-02
Unclassified CRITICAL 9.3
CVE-2026-25069

SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log file API endpoints. An unauth…

Mitigation only
Fix from $2,300 2026-02-01
Online Exam System CRITICAL 9.8
CVE-2020-37057

Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through th…

Mitigation only
Fix from $2,300 2026-01-30
Unclassified CRITICAL 9.8
CVE-2020-37056

Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating reque…

Mitigation only
Fix from $2,300 2026-01-30
Unclassified CRITICAL 9.8
CVE-2020-37052

AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system …

Mitigation only
Fix from $2,300 2026-01-30
Unclassified CRITICAL 9.8
CVE-2020-37050

Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with care…

Mitigation only
Fix from $2,300 2026-01-30
Unclassified CRITICAL 9.8
CVE-2020-37043

10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR, and DEP protections through c…

Mitigation only
Fix from $2,300 2026-01-30
Unclassified CRITICAL 9.8
CVE-2020-37027

Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the ext…

Mitigation only
Fix from $2,300 2026-01-30
Unclassified CRITICAL 9.8
CVE-2019-25232

NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary she…

Mitigation only
Fix from $2,300 2026-01-30
Orval CRITICAL 9.8
CVE-2026-25141

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7…

Fix: 7.21.0 / 8.2.0+
Fix from $2,300 2026-01-30