Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Semcms CRITICAL 9.8
CVE-2026-1552

A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of t…

Mitigation only
Fix from $2,300 2026-01-29
Maker.js CRITICAL 9.8
CVE-2026-24888

Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject`…

Fix: after 0.19.1
Fix from $2,300 2026-01-28
Bulk Extractor CRITICAL 9.8
CVE-2026-24857

`bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow…

Mitigation only
Fix from $2,300 2026-01-28
A7000r Firmware CRITICAL 9.8
CVE-2026-1547

A vulnerability was detected in Totolink A7000R 4.1cu.4154. This affects the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi. The manipul…

Mitigation only
Fix from $2,300 2026-01-28
Jsherp CRITICAL 9.8
CVE-2026-1546

A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshER…

Fix: after 3.6
Fix from $2,300 2026-01-28
School Management System CRITICAL 9.8
CVE-2026-1545

A weakness has been identified in itsourcecode School Management System 1.0. The affected element is an unknown function of the file /course/index.ph…

Mitigation only
Fix from $2,300 2026-01-28
Nocodb CRITICAL 9.0
CVE-2026-24769

NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS) vulnerability exists in Noco…

Fix: 0.301.0+
Fix from $2,300 2026-01-28
Online Music Site CRITICAL 9.8
CVE-2026-1535

A security vulnerability has been detected in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Administrator/PHP/Ad…

Mitigation only
Fix from $2,300 2026-01-28
Online Music Site CRITICAL 9.8
CVE-2026-1534

A weakness has been identified in code-projects Online Music Site 1.0. This affects an unknown function of the file /Administrator/PHP/AdminEditUser.…

Mitigation only
Fix from $2,300 2026-01-28
Online Music Site CRITICAL 9.8
CVE-2026-1533

A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PH…

Mitigation only
Fix from $2,300 2026-01-28
Discourse CRITICAL 9.9
CVE-2025-68662

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in Final…

Fix: 3.5.4 / 2025.11.2+
Fix from $2,300 2026-01-28
Openproject CRITICAL 9.0
CVE-2026-24772

OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced…

Fix: 17.0.2+
Fix from $2,300 2026-01-28
66biolinks CRITICAL 9.1
CVE-2025-69602

A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after su…

No fix yet
Fix from $2,300 2026-01-28
Blue CRITICAL 9.9
CVE-2025-57795

Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configur…

Fix: 8.14.13+
Fix from $2,300 2026-01-28
Blue CRITICAL 9.1
CVE-2025-57794

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The applica…

Fix: 8.14.9+
Fix from $2,300 2026-01-28
Blue CRITICAL 10.0
CVE-2025-57792

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application e…

Fix: 8.14.9+
Fix from $2,300 2026-01-28
Unclassified CRITICAL 9.8
CVE-2020-36967

Zortam Mp3 Media Studio 27.60 contains a buffer overflow vulnerability in the library creation file selection process that allows remote code executi…

Mitigation only
Fix from $2,300 2026-01-28
Unclassified CRITICAL 9.8
CVE-2020-36964

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing s…

Mitigation only
Fix from $2,300 2026-01-28
Tendenci CRITICAL 9.8
CVE-2020-36962EPSS 11%

Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas d…

Mitigation only
Fix from $2,300 2026-01-28
Unclassified CRITICAL 9.8
CVE-2020-36961

10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbi…

Mitigation only
Fix from $2,300 2026-01-28
Jsonpath CRITICAL 9.8
CVE-2025-61140

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

Mitigation only
Fix from $2,300 2026-01-28
Unclassified CRITICAL 9.8
CVE-2026-1056EPSS 12%

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_di…

Mitigation only
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40554EPSS 58%

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke …

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40553EPSS 60%

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40552EPSS 50%

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to ex…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40551 KEVEPSS 84%

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40536 KEVEPSS 82%

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated att…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Dokploy CRITICAL 9.9
CVE-2026-24841

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokp…

Fix: 0.26.6+
Fix from $2,300 2026-01-28
Clatter CRITICAL 9.1
CVE-2026-24785

Clatter is a no_std compatible, pure Rust implementation of the Noise protocol framework with post-quantum support. Versiosn prior to2.2.0 have a pro…

Fix: 2.2.0+
Fix from $2,300 2026-01-28
Sandboxjs CRITICAL 10.0
CVE-2026-23830

SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated …

Fix: 0.8.26+
Fix from $2,300 2026-01-28