Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ragflow CRITICAL 9.8
CVE-2026-24770

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a …

Fix: after 0.23.1
Fix from $2,300 2026-01-27
Dozzle CRITICAL 9.9
CVE-2026-24740

Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restrict…

Fix: 9.0.3+
Fix from $2,300 2026-01-27
Unclassified CRITICAL 9.8
CVE-2025-21589

An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacke…

Mitigation only
Fix from $2,300 2026-01-27
Fortianalyzer CRITICAL 9.8
CVE-2026-24858 KEVEPSS 86%

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Fort…

Fix: 7.4.10 / 7.4.11+
Fix from $2,300 2026-01-27
Unclassified CRITICAL 10.0
CVE-2025-14988

A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the…

No fix yet
Fix from $2,300 2026-01-27
Gnupg CRITICAL 9.8
CVE-2026-24881

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflo…

Fix: 2.5.17 / 5.0.1+
Fix from $2,300 2026-01-27
Suricata CRITICAL 9.1
CVE-2026-22264

Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free cond…

Fix: 7.0.14 / 8.0.3+
Fix from $2,300 2026-01-27
Suricata CRITICAL 9.8
CVE-2026-22262

Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14,…

Fix: 7.0.14 / 8.0.3+
Fix from $2,300 2026-01-27
Kyverno CRITICAL 9.9
CVE-2026-22039

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bo…

Fix: 1.15.3 / 1.16.3+
Fix from $2,300 2026-01-27
Mobile Shop Management System CRITICAL 9.8
CVE-2025-69564

code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password,…

Mitigation only
Fix from $2,300 2026-01-27
Mobile Shop Management System CRITICAL 9.8
CVE-2025-69563

code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter.

Mitigation only
Fix from $2,300 2026-01-27
Mobile Shop Management System CRITICAL 9.8
CVE-2025-69562

code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter.

Mitigation only
Fix from $2,300 2026-01-27
Computer Book Store CRITICAL 9.8
CVE-2025-69559

code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.

Mitigation only
Fix from $2,300 2026-01-27
Xray Monolith CRITICAL 9.1
CVE-2026-24874

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before …

Fix: 2025.12.30+
Fix from $2,300 2026-01-27
Unclassified CRITICAL 9.8
CVE-2026-24872

improper pointer arithmetic vulnerability in ProjectSkyfire SkyFire_548.This issue affects SkyFire_548: before 5.4.8-stable5.

Patch available
Fix from $2,300 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24871

Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects Minecraft-Rcon-Mana…

Patch available
Fix from $2,300 2026-01-27
Ix Ray Engine 1.6 CRITICAL 9.8
CVE-2026-24832

Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

Fix: 1.3+
Fix from $2,300 2026-01-27
Mobile Shop Management System CRITICAL 9.8
CVE-2025-69565

code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.

Mitigation only
Fix from $2,300 2026-01-27
Debian Linux CRITICAL 9.8
CVE-2025-68670

xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from im…

Fix: 0.10.5+
Fix from $2,300 2026-01-27
Unclassified CRITICAL 9.8
CVE-2021-47901

Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected e…

Mitigation only
Fix from $2,300 2026-01-27
Unclassified CRITICAL 9.8
CVE-2021-47900

Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system comm…

Mitigation only
Fix from $2,300 2026-01-27
Unclassified CRITICAL 9.8
CVE-2020-36948

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attac…

Mitigation only
Fix from $2,300 2026-01-27
Knockpy CRITICAL 9.8
CVE-2020-36941

Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server he…

Mitigation only
Fix from $2,300 2026-01-27
Unclassified CRITICAL 9.8
CVE-2020-36940

Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows attackers to crash the applica…

Mitigation only
Fix from $2,300 2026-01-27
N8n CRITICAL 9.9
CVE-2026-1470EPSS 19%

n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated…

Fix: 1.123.17 / 2.4.5+
Fix from $2,300 2026-01-27
Unclassified CRITICAL 9.8
CVE-2026-24830

Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.

Patch available
Fix from $2,300 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24826

Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability i…

Patch available
Fix from $2,300 2026-01-27
Ezcast Pro Dongle Ii Firmware CRITICAL 9.1
CVE-2026-24346

Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web applicat…

Mitigation only
Fix from $2,300 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24823

Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in FASTSHIFT X-TRACK (Software/X-Track/USER…

Patch available
Fix from $2,300 2026-01-27
Unclassified CRITICAL 10.0
CVE-2026-24822

Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files…

Patch available
Fix from $2,300 2026-01-27