Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openproject CRITICAL 9.0
CVE-2026-24772

OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced…

Fix: 17.0.2+
Fix from $2,300 2026-01-28
66biolinks CRITICAL 9.1
CVE-2025-69602

A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after su…

No fix yet
Fix from $2,300 2026-01-28
Blue CRITICAL 9.9
CVE-2025-57795

Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configur…

Fix: 8.14.13+
Fix from $2,300 2026-01-28
Blue CRITICAL 9.1
CVE-2025-57794

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The applica…

Fix: 8.14.9+
Fix from $2,300 2026-01-28
Blue CRITICAL 10.0
CVE-2025-57792

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application e…

Fix: 8.14.9+
Fix from $2,300 2026-01-28
Unclassified CRITICAL 9.8
CVE-2020-36967

Zortam Mp3 Media Studio 27.60 contains a buffer overflow vulnerability in the library creation file selection process that allows remote code executi…

Mitigation only
Fix from $2,300 2026-01-28
Unclassified CRITICAL 9.8
CVE-2020-36964

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing s…

Mitigation only
Fix from $2,300 2026-01-28
Tendenci CRITICAL 9.8
CVE-2020-36962EPSS 11%

Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas d…

Mitigation only
Fix from $2,300 2026-01-28
Unclassified CRITICAL 9.8
CVE-2020-36961

10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbi…

Mitigation only
Fix from $2,300 2026-01-28
Jsonpath CRITICAL 9.8
CVE-2025-61140

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

Mitigation only
Fix from $2,300 2026-01-28
Unclassified CRITICAL 9.8
CVE-2026-1056EPSS 12%

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_di…

Mitigation only
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40554EPSS 58%

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke …

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40553EPSS 60%

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40552EPSS 50%

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to ex…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40551 KEVEPSS 84%

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40536 KEVEPSS 82%

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated att…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Dokploy CRITICAL 9.9
CVE-2026-24841

Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokp…

Fix: 0.26.6+
Fix from $2,300 2026-01-28
Clatter CRITICAL 9.1
CVE-2026-24785

Clatter is a no_std compatible, pure Rust implementation of the Noise protocol framework with post-quantum support. Versiosn prior to2.2.0 have a pro…

Fix: 2.2.0+
Fix from $2,300 2026-01-28
Sandboxjs CRITICAL 10.0
CVE-2026-23830

SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated …

Fix: 0.8.26+
Fix from $2,300 2026-01-28
Ragflow CRITICAL 9.8
CVE-2026-24770

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a …

Fix: after 0.23.1
Fix from $2,300 2026-01-27
Dozzle CRITICAL 9.9
CVE-2026-24740

Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restrict…

Fix: 9.0.3+
Fix from $2,300 2026-01-27
Unclassified CRITICAL 9.8
CVE-2025-21589

An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacke…

Mitigation only
Fix from $2,300 2026-01-27
Fortianalyzer CRITICAL 9.8
CVE-2026-24858 KEVEPSS 86%

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Fort…

Fix: 7.4.10 / 7.4.11+
Fix from $2,300 2026-01-27
Unclassified CRITICAL 10.0
CVE-2025-14988

A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the…

No fix yet
Fix from $2,300 2026-01-27
Gnupg CRITICAL 9.8
CVE-2026-24881

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflo…

Fix: 2.5.17 / 5.0.1+
Fix from $2,300 2026-01-27
Suricata CRITICAL 9.1
CVE-2026-22264

Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free cond…

Fix: 7.0.14 / 8.0.3+
Fix from $2,300 2026-01-27
Suricata CRITICAL 9.8
CVE-2026-22262

Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14,…

Fix: 7.0.14 / 8.0.3+
Fix from $2,300 2026-01-27
Kyverno CRITICAL 9.9
CVE-2026-22039

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bo…

Fix: 1.15.3 / 1.16.3+
Fix from $2,300 2026-01-27
Mobile Shop Management System CRITICAL 9.8
CVE-2025-69564

code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password,…

Mitigation only
Fix from $2,300 2026-01-27
Mobile Shop Management System CRITICAL 9.8
CVE-2025-69563

code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter.

Mitigation only
Fix from $2,300 2026-01-27