Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ax3 Firmware CRITICAL 9.8
CVE-2025-69762

Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote …

Mitigation only
Fix from $2,300 2026-01-21
Unclassified CRITICAL 9.8
CVE-2021-47875

GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buf…

Mitigation only
Fix from $2,300 2026-01-21
Unclassified CRITICAL 9.8
CVE-2021-47854

DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execu…

Mitigation only
Fix from $2,300 2026-01-21
Mini Mouse CRITICAL 9.8
CVE-2021-47851

Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP e…

Mitigation only
Fix from $2,300 2026-01-21
Graphql Engine CRITICAL 9.8
CVE-2021-47748

Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manip…

Mitigation only
Fix from $2,300 2026-01-21
Unified Communications Manager CRITICAL 9.8
CVE-2026-20045 KEV

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME…

Fix: 14su5+
Fix from $2,300 2026-01-21
Debian Linux CRITICAL 9.8
CVE-2026-24061 KEVEPSS 98%

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Fix: after 2.7
Fix from $2,300 2026-01-21
Unclassified CRITICAL 9.8
CVE-2025-15521

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeove…

Mitigation only
Fix from $2,300 2026-01-21
Wrangler CRITICAL 9.9
CVE-2026-0933

SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--com…

Fix: 3.114.17 / 4.59.1+
Fix from $2,300 2026-01-20
Agile Product Lifecycle Management For Process CRITICAL 9.8
CVE-2026-21969

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal). The support…

Mitigation only
Fix from $2,300 2026-01-20
HTTP Server CRITICAL 10.0
CVE-2026-21962 KEVEPSS 42%

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy P…

Patch available
Fix from $2,300 2026-01-20
Node.js CRITICAL 10.0
CVE-2026-21636

A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even …

Fix: 25.3.0+
Fix from $2,300 2026-01-20
Node.js CRITICAL 9.1
CVE-2025-55130

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink…

Fix: 20.20.0 / 22.22.0+
Fix from $2,300 2026-01-20
Ply CRITICAL 9.8
CVE-2025-56005EPSS 17%

An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the…

No fix yet
Fix from $2,300 2026-01-20
N104s R1 Firmware CRITICAL 9.8
CVE-2025-55423

A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port…

Fix: after 12.07.6
Fix from $2,300 2026-01-20
Xdocreport CRITICAL 9.8
CVE-2025-65482

An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a craft…

Fix: after 2.0.3
Fix from $2,300 2026-01-20
Xdocreport CRITICAL 9.8
CVE-2025-64087

A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execu…

Fix: after 2.1.0
Fix from $2,300 2026-01-20
Applinx CRITICAL 9.8
CVE-2025-36418

IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to cra…

Mitigation only
Fix from $2,300 2026-01-20
Unclassified CRITICAL 9.9
CVE-2026-22844EPSS 13%

A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote …

Mitigation only
Fix from $2,300 2026-01-20
Unclassified CRITICAL 9.8
CVE-2025-14533

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This i…

Mitigation only
Fix from $2,300 2026-01-20
Unclassified CRITICAL 9.8
CVE-2026-1221

PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote att…

Mitigation only
Fix from $2,300 2026-01-20
Chrome CRITICAL 9.8
CVE-2026-0907EPSS 8%

Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page.…

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $2,300 2026-01-20
Chrome CRITICAL 9.8
CVE-2026-0906

Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) vi…

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $2,300 2026-01-20
Chrome CRITICAL 9.8
CVE-2026-0905

Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially o…

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $2,300 2026-01-20
Orval CRITICAL 9.8
CVE-2026-23947

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vul…

Fix: 7.19.0 / 8.0.2+
Fix from $2,300 2026-01-20
Imagemagick CRITICAL 9.8
CVE-2026-23876

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffe…

Fix: 6.9.13-38 / 7.1.2-13+
Fix from $2,300 2026-01-20
Imagemagick CRITICAL 9.8
CVE-2026-22770

ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of d…

Fix: 7.1.2-13+
Fix from $2,300 2026-01-20
Crmeb CRITICAL 9.8
CVE-2026-1202

A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/Log…

Fix: after 5.6.3
Fix from $2,300 2026-01-20
Ksoa CRITICAL 9.8
CVE-2026-1179

A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the component HTTP GET Parameter H…

Mitigation only
Fix from $2,300 2026-01-19
Arcane CRITICAL 9.8
CVE-2026-23944

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be prox…

Fix: 1.13.2+
Fix from $2,300 2026-01-19