Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.8
CVE-2026-0905

Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially o…

Fix: 144.0.7559.59 / 144.0.7559.60+
Fix from $2,300 2026-01-20
Orval CRITICAL 9.8
CVE-2026-23947

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vul…

Fix: 7.19.0 / 8.0.2+
Fix from $2,300 2026-01-20
Imagemagick CRITICAL 9.8
CVE-2026-23876

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffe…

Fix: 6.9.13-38 / 7.1.2-13+
Fix from $2,300 2026-01-20
Imagemagick CRITICAL 9.8
CVE-2026-22770

ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of d…

Fix: 7.1.2-13+
Fix from $2,300 2026-01-20
Crmeb CRITICAL 9.8
CVE-2026-1202

A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/Log…

Fix: after 5.6.3
Fix from $2,300 2026-01-20
Ksoa CRITICAL 9.8
CVE-2026-1179

A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the component HTTP GET Parameter H…

Mitigation only
Fix from $2,300 2026-01-19
Arcane CRITICAL 9.8
CVE-2026-23944

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be prox…

Fix: 1.13.2+
Fix from $2,300 2026-01-19
Alchemy Cms CRITICAL 9.9
CVE-2026-23885

Alchemy is an open source content management system engine written in Ruby on Rails. Prior to versions 7.4.12 and 8.0.3, the application uses the Rub…

Fix: 7.4.12 / 8.0.3+
Fix from $2,300 2026-01-19
Ksoa CRITICAL 9.8
CVE-2026-1178

A security vulnerability has been detected in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /kmf/select.jsp of th…

Mitigation only
Fix from $2,300 2026-01-19
Ksoa CRITICAL 9.8
CVE-2026-1177

A weakness has been identified in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /kmf/save_folder.jsp of the…

Mitigation only
Fix from $2,300 2026-01-19
Mytube CRITICAL 9.8
CVE-2026-23837

MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions …

Fix: 1.7.66+
Fix from $2,300 2026-01-19
School Management System CRITICAL 9.8
CVE-2026-1176

A security flaw has been discovered in itsourcecode School Management System 1.0. Affected is an unknown function of the file /subject/index.php. Per…

Mitigation only
Fix from $2,300 2026-01-19
Siyuan CRITICAL 9.6
CVE-2026-23852

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attac…

Fix: 3.5.4+
Fix from $2,300 2026-01-19
Tugtainer CRITICAL 9.1
CVE-2026-23846

Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transm…

Fix: 1.16.1+
Fix from $2,300 2026-01-19
Prime CRITICAL 9.8
CVE-2026-1173

A vulnerability was found in birkir prime up to 0.4.0.beta.0. The impacted element is an unknown function of the file /graphql of the component Graph…

Fix: after 0.4.0
Fix from $2,300 2026-01-19
Aion CRITICAL 9.8
CVE-2025-55252

HCL AION  version 2 is affected by a Weak Password Policy vulnerability. This can  allow the use of easily guessable passwords, potentially resulting…

Mitigation only
Fix from $2,300 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-23884

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-23883

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, `xf_Pointer_New` frees `cursorPixels` on failure, then `poi…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-23534

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-23533

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the RDPGFX Cle…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
Unclassified CRITICAL 9.9
CVE-2026-22797

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before …

Mitigation only
Fix from $2,300 2026-01-19
Aion CRITICAL 9.8
CVE-2025-55251

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code …

Mitigation only
Fix from $2,300 2026-01-19
Aion CRITICAL 9.8
CVE-2025-52660

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code …

Mitigation only
Fix from $2,300 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-23532

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP c…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-23531

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompre…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
Freerdp CRITICAL 9.8
CVE-2026-23530

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWi…

Fix: 3.21.0+
Fix from $2,300 2026-01-19
810 Firmware CRITICAL 9.8
CVE-2026-1162

A flaw has been found in UTT HiPER 810 1.7.4-141218. The impacted element is the function strcpy of the file /goform/setSysAdm. This manipulation of …

Mitigation only
Fix from $2,300 2026-01-19
Directory Management System CRITICAL 9.8
CVE-2026-1160

A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of t…

Mitigation only
Fix from $2,300 2026-01-19
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-1159

A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This issue affects some unknown processing of the file /order…

Mitigation only
Fix from $2,300 2026-01-19
Devolutions Server CRITICAL 9.8
CVE-2026-0610

SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12

Fix: 2025.3.14.0+
Fix from $2,300 2026-01-19