Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2021-47819

ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code exe…

Mitigation only
Fix from $2,300 2026-01-15
Unclassified CRITICAL 9.8
CVE-2021-47781

Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of service condition through a malic…

Mitigation only
Fix from $2,300 2026-01-15
Unclassified CRITICAL 9.8
CVE-2021-47774

Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. A…

Mitigation only
Fix from $2,300 2026-01-15
Network Inventory Explorer CRITICAL 9.8
CVE-2021-47772

10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code …

Mitigation only
Fix from $2,300 2026-01-15
Cms CRITICAL 9.8
CVE-2021-47753

phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file…

Mitigation only
Fix from $2,300 2026-01-15
Invoiceplane CRITICAL 9.9
CVE-2025-67084

File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can late…

Fix: 1.6.4+
Fix from $2,300 2026-01-15
Tdc X401gl Firmware CRITICAL 9.1
CVE-2026-22910

The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. Thi…

Mitigation only
Fix from $2,300 2026-01-15
Tdc X401gl Firmware CRITICAL 9.1
CVE-2026-22909

Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potential…

Mitigation only
Fix from $2,300 2026-01-15
Tdc X401gl Firmware CRITICAL 9.1
CVE-2026-22908

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confi…

Fix: 1.4.0+
Fix from $2,300 2026-01-15
Tdc X401gl Firmware CRITICAL 9.1
CVE-2026-22907

An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data.

Fix: 1.4.0+
Fix from $2,300 2026-01-15
Freerdp CRITICAL 9.1
CVE-2026-22859

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑suppli…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.1
CVE-2026-22858

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding pa…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.8
CVE-2026-22857

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is …

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.1
CVE-2026-22855

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path wh…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.8
CVE-2026-22854

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlle…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.8
CVE-2026-22853

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the o…

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Freerdp CRITICAL 9.8
CVE-2026-22852

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in …

Fix: 3.20.1+
Fix from $2,300 2026-01-14
Cursor CRITICAL 9.8
CVE-2026-22708

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce…

Fix: 2.3+
Fix from $2,300 2026-01-14
Freeimage CRITICAL 9.8
CVE-2025-70968

FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().

Mitigation only
Fix from $2,300 2026-01-14
Edgeconnect Sd Wan Orchestrator CRITICAL 9.8
CVE-2025-37184

A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requireme…

Fix: 9.3.6 / 9.4.3+
Fix from $2,300 2026-01-14
Bluvoyix CRITICAL 9.8
CVE-2026-22238

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this…

Mitigation only
Fix from $2,300 2026-01-14
Bluvoyix CRITICAL 9.8
CVE-2026-22237

The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit th…

Mitigation only
Fix from $2,300 2026-01-14
Bluvoyix CRITICAL 9.8
CVE-2026-22236

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit th…

Mitigation only
Fix from $2,300 2026-01-14
Unclassified CRITICAL 9.8
CVE-2026-23550EPSS 21%

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: fr…

Mitigation only
Fix from $2,300 2026-01-14
Unclassified CRITICAL 9.8
CVE-2025-14502

The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the templa…

Mitigation only
Fix from $2,300 2026-01-14
Unclassified CRITICAL 9.8
CVE-2025-14301

The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is d…

Mitigation only
Fix from $2,300 2026-01-14
Enclave CRITICAL 10.0
CVE-2026-22686

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in…

Fix: 2.7.0+
Fix from $2,300 2026-01-14
Webgrind CRITICAL 9.8
CVE-2023-54339

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter…

Fix: after 1.1
Fix from $2,300 2026-01-13
Multi Server CRITICAL 9.1
CVE-2023-54337

Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the applicatio…

No fix yet
Fix from $2,300 2026-01-13
Extplorer CRITICAL 9.8
CVE-2023-54335EPSS 5%

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request.…

Fix: after 2.1.14
Fix from $2,300 2026-01-13