Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-9559 A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files during campaign imports, a flaw … Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41277 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41276 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41275 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41274 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41273 Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and R… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41272 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41270 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2025-41269 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console W… Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.1 CVE-2025-41268 Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 … Wf 500 Firmware after 7.9.1.0_r2502171040 Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-9558 A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-49201 The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows an attacker to decrypt, modify… Wave 7 Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-49200 The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentia… Wave 7 Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-49199 Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. Predator Connect W6x Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-49197 Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requests when Base64 decoding fai… Predator Connect W6x Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-3655 The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-8732EPSS 22% The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.6 CVE-2026-9967 Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted H… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $2,3002026-05-28 CRITICAL 9.6 CVE-2026-9918 Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a… Chrome 148.0.7778.216+ Fix from $2,3002026-05-28 CRITICAL 9.0 CVE-2026-9891 Use after free in Extensions in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potential… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $2,3002026-05-28 CRITICAL 9.6 CVE-2026-9886 Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafte… Chrome 148.0.7778.216+ Fix from $2,3002026-05-28 CRITICAL 9.0 CVE-2026-9881 Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension… Chrome 148.0.7778.216+ Fix from $2,3002026-05-28 CRITICAL 9.6 CVE-2026-9876 Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a c… Chrome 148.0.7778.216+ Fix from $2,3002026-05-28 CRITICAL 9.6 CVE-2026-9875 Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via… Chrome 148.0.7778.216+ Fix from $2,3002026-05-28 CRITICAL 9.6 CVE-2026-9874 Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $2,3002026-05-28 CRITICAL 9.6 CVE-2026-9872 Out of bounds write in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via … Chrome 148.0.7778.216+ Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-8809 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and inclu… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.9 CVE-2026-44881 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber… Portainer 2.33.8 / 2.39.2+ Fix from $2,3002026-05-28 CRITICAL 9.9 CVE-2026-9645 Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabli… Scadabr Mitigation only Fix from $2,3002026-05-28 CRITICAL 10.0 CVE-2026-46840 Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are 24.2.0-26.1.0. Easily exploit… Rest Data Services after 26.1.0 Fix from $2,3002026-05-28