Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-9406 A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the… Mitigation only Fix from $2,3002026-05-25 CRITICAL 9.8 CVE-2026-9405 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.c… Mitigation only Fix from $2,3002026-05-25 CRITICAL 9.8 CVE-2026-9404 A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the … Mitigation only Fix from $2,3002026-05-24 CRITICAL 9.8 CVE-2026-9388 A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cste… Mitigation only Fix from $2,3002026-05-24 CRITICAL 9.8 CVE-2026-9387 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/c… Mitigation only Fix from $2,3002026-05-24 CRITICAL 9.8 CVE-2026-9386 A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of t… Mitigation only Fix from $2,3002026-05-24 CRITICAL 9.8 CVE-2026-9385 A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi… Mitigation only Fix from $2,3002026-05-24 CRITICAL 9.8 CVE-2026-9384 A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstec… Mitigation only Fix from $2,3002026-05-24 CRITICAL 9.8 CVE-2018-25357 Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PH… Dolibarr Erp\/crm after 7.0.3 Fix from $2,3002026-05-23 CRITICAL 9.8 CVE-2018-25350 userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requ… Mitigation only Fix from $2,3002026-05-23 CRITICAL 9.8 CVE-2026-47280 Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. Azure Resource Manager No fix yet Fix from $2,3002026-05-22 CRITICAL 10.0 CVE-2026-42901 Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. Entra Id Mitigation only Fix from $2,3002026-05-22 CRITICAL 9.3 CVE-2026-41090 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t… 365 Copilot Mitigation only Fix from $2,3002026-05-22 CRITICAL 9.8 CVE-2026-40412 Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. Azure Orbital Spatio Mitigation only Fix from $2,3002026-05-22 CRITICAL 9.8 CVE-2026-33843 Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privilege… Entra Id Mitigation only Fix from $2,3002026-05-22 CRITICAL 9.8 CVE-2026-23652 Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu… Power Pages Mitigation only Fix from $2,3002026-05-22 CRITICAL 9.3 CVE-2026-48700 An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileMa… Mitigation only Fix from $2,3002026-05-22 CRITICAL 10.0 CVE-2026-33712 Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allo… Mitigation only Fix from $2,3002026-05-22 CRITICAL 9.8 CVE-2026-32253 Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed… Sunshine 2026.516.143833+ Fix from $2,3002026-05-22 CRITICAL 9.6 CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--exampl… Net 0.55.0+ Fix from $2,3002026-05-22 CRITICAL 9.1 CVE-2026-8673 Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avan… Avantra 25.3.0+ Fix from $2,3002026-05-22 CRITICAL 9.6 CVE-2026-8670 Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This… Avantra 25.3.1+ Fix from $2,3002026-05-22 CRITICAL 9.8 CVE-2026-44930 An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi… Cxf 3.6.11 / 4.1.6+ Fix from $2,3002026-05-22 CRITICAL 9.2 CVE-2026-9054 An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic. Mitigation only Fix from $2,3002026-05-22 CRITICAL 10.0 CVE-2026-46595 Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than pu… Crypto 0.52.0+ Fix from $2,3002026-05-22 CRITICAL 9.1 CVE-2026-42508EPSS 7% Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are check… Crypto 0.52.0+ Fix from $2,3002026-05-22 CRITICAL 9.1 CVE-2026-39834 When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the w… Crypto 0.52.0+ Fix from $2,3002026-05-22 CRITICAL 9.1 CVE-2026-39833 The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign … Crypto 0.52.0+ Fix from $2,3002026-05-22 CRITICAL 9.1 CVE-2026-39831 The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence … Crypto 0.52.0+ Fix from $2,3002026-05-22 CRITICAL 9.1 CVE-2026-39832 When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destinatio… Crypto 0.52.0+ Fix from $2,3002026-05-22