Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-70067 Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, w… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.1 CVE-2026-7482 Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied… Ollama 0.17.1+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-7747 A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function loginauth of the file /cgi-bin… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2025-14320 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Tra… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-29200 A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows … Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-7719 A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. The affected element is the function loginauth of the file /cgi-bin/cstec… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.0 CVE-2026-7372 A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can l… Gv Vms Firmware 21.0.0+ Fix from $2,3002026-05-04 CRITICAL 9.3 CVE-2026-7161 An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broa… Gv Ip Device Utility Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42370 A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can l… Gv Vms Firmware 21.0.0+ Fix from $2,3002026-05-04 CRITICAL 10.0 CVE-2026-42369 GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other security devices. It is a native app… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42368 A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request ca… Gv Lpc2011 Firmware Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-7690 A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm of the file /cgi-bin/adm.cgi. … Wl Wn570ha1 Firmware Mitigation only Fix from $2,3002026-05-03 CRITICAL 9.8 CVE-2026-7458 The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This i… Mitigation only Fix from $2,3002026-05-02 CRITICAL 9.8 CVE-2026-4882 The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_A… Mitigation only Fix from $2,3002026-05-02 CRITICAL 10.0 CVE-2026-37541 Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is n… Open Vehicle Monitoring System Firmware Mitigation only Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-37540 OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it performs multiplication of tw… Openamp Mitigation only Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-37539 Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and decoder.cpp in function decodeFr… Mitigation only Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-37534 Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Transport_Proto… Mitigation only Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-37531 AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the … Automotive Grade Linux after 17.1.12 Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-42473 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesyste… Mitigation only Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-42472 Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the … Mitigation only Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-43039 In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix missing data copy and wrong recycle in ZC RX dispatch… Linux Kernel 6.19.12+ Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-43038 In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review … Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-43037 In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following … Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-43011 In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-42484 A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly … Hashcat Mitigation only Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-42483 A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitr… Hashcat Mitigation only Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-42482 A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a deni… Hashcat Mitigation only Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-31718 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger When a du… Linux Kernel 6.7 / 6.12.84+ Fix from $2,3002026-05-01 CRITICAL 9.8 CVE-2026-31705 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment smb2_get_ea() appl… Linux Kernel 5.16 / 6.2+ Fix from $2,3002026-05-01