Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-5166 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institu… Mitigation only Fix from $2,3002026-04-29 CRITICAL 9.8 CVE-2026-41940 KEVEPSS 99% cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to … Wp Squared 86.0.41 / 110.0.97+ Fix from $2,3002026-04-29 CRITICAL 9.8 CVE-2026-38992 Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows a… Mitigation only Fix from $2,3002026-04-29 CRITICAL 9.8 CVE-2026-36841 TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function. Mitigation only Fix from $2,3002026-04-29 CRITICAL 9.0 CVE-2026-42523 Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHu… GitHub 1.46.0.1+ Fix from $2,3002026-04-29 CRITICAL 9.8 CVE-2026-42249 Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP respon… Ollama after 0.17.5 Fix from $2,3002026-04-29 CRITICAL 9.8 CVE-2026-42248 Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows impl… Ollama after 0.17.5 Fix from $2,3002026-04-29 CRITICAL 10.0 CVE-2026-3325 SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The v… Mitigation only Fix from $2,3002026-04-29 CRITICAL 9.6 CVE-2026-7333 Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p… Chrome 147.0.7727.138+ Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-41446 Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MA… Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.6 CVE-2026-41397 OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation du… Openclaw 2026.3.31+ Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-41386 OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes… Openclaw 2026.3.22+ Fix from $2,3002026-04-28 CRITICAL 9.4 CVE-2026-3893 The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its con… Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-24178 NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause author… Nvflare 2.7.2+ Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-41873 ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading t… Pony Mail Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2025-60889 Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or othe… Hpx after 1.11.0 Fix from $2,3002026-04-28 CRITICAL 9.6 CVE-2026-7321 Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150… Firefox 140.10.1 / 150.0+ Fix from $2,3002026-04-28 CRITICAL 9.4 CVE-2026-7248 A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. Th… Di 8100 Firmware No fix yet Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-7244 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cg… Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-7243 A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi… Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-7242 A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi… Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-7241 A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi o… Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-7240 A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAccountCfg of the file /cgi-bin… Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-7204 A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi… Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-7203 A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cst… Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-7202 A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of… Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-32644 Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys. Mitigation only Fix from $2,3002026-04-28 CRITICAL 9.1 CVE-2026-40976 In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be v… Spring Boot 4.0.6+ Fix from $2,3002026-04-28 CRITICAL 9.8 CVE-2026-40974 Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring… Spring Boot 2.7.33 / 3.3.19+ Fix from $2,3002026-04-28 CRITICAL 9.1 CVE-2026-40971 When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitM… Spring Boot 3.5.14 / 4.0.6+ Fix from $2,3002026-04-27