Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-7156 A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the com… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7155 A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPasswordCfg of the file /cgi-bi… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7154 A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cg… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.4 CVE-2024-46636 NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category … Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7153 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7152 A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecg… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-35903 MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Dige… Mipc252w Firmware Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-31255 A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where i… Ac18 Firmware Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7140 A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the c… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7139 A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of th… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7138 A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg of the file /cgi-bin/cstecgi.… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7137 A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cste… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7136 A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-41462 ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is d… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-30352 A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitr… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.1 CVE-2026-40514 SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption wi… Smartermail 100.0.9610+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7125 A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cs… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7124 A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7123 A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the compon… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7122 A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the … Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7121 A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the compone… Mitigation only Fix from $2,3002026-04-27 CRITICAL 10.0 CVE-2026-33453EPSS 6% Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's ca… Camel after 4.14.5 Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-22337 Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Socia… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.3 CVE-2026-22336 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This i… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-41409 The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized … Mina 2.0.28 / 2.1.11+ Fix from $2,3002026-04-27 CRITICAL 9.4 CVE-2026-33454 The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt… Camel 4.14.6 / 4.18.1+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-41635 Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at … Mina 2.0.28 / 2.1.11+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-40860 JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa… Camel 4.14.7 / 4.18.2+ Fix from $2,3002026-04-27 CRITICAL 9.9 CVE-2026-40453 The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable… Camel 4.14.6 / 4.18.2+ Fix from $2,3002026-04-27 CRITICAL 9.3 CVE-2026-42363 An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broa… Mitigation only Fix from $2,3002026-04-27