Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-7124 A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7123 A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the compon… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7122 A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the … Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7121 A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the compone… Mitigation only Fix from $2,3002026-04-27 CRITICAL 10.0 CVE-2026-33453EPSS 6% Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's ca… Camel after 4.14.5 Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-22337 Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Socia… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.3 CVE-2026-22336 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This i… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-41409 The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be deserialized … Mina 2.0.28 / 2.1.11+ Fix from $2,3002026-04-27 CRITICAL 9.4 CVE-2026-33454 The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterSt… Camel 4.14.6 / 4.18.1+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-41635 Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not check the class at … Mina 2.0.28 / 2.1.11+ Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-40860 JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessa… Camel 4.14.7 / 4.18.2+ Fix from $2,3002026-04-27 CRITICAL 9.9 CVE-2026-40453 The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable… Camel 4.14.6 / 4.18.2+ Fix from $2,3002026-04-27 CRITICAL 9.3 CVE-2026-42363 An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broa… Mitigation only Fix from $2,3002026-04-27 CRITICAL 9.8 CVE-2026-7037 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstec… Mitigation only Fix from $2,3002026-04-26 CRITICAL 9.8 CVE-2026-7036 A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP… I9 Firmware Mitigation only Fix from $2,3002026-04-26 CRITICAL 9.8 CVE-2026-6987 A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher … Picoclaw after 0.2.4 Fix from $2,3002026-04-25 CRITICAL 9.4 CVE-2026-31685 In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` … Linux Kernel 6.6.136 / 6.12.83+ Fix from $2,3002026-04-25 CRITICAL 9.1 CVE-2026-31682 In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-04-25 CRITICAL 9.8 CVE-2026-6951 Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://… Simple Git 3.36.0+ Fix from $2,3002026-04-25 CRITICAL 9.9 CVE-2026-41478 Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability … Saltcorn 1.4.6 / 1.5.6+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41473 CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated … Cyberpanel 2.4.4+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41248 Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro c… Mitigation only Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41475 BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-sta… Bacnet Stack 1.4.3+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41428 Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-a… Budibase 3.35.4+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-41492 Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/v… Dgraph 25.3.3+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41415 PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a mal… Pjsip 2.17+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41328 Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attack… Dgraph 25.3.3+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41327 Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attack… Dgraph 25.3.3+ Fix from $2,3002026-04-24 CRITICAL 10.0 CVE-2026-42043 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axio… Axios 0.31.1 / 1.15.1+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-42044 Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollutio… Axios 1.15.1+ Fix from $2,3002026-04-24