Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-6644 A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r… Data Master 4.3.3.RR42 / 5.1.2.reo1+ Fix from $2,3002026-04-20 CRITICAL 9.9 CVE-2026-6643 A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing u… Data Master 4.3.3.RR42 / 5.1.2.reo1+ Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-32956 SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbit… Sd 330ac Firmware 1.50 / 5.1.0+ Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-41242 protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in… Protobufjs 7.5.5+ Fix from $2,3002026-04-18 CRITICAL 9.8 CVE-2026-40494 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 45d48d1f2e8e0d… Patch available Fix from $2,3002026-04-18 CRITICAL 9.8 CVE-2026-40493 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3f… Patch available Fix from $2,3002026-04-18 CRITICAL 9.8 CVE-2026-40492 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb… Patch available Fix from $2,3002026-04-18 CRITICAL 9.0 CVE-2026-40487 Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitr… Postiz 2.21.6+ Fix from $2,3002026-04-18 CRITICAL 9.0 CVE-2026-40572 NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 use… Novumos 0.24+ Fix from $2,3002026-04-18 CRITICAL 9.3 CVE-2026-40317 NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary … Novumos 0.24+ Fix from $2,3002026-04-18 CRITICAL 9.1 CVE-2026-40582 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and… Patch available Fix from $2,3002026-04-18 CRITICAL 9.1 CVE-2026-40484 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive… Patch available Fix from $2,3002026-04-18 CRITICAL 9.1 CVE-2026-40324 Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Ut… Patch available Fix from $2,3002026-04-18 CRITICAL 9.1 CVE-2026-5720 miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or infor… Miniupnpd 2.3.10+ Fix from $2,3002026-04-17 CRITICAL 9.0 CVE-2026-40478 Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulne… Thymeleaf 3.1.4+ Fix from $2,3002026-04-17 CRITICAL 9.0 CVE-2026-40477 Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulne… Thymeleaf 3.1.4+ Fix from $2,3002026-04-17 CRITICAL 9.8 CVE-2026-40351 FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without run… Fastgpt 4.14.9.5+ Fix from $2,3002026-04-17 CRITICAL 9.1 CVE-2026-40258 The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerabil… Patch available Fix from $2,3002026-04-17 CRITICAL 9.8 CVE-2026-29013 libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c reli… Libcoap 4.3.5b+ Fix from $2,3002026-04-17 CRITICAL 9.1 CVE-2026-33689 xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing log… Xrdp 0.10.6+ Fix from $2,3002026-04-17 CRITICAL 9.1 CVE-2026-23500 Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT … Dolibarr Erp\/crm 23.0.0+ Fix from $2,3002026-04-17 CRITICAL 9.9 CVE-2026-40342 Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader con… Firebird 3.0.14 / 4.0.7+ Fix from $2,3002026-04-17 CRITICAL 9.8 CVE-2026-35546 Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant … Cx7 Firmware Mitigation only Fix from $2,3002026-04-17 CRITICAL 9.1 CVE-2026-33516 xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capability exchange phase. The … Xrdp 0.10.6+ Fix from $2,3002026-04-17 CRITICAL 9.1 CVE-2026-40525 OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authenticatio… Openviking 0.3.9+ Fix from $2,3002026-04-17 CRITICAL 9.1 CVE-2026-40518 ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation whe… Deerflow Patch available Fix from $2,3002026-04-17 CRITICAL 9.1 CVE-2026-6284 An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited… Mitigation only Fix from $2,3002026-04-17 CRITICAL 9.8 CVE-2026-41153 In JetBrains Junie before 252.549.29 command execution was possible via malicious project file Junie 252.549.29+ Fix from $2,3002026-04-17 CRITICAL 9.8 CVE-2026-37749 A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication … Mitigation only Fix from $2,3002026-04-17 CRITICAL 9.8 CVE-2025-15625 Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases. Pro Cloud Server Mitigation only Fix from $2,3002026-04-17