Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-5058 aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… Mitigation only Fix from $2,3002026-04-11 CRITICAL 9.8 CVE-2026-4149 Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary … Era 300 Firmware 83.1-61240+ Fix from $2,3002026-04-11 CRITICAL 9.8 CVE-2026-40190 LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith)… Langsmith 0.5.18+ Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-40189 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for direct… Goshs 2.0.0+ Fix from $2,3002026-04-10 CRITICAL 9.6 CVE-2026-30232 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartb… Chartbrew 4.8.5+ Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-33707 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email… Chamilo Lms 1.11.38+ Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-33698 Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ director… Chamilo Lms 1.11.38+ Fix from $2,3002026-04-10 CRITICAL 9.9 CVE-2026-5483 A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows… Openshift Ai 2.16.4 / 2.25.4+ Fix from $2,3002026-04-10 CRITICAL 9.1 CVE-2026-35652 OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows non-allowlisted senders to exec… Openclaw 2026.3.22+ Fix from $2,3002026-04-10 CRITICAL 9.1 CVE-2026-34727 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking wh… Vikunja 2.3.0+ Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-23781 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the appl… Control M\/managed File Transfer after 9.0.22 Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-36236 SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter. Engineers Online Portal Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-36235 A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this is… Online Student Enrollment System Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-36234 itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter. Online Student Enrollment System Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-36233 A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason fo… Online Student Enrollment System Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-36232 A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this … Online Student Enrollment System Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-29861 PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php. Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2025-44560 owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking. No fix yet Fix from $2,3002026-04-10 CRITICAL 9.6 CVE-2026-6068 NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global d… Netwide Assembler No fix yet Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-6057 FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrar… Patch available Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-6029 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setVpnAccountCfg of the file /cgi-bin/cst… Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-6028 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setPptpServerCfg of the file /cgi-bin/c… Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-6027 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the function setUrlFilterRules of the file /cgi-bin/cstec… Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-6026 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setPortalConfWeChat of the file… Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.6 CVE-2026-1115 A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.… Lollms after 2.1.0 Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-6025 A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of t… Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-6024 A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP … I6 Firmware Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-5997 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setLoginPasswordCfg of the file /cgi-bin/… Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-5996 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setAdvancedInfoShow of the … Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-5995 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.… Mitigation only Fix from $2,3002026-04-10