Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2019-25710 Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute… Dolibarr Erp\/crm after 8.0.4 Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2019-25709 CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the … Image Hosting Script Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2019-25697 CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug… Cmssite Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6116 A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin… Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6115 A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setAppCfg of the file /cgi-bin/cstecgi.cgi of the component… Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6114 A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setNetworkCfg of the file /cgi-bin/cste… Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6113 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTtyServiceCfg … Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6112 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the… Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6110 A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.1. This affects the function generate_thoughts of the file metagpt/strategy/tot.… Metagpt Patch available Fix from $2,3002026-04-12 CRITICAL 9.3 CVE-2026-31845 A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/… Mitigation only Fix from $2,3002026-04-11 CRITICAL 9.8 CVE-2026-5059 aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on… Mitigation only Fix from $2,3002026-04-11 CRITICAL 9.8 CVE-2026-5058 aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte… Mitigation only Fix from $2,3002026-04-11 CRITICAL 9.8 CVE-2026-4149 Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary … Era 300 Firmware 83.1-61240+ Fix from $2,3002026-04-11 CRITICAL 9.8 CVE-2026-40190 LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith)… Langsmith 0.5.18+ Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-40189 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for direct… Goshs 2.0.0+ Fix from $2,3002026-04-10 CRITICAL 9.6 CVE-2026-30232 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 4.8.5, Chartb… Chartbrew 4.8.5+ Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-33707 Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email… Chamilo Lms 1.11.38+ Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-33698 Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ director… Chamilo Lms 1.11.38+ Fix from $2,3002026-04-10 CRITICAL 9.9 CVE-2026-5483 A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows… Openshift Ai 2.16.4 / 2.25.4+ Fix from $2,3002026-04-10 CRITICAL 9.1 CVE-2026-35652 OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows non-allowlisted senders to exec… Openclaw 2026.3.22+ Fix from $2,3002026-04-10 CRITICAL 9.1 CVE-2026-34727 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking wh… Vikunja 2.3.0+ Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-23781 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the appl… Control M\/managed File Transfer after 9.0.22 Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-36236 SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter. Engineers Online Portal Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-36235 A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this is… Online Student Enrollment System Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-36234 itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter. Online Student Enrollment System Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-36233 A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason fo… Online Student Enrollment System Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-36232 A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this … Online Student Enrollment System Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-29861 PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php. Mitigation only Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2025-44560 owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking. No fix yet Fix from $2,3002026-04-10 CRITICAL 9.6 CVE-2026-6068 NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global d… Netwide Assembler No fix yet Fix from $2,3002026-04-10