Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-36057 Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $… Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-4277 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated o… Django 4.2.30 / 5.2.13+ Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-35458 Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns wi… Gotenberg 8.29.1+ Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-30079 In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authenticati… Oai Cn5g Amf No fix yet Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-24450 An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious fi… Libraw Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-21413 A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A speciall… Libraw Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-20911 A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially cr… Libraw Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-20889 A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file … Libraw Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-20884 An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can l… Libraw Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2025-62818 An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24… Exynos 990 Firmware Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2025-52909 An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W… Exynos W1000 Firmware Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-5735 Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that wi… Firefox 149.0.2+ Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-5734 Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed eviden… Firefox 140.9.1 / 149.0.2+ Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-5731 Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of th… Firefox Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-28808 Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when se… Erlang\/inets 9.1.0.6 / 9.3.2.4+ Fix from $2,3002026-04-07 CRITICAL 9.6 CVE-2026-23818 A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacke… Aruba Networking Private 5g Core 1.25.3.1+ Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-22679EPSS 21% Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/dev… E Cology 20260312+ Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2021-4473EPSS 6% Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated… Tianxin Internet Behavior Management System 4.0.0.7_20210716.180815+ Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-1114 In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key f… Lollms Patch available Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2025-65115 Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows… Job Management Partner 1\/it Desktop Management Manager after 13-01-06 Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-0740EPSS 63% The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Co… Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2026-35471 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixe… Goshs 2.0.0+ Fix from $2,3002026-04-06 CRITICAL 9.3 CVE-2026-35408 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked… Directus 11.17.0+ Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-35393 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2… Goshs 2.0.0+ Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-35392 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is … Goshs 2.0.0+ Fix from $2,3002026-04-06 CRITICAL 9.1 CVE-2026-35459 pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vu… Pyload Ng 0.5.0b3.dev97+ Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-35197 dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbit… Dye Mitigation only Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-35184 EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the… Ecclesiacrm 8.0.0+ Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-35178 Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0… Forceworkbench 65.0.0+ Fix from $2,3002026-04-06 CRITICAL 10.0 CVE-2025-54328 An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1… Exynos 980 Firmware Mitigation only Fix from $2,3002026-04-06