Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-25676 Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code… Ask Expert Script Mitigation only Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2019-25674 CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug… Cmssite Mitigation only Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2026-5584 A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py… Agenticseek Mitigation only Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2026-5574 A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBr… Hi Led Wr120 G2 Firmware No fix yet Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2026-5573 A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the file /fs. Executing a manipul… Hi Led Wr120 G2 Firmware Mitigation only Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2026-5570 A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function index_config of the file /LoginC… Hi Led Wr120 G2 Firmware Mitigation only Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2026-5569 A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /Technostrobe/ of the componen… Hi Led Wr120 G2 Firmware Mitigation only Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2026-5562 A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutio… Ui after 0.7.2 Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2026-5526 A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionali… 4g03 Pro Firmware Mitigation only Fix from $2,3002026-04-04 CRITICAL 9.8 CVE-2018-25254 NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sen… Nico Ftp after 3.0.1.19 Fix from $2,3002026-04-04 CRITICAL 9.8 CVE-2016-20052 Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP execut… Snews after 1.7 Fix from $2,3002026-04-04 CRITICAL 9.8 CVE-2026-35616 KEVEPSS 91% A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized … Forticlientems Patch available Fix from $2,3002026-04-04 CRITICAL 10.0 CVE-2026-34955 PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK_ISOLATED) calls subprocess.r… Praisonai 4.5.97+ Fix from $2,3002026-04-04 CRITICAL 9.8 CVE-2026-34775 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and… Electron 38.8.6 / 39.8.4+ Fix from $2,3002026-04-04 CRITICAL 9.1 CVE-2026-34953 PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any token not found in its internal … Praisonai 4.5.97+ Fix from $2,3002026-04-03 CRITICAL 9.1 CVE-2026-34952 PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent … Praisonai 4.5.97+ Fix from $2,3002026-04-03 CRITICAL 10.0 CVE-2026-34938EPSS 14% PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-l… Praisonaiagents 1.5.90+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-34937 PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-c… Praisonaiagents 1.5.90+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-34935 PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and… Praisonai 4.5.69+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-34934 PraisonAI is a multi-agent teams system. Prior to version 4.5.90, the get_all_user_threads function constructs raw SQL queries using f-strings with u… Praisonai 4.5.90+ Fix from $2,3002026-04-03 CRITICAL 9.0 CVE-2026-34612 Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Inje… Kestra 1.3.7+ Fix from $2,3002026-04-03 CRITICAL 9.1 CVE-2021-4477 Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that allows traffic from VPN connecti… Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2018-25236 Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the… Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2017-20236 ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the web user interface that allows… Icx35 Hwc Firmware 1.3+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2017-20235 ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that al… Icx35 Hwc Firmware 1.3+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2017-20234 GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthoriz… Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-27634 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max… Piwigo 16.3.0+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2018-25237 Hirschmann HiSecOS devices versions prior to 05.3.03 contain a buffer overflow vulnerability in the HTTPS login interface when RADIUS authentication … Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-35561 Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow … Athena Odbc 2.1.0.0+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2017-20237 Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allow… Mitigation only Fix from $2,3002026-04-03