Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-30643 An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload. Dedecms after 5.7.118 Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-20160 A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands o… Smart Software Manager On Prem 9-202601+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-20093 A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker … Mitigation only Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2024-43028 A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a cra… Jeecg Boot after 3.5.3 Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2024-40489 There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary… Jeecg Boot after 3.5.3 Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-31027 TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerab… A3600r Firmware Mitigation only Fix from $2,3002026-04-01 CRITICAL 9.6 CVE-2026-34430 ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arb… Deerflow 2026-03-29+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-29014EPSS 39% MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary … Metinfo Mitigation only Fix from $2,3002026-04-01 CRITICAL 10.0 CVE-2026-4370 A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the internal Dqlite database cluster f… Juju 3.6.20 / 4.0.5+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-5257 A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of the file /delstaffinfo.php o… Simple Laundry System Mitigation only Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-5256 A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /modify.php of the component Pa… Simple Laundry System Mitigation only Fix from $2,3002026-04-01 CRITICAL 9.1 CVE-2025-15484 The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthent… Mitigation only Fix from $2,3002026-04-01 CRITICAL 9.6 CVE-2026-5290 Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentia… Chrome 146.0.7680.177+ Fix from $2,3002026-04-01 CRITICAL 9.6 CVE-2026-5289 Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potential… Chrome 146.0.7680.177+ Fix from $2,3002026-04-01 CRITICAL 9.6 CVE-2026-5288 Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to p… Chrome 146.0.7680.177+ Fix from $2,3002026-04-01 CRITICAL 9.1 CVE-2026-4374 Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing … Connext Professional 7.3.1.1 / 7.7.0+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2025-71281 XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used instead of a stricter first-wor… Xenforo 2.3.7+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2025-71279 XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the se… Xenforo 2.3.7+ Fix from $2,3002026-04-01 CRITICAL 9.6 CVE-2026-34449 SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop … Siyuan 3.6.2+ Fix from $2,3002026-03-31 CRITICAL 9.0 CVE-2026-34448 SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field … Siyuan 3.6.2+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-34400 Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, … Alerta 9.1.0+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-1579 The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any m… Autopilot No fix yet Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-4800 Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but di… Lodash 4.18.0+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30285 An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the fil… Zora Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.3 CVE-2026-3356 The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access and manipulate its management… Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30286 An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via t… Zefiro Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30283 An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal fi… Animal Sounds And Ringtones Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.0 CVE-2026-30282 An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files vi… Cast To Tv Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30278 An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files via the file… Fly Is Fun Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.3 CVE-2026-34361 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator H… Hl7 Fhir Core 6.9.4+ Fix from $2,3002026-03-31