Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-5035 A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Param… Accounting System Mitigation only Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-5034 A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of … Accounting System Mitigation only Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-5033 A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_cos… Accounting System Mitigation only Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-5030 A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecg… Nr1800x Firmware Mitigation only Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-5020 A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNoticeCfg of the file /cgi-bin/cste… A3600r Firmware Mitigation only Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-4851 GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine provides Remote Procedure Ca… Grid\ after 0.127 Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-5019 A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality … Simple Food Order System Mitigation only Fix from $2,3002026-03-29 CRITICAL 9.8 CVE-2026-5018 A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the … Simple Food Order System Mitigation only Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2026-5017 A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of t… Simple Food Order System Mitigation only Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2026-3256 HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::S… Http\ after 0.53 Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2025-15604 Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.06 through 6.16, the random_s… Amon2 6.17+ Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2018-25223 Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input … Crashmail Ii after 1.6 Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2018-25221 EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplyin… Easy Chat Server after 3.1 Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2018-25220 Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input stri… Bochs Mitigation only Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2017-20229 MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate… Mawk after 1.3.3-17 Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2017-20227 JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by s… Jad Java Decompiler Mitigation only Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2017-20225 TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate bo… Tiemu after 2.0.8 Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2016-20049 JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversiz… Jad Java Decompiler Mitigation only Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2025-9497 Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider … Timeprovider 4100 Firmware 2.5.0+ Fix from $2,3002026-03-28 CRITICAL 9.8 CVE-2026-33994 Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39 and prior to version 3.0.25,… Locutus 3.0.25+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33993 Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, the `unserialize()` function i… Locutus 3.0.25+ Fix from $2,3002026-03-27 CRITICAL 9.6 CVE-2026-33976 Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can … Notesnook Desktop 3.3.11 / 3.3.17+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33943 Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection … Happy Dom 20.8.8+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33937 Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-… Handlebars 4.7.9+ Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-33896 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificate… Forge after 1.3.3 Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33879 Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models… Federated Learning And Interoperability Platform 0.1.1+ Fix from $2,3002026-03-27 CRITICAL 9.3 CVE-2026-33875 Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authenticatio… Authenticator 4.16.0+ Fix from $2,3002026-03-27 CRITICAL 9.9 CVE-2026-33873 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assistant feature in Langflow exec… Langflow 1.9.0+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-34475 Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/… Varnish Enterprise 8.0.1+ Fix from $2,3002026-03-27 CRITICAL 9.6 CVE-2026-34205 Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured w… Mitigation only Fix from $2,3002026-03-27