Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2025-41008 SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'client'… Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-31851 Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication int… Nebula300plus Firmware after 12.01.01.37 Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-31848 Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which contains Base64-encoded credential… Nebula300plus Firmware after 12.01.01.37 Fix from $2,3002026-03-23 CRITICAL 9.3 CVE-2025-41007 SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'search' parameter in th… Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-4585 A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects unknown code of the file /Easy… Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-32968 Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in … Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-4581 A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the compone… Simple Laundry System Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-4580 A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php o… Simple Laundry System Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-4579 A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the compon… Simple Laundry System Mitigation only Fix from $2,3002026-03-23 CRITICAL 10.0 CVE-2026-3587 An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of … Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.1 CVE-2026-4601 Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in t… Jsrsasign 11.1.1+ Fix from $2,3002026-03-23 CRITICAL 9.1 CVE-2026-4600 Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter valid… Jsrsasign 11.1.1+ Fix from $2,3002026-03-23 CRITICAL 9.1 CVE-2026-4599 Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigInteg… Jsrsasign 11.1.1+ Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-4567 A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi-bin/UploadCfg. The manipulat… A15 Firmware Mitigation only Fix from $2,3002026-03-23 CRITICAL 10.0 CVE-2026-4606 GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any local user to gain full cont… Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2019-25614 Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sen… Freefloat Ftp Server Mitigation only Fix from $2,3002026-03-22 CRITICAL 9.1 CVE-2026-32064 OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthen… Openclaw 2026.2.21+ Fix from $2,3002026-03-21 CRITICAL 9.8 CVE-2026-32056 OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attac… Openclaw 2026.2.22+ Fix from $2,3002026-03-21 CRITICAL 9.8 CVE-2026-32052 OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidde… Openclaw 2026.2.24+ Fix from $2,3002026-03-21 CRITICAL 9.9 CVE-2026-32048 OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to … Openclaw 2026.3.1+ Fix from $2,3002026-03-21 CRITICAL 9.8 CVE-2026-32046 OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by explo… Openclaw 2026.2.21+ Fix from $2,3002026-03-21 CRITICAL 9.1 CVE-2026-32045 OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and… Openclaw 2026.2.21+ Fix from $2,3002026-03-21 CRITICAL 9.1 CVE-2026-24060 Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker… Mitigation only Fix from $2,3002026-03-21 CRITICAL 9.8 CVE-2026-33228 flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed … Flatted 3.4.2+ Fix from $2,3002026-03-20 CRITICAL 9.1 CVE-2026-33210 Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnera… Json 2.15.2.1 / 2.17.1.2+ Fix from $2,3002026-03-20 CRITICAL 9.1 CVE-2026-33186 gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of … Grpc 1.79.3+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-29796 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent … Eparking.fi Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-25192 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent … Charge Portal Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.6 CVE-2026-21732 A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU… Ddk after 25.1 Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-3584EPSS 7% The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' functio… Mitigation only Fix from $2,3002026-03-20