Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-4499 A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Executing a manipulation can le… Dir 820lw Firmware Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4497 A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/c… Wa300 Firmware Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.9 CVE-2026-32710 MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 before 11.4.10 and 11.8 before 11… MariaDB 11.4.10 / 11.8.6+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-22901 A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulne… Qunetswitch after 2.0.5.0906 Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-22900 A use of hard-coded credentials vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to gai… Qunetswitch 2.0.5.0906+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-22898 A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerabi… Qvr Pro 2.7.4.1485+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-22897 A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitra… Qunetswitch 2.0.4.0415+ Fix from $2,3002026-03-20 CRITICAL 9.1 CVE-2025-59383 A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploit the vulnerability to modify… Media Streaming Add On 500.1.1.0+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2025-15608 This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalid… Archer Ax53 Firmware Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2025-15607 A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbit… Archer Ax53 Firmware Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.9 CVE-2026-22172 OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password… Openclaw 2026.3.12+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2024-44722 SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd. Sysak after 2.0 Fix from $2,3002026-03-20 CRITICAL 9.1 CVE-2026-33131 H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in the NodeRequestUrl (which exte… H3 No fix yet Fix from $2,3002026-03-20 CRITICAL 10.0 CVE-2026-33128 H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream is vulnerable to Server-Sent E… H3 1.15.6+ Fix from $2,3002026-03-20 CRITICAL 9.0 CVE-2026-33067 SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, description) using template l… Siyuan 3.6.1+ Fix from $2,3002026-03-20 CRITICAL 9.0 CVE-2026-33066 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lute.New() without calling SetS… Siyuan 3.6.1+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-33057EPSS 5% Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai… Mesop 1.2.3+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-33054 Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability tha… Mesop 1.2.3+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4473 A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appo… Online Doctor Appointment System Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.9 CVE-2026-32768 Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, due to a miswritten NetworkPo… Chall Manager 0.6.5+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4472 A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the fi… Online Frozen Foods Ordering System Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4471 A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_em… Online Frozen Foods Ordering System Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4470 A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of … Online Frozen Foods Ordering System Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4469 A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of… Online Frozen Foods Ordering System Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.1 CVE-2026-33024 AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpo… Avideo Encoder 8.0+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-33017 KEVEPSS 96% Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id… Langflow 1.8.2+ Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-4038 The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check… Mitigation only Fix from $2,3002026-03-20 CRITICAL 9.8 CVE-2026-32945 PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability… Pjsip 2.17+ Fix from $2,3002026-03-20 CRITICAL 9.0 CVE-2026-32891 Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and be… Anchorr after 1.4.1 Fix from $2,3002026-03-20 CRITICAL 9.6 CVE-2026-32890 Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and… Anchorr after 1.4.1 Fix from $2,3002026-03-20