Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-67114 Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG393… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-67113 OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allo… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-67112 Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware … Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-32867 OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files vi… Ecase Ecomplaint 10.1.0.0+ Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-32865 OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'F… Ecase Ecomplaint 10.1.0.0+ Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-30402 An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function Wgcloud after 2.3.7 Fix from $2,3002026-03-19 CRITICAL 9.1 CVE-2026-2369 A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overr… Libsoup Patch available Fix from $2,3002026-03-19 CRITICAL 10.0 CVE-2026-22557EPSS 28% A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on t… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.1 CVE-2025-71257EPSS 45% BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil… Footprints after 20.24.01.001 Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2006-10003 XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the s… Xml\ 2.48+ Fix from $2,3002026-03-19 CRITICAL 9.1 CVE-2026-27067 Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-27065 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress build… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-60237 Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0. Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-60233 Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2. Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-27542 Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows P… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.0 CVE-2026-27540 Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.3 CVE-2026-27413 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL… Mitigation only Fix from $2,3002026-03-19 CRITICAL 10.0 CVE-2026-32737 Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests with… Romeo 0.2.1+ Fix from $2,3002026-03-18 CRITICAL 9.9 CVE-2026-32731 ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `… Import Export 3.5.3+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2025-15031 A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically,… Mlflow after 3.10.1 Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-31972 SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been a… Samtools 1.21.1+ Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-25873 OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute ar… Patch available Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-31967 HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the… Htslib 1.21.1 / 1.22.2+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-31966 HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one… Htslib 1.21.1 / 1.22.2+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-32633 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r… Glances 4.5.2+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-32611 Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export… Glances 4.5.2+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-30704 The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB Mitigation only Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-30703 A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi e… Mitigation only Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-30702 The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login pa… Mitigation only Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-30701 The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of S… Mitigation only Fix from $2,3002026-03-18