Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-32191 Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t… Bing Images Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-32169 Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. Azure Cloud Shell Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.6 CVE-2026-30924 qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins whi… Qui 1.15.0+ Fix from $2,3002026-03-19 CRITICAL 10.0 CVE-2026-30836 Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard ag… Step Ca 0.30.0+ Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-27953 ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing … Ormar 0.23.1+ Fix from $2,3002026-03-19 CRITICAL 10.0 CVE-2026-26138 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. Purview Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.9 CVE-2026-26137 Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. 365 Copilot Chat No fix yet Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-23658 Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. Azure Devops No fix yet Fix from $2,3002026-03-19 CRITICAL 9.1 CVE-2026-32238 OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command … Openemr 8.0.0.2+ Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-3548 Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer overflow could occur when imprope… Wolfssl 5.9.0+ Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-30694 An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component Dedecms after 5.7.118 Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-67114 Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG393… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-67113 OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allo… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-67112 Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware … Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-32867 OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files vi… Ecase Ecomplaint 10.1.0.0+ Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-32865 OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when requesting a password reset via 'F… Ecase Ecomplaint 10.1.0.0+ Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-30402 An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function Wgcloud after 2.3.7 Fix from $2,3002026-03-19 CRITICAL 9.1 CVE-2026-2369 A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resource, leading to a buffer overr… Libsoup Patch available Fix from $2,3002026-03-19 CRITICAL 10.0 CVE-2026-22557EPSS 28% A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on t… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.1 CVE-2025-71257EPSS 45% BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil… Footprints after 20.24.01.001 Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2006-10003 XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the s… Xml\ 2.48+ Fix from $2,3002026-03-19 CRITICAL 9.1 CVE-2026-27067 Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Upload a Web Shell to a Web Server… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-27065 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress build… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-60237 Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0. Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2025-60233 Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n/a through 1.4.2. Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-27542 Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows P… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.0 CVE-2026-27540 Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead… Mitigation only Fix from $2,3002026-03-19 CRITICAL 9.3 CVE-2026-27413 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL… Mitigation only Fix from $2,3002026-03-19 CRITICAL 10.0 CVE-2026-32737 Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests with… Romeo 0.2.1+ Fix from $2,3002026-03-18 CRITICAL 9.9 CVE-2026-32731 ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, The `extract()` function in `… Import Export 3.5.3+ Fix from $2,3002026-03-18