Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-4182 A weakness has been identified in D-Link DIR-816 1.10CNB05. This impacts an unknown function of the file /goform/form2Wl5RepeaterStep2.cgi of the com… Dir 816 Firmware Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-4181 A security flaw has been discovered in D-Link DIR-816 1.10CNB05. This affects an unknown function of the file /goform/form2RepeaterStep2.cgi of the c… Dir 816 Firmware Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-4180 A vulnerability was identified in D-Link DIR-816 1.10CNB05. The impacted element is an unknown function of the file redirect.asp of the component goa… Dir 816 Firmware Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-4170 A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/manage… Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-4164 A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is the function Delete_Mac_list/SetName/GuestWifi of the file /cgi-bin/wireless.cgi of t… Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-4163 A vulnerability was detected in Wavlink WL-WN579A3 220323. This issue affects the function SetName/GuestWifi of the file /cgi-bin/wireless.cgi of the… Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.0 CVE-2026-32635 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-n… Angular Cli 19.2.0 / 21.2.4+ Fix from $2,3002026-03-16 CRITICAL 9.6 CVE-2026-32626 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, An… Anythingllm after 1.11.1 Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-32640 SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modules) can leak dangerous modul… Simpleeval 1.0.5+ Fix from $2,3002026-03-16 CRITICAL 9.9 CVE-2026-32621 Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vul… Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-20998 Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication. Smart Switch 3.7.69.15+ Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-20997 Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authenticat… Smart Switch 3.7.69.15+ Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2025-69246 Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automated logon requests without tr… Raytha 1.4.6+ Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2025-52648 HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tamp… Aion 2.1.2+ Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2025-15060 claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2017-20224 Telesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload mal… Sdt Cs3b1 Firmware Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2017-20223 Telesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass… Sdt Cs3b1 Firmware Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2016-20030 ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting pa… Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2016-20026 ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated attackers to access the manage… Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2016-20024 ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying exec… Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2015-20121 Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by … Realtyscript Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2015-20120 Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extra… Realtyscript Mitigation only Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2026-3891EPSS 25% The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation… Mitigation only Fix from $2,3002026-03-13 CRITICAL 9.8 CVE-2026-32746EPSS 24% telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does … Inetutils after 2.7 Fix from $2,3002026-03-13 CRITICAL 9.1 CVE-2026-32367 Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.Th… Mitigation only Fix from $2,3002026-03-13 CRITICAL 9.9 CVE-2026-32306 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API accepts user-controlled aggregat… Oneuptime 10.0.23+ Fix from $2,3002026-03-13 CRITICAL 9.8 CVE-2026-32304 Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) functi… Locutus 3.0.14+ Fix from $2,3002026-03-13 CRITICAL 9.3 CVE-2026-32301 Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Side Request Forgery (SSRF) when… Centrifugo 6.7.0+ Fix from $2,3002026-03-13 CRITICAL 9.1 CVE-2026-31897 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in freerdp_bitmap_decompress_planar … Freerdp 3.24.0+ Fix from $2,3002026-03-13 CRITICAL 9.4 CVE-2026-31885 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-ADPCM and IMA-ADPCM decoders d… Freerdp 3.24.0+ Fix from $2,3002026-03-13