Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-31883 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM and MS-ADPCM audio decoders lea… Freerdp 3.24.0+ Fix from $2,3002026-03-13 CRITICAL 9.8 CVE-2026-31806 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND mes… Freerdp 3.24.0+ Fix from $2,3002026-03-13 CRITICAL 10.0 CVE-2026-26954 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox… Sandboxjs 0.8.34+ Fix from $2,3002026-03-13 CRITICAL 9.8 CVE-2026-25823 HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have a stac… Mitigation only Fix from $2,3002026-03-13 CRITICAL 9.1 CVE-2026-25818 HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak e… Mitigation only Fix from $2,3002026-03-13 CRITICAL 9.4 CVE-2026-23941 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smugglin… Erlang\/inets 9.1.0.5 / 9.3.2.3+ Fix from $2,3002026-03-13 CRITICAL 9.9 CVE-2026-22192 Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged m… Wpdiscuz 7.6.47+ Fix from $2,3002026-03-13 CRITICAL 9.8 CVE-2026-1668 The web interface on multiple Omada switches does not adequately validate certain external inputs, which may lead to out-of-bound memory access when … Omada Sg2005p Pd Firmware 1.0.19 / 1.20.17+ Fix from $2,3002026-03-13 CRITICAL 10.0 CVE-2026-3611EPSS 6% The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With n… Iq4e Firmware 3.30+ Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-32260 Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_proces… Deno 2.7.2+ Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-32248 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauth… Parse Server 8.6.38 / 9.6.0+ Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-1525 Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-leng… Undici 6.24.0 / 7.24.0+ Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-32232 ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink A… Zeptoclaw after 0.7.5 Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-26793 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attack… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2025-70245 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-28256 A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclo… Tracer Sc\+ Firmware 6.3.2310+ Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-28255 A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive info… Tracer Sc Firmware 6.3.2310+ Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-28252 A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypa… Tracer Sc Firmware 6.3.2310+ Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-26795 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. Th… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-26792 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, targe… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-26791 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server funct… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.6 CVE-2026-28792 Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Al… Tinacms\/cli 2.1.8+ Fix from $2,3002026-03-12 CRITICAL 9.9 CVE-2026-21708 A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. Veeam Backup \& Replication 12.3.2.4465.+ Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25528 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25527 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25526 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25525 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25524 XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Xoogallery No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25523 XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Xoogallery No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25522 XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQ… Xoogallery No fix yet Fix from $2,3002026-03-12