Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-28255 A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive info… Tracer Sc Firmware 6.3.2310+ Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-28252 A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypa… Tracer Sc Firmware 6.3.2310+ Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-26795 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. Th… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-26792 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, targe… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-26791 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server funct… Ar300m16 Firmware Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.6 CVE-2026-28792 Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Al… Tinacms\/cli 2.1.8+ Fix from $2,3002026-03-12 CRITICAL 9.9 CVE-2026-21708 A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user. Veeam Backup \& Replication 12.3.2.4465.+ Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25528 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25527 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25526 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25525 Inout EasyRooms Ultimate Edition v1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by… Inout Homestay No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25524 XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Xoogallery No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25523 XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Xoogallery No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25522 XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQ… Xoogallery No fix yet Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2019-25521 XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Xoogallery No fix yet Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2019-25520 Jettweb PHP Hazir Haber Sitesi Scripti V1 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated att… Php Stock News Site Script Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2019-25515 Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an authentication bypass vulnerability in the login.php administration panel that allows unauthent… Php Stock News Site Script Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2019-25514 Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows attackers to inject malicious SQL commands through the … Php Stock News Site Script Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2019-25513 Jettweb PHP Hazir Haber Sitesi Scripti V3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie… Php Stock News Site Script Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2019-25510 Jettweb PHP Hazir Haber Sitesi Scripti V2 contains an authentication bypass vulnerability in the administration panel that allows unauthenticated att… Php Stock News Site Script Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2019-25488 Jettweb Hazir Rent A Car Scripti V4 contains multiple SQL injection vulnerabilities in the admin panel that allow unauthenticated attackers to manipu… Php Ready Rent A Car Site Script Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.4 CVE-2026-28384 An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as th… Patch available Fix from $2,3002026-03-12 CRITICAL 9.1 CVE-2026-21671 A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) de… Veeam Backup \& Replication after 13.0.1.1071 Fix from $2,3002026-03-12 CRITICAL 9.9 CVE-2026-21669 A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server. Veeam Backup \& Replication 13.0.1.2067+ Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-3060 SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disaggregation module, which deseri… Sglang after 0.5.9 Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-3059 SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, which deserializes untrusted dat… Sglang after 0.5.9 Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-4014 A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. This impacts an unknown function of the file /curvus2/signup.php of … Cafe Reservation System Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-3981 A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctor_action.php.… Online Doctor Appointment System Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2026-3980 A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of the file /admin/patient_acti… Online Doctor Appointment System Mitigation only Fix from $2,3002026-03-12 CRITICAL 9.8 CVE-2025-59388 A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit the vulnerability … Hyper Data Protector 2.3.1.455+ Fix from $2,3002026-03-12