Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-67038 KEVEPSS 16% An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. … Eds5032 Firmware Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2025-67035 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due… Eds5032 Firmware Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-30741 A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt… Openclaw after 2026.2.6 Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-30903 External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an … Workplace Desktop 6.4.17 / 6.5.15+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-3944 A vulnerability was determined in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /att_add.php. Th… University Management System Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-3826 IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the se… Organization Portal System Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-2631 The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the … Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-27842 Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configura… Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-24448 Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access. Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2023-27573 netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcd… Netbox Docker 2.5.0+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-29515 MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log … Fileexplorer Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-23813 A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote a… Arubaos Cx after 10.17.0001 Fix from $2,3002026-03-11 CRITICAL 9.1 CVE-2026-31800 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.12 and 8.6.25, the _Grap… Parse Server 8.6.25 / 9.5.2+ Fix from $2,3002026-03-10 CRITICAL 10.0 CVE-2026-30966 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Serv… Parse Server 8.6.20 / 9.5.2+ Fix from $2,3002026-03-10 CRITICAL 9.1 CVE-2026-30965 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerab… Parse Server 8.6.21 / 9.5.2+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-0120 In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execu… Android Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-0116 In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code… Android Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-0114 In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execu… Android Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-0113 In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalat… Android Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-0111 In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalat… Android Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-0110 In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote escalation of privilege with … Android Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-29793 Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, Socket.IO cli… Feathers 5.0.42+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-29792 Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, an unauthentic… Feathers 5.0.42+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-28292 `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacke… Simple Git 3.32.2+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-3843 Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuratio… Buk Ts G Gas Station Automation System 2.10.2+ Fix from $2,3002026-03-10 CRITICAL 9.1 CVE-2026-30970 Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1… Coral Server 1.1.0+ Fix from $2,3002026-03-10 CRITICAL 9.1 CVE-2026-30969 Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1… Coral Server 1.1.0+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-30968 Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1… Coral Server 1.1.0+ Fix from $2,3002026-03-10 CRITICAL 9.4 CVE-2026-30960 rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical methods support and physics … Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.9 CVE-2026-30957 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allow a low-privileged authentica… Oneuptime 10.0.21+ Fix from $2,3002026-03-10