Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-30956 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isol… Oneuptime 10.0.21+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-30930 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string co… Glances 4.5.1+ Fix from $2,3002026-03-10 CRITICAL 9.3 CVE-2026-26105 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20076+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-23240 In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered du… Linux Kernel 6.12.75 / 6.18.16+ Fix from $2,3002026-03-10 CRITICAL 9.1 CVE-2025-69615 Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. … Account Management Portal after 2025-10-24 Fix from $2,3002026-03-10 CRITICAL 9.4 CVE-2025-69614 Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. A… Account Management Portal 2025-10-27+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2025-56422 A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server. Limesurvey after 6.14.3 Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2025-41709 An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device. Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.6 CVE-2025-40943 Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering an autho… Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.9 CVE-2026-30921 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project user… Oneuptime 10.0.20+ Fix from $2,3002026-03-10 CRITICAL 9.9 CVE-2026-30887 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/Java… Oneuptime 10.0.18+ Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-30869 SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read … Siyuan 3.5.10+ Fix from $2,3002026-03-10 CRITICAL 9.0 CVE-2026-30862 Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table … Appsmith 1.96+ Fix from $2,3002026-03-10 CRITICAL 9.1 CVE-2026-27685 SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, … Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.8 CVE-2026-0953 The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon.… Mitigation only Fix from $2,3002026-03-10 CRITICAL 9.1 CVE-2025-11158 Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT … Vantara Pentaho Data Integration And Analytics 10.2.0.6+ Fix from $2,3002026-03-10 CRITICAL 9.1 CVE-2026-31816EPSS 15% Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() m… Budibase after 3.31.4 Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2026-25960 vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in… Vllm 0.17.0+ Fix from $2,3002026-03-09 CRITICAL 9.0 CVE-2026-25737 Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerabili… Budibase after 3.24.0 Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2025-70039 An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223. Twake Mitigation only Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2025-70046 An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master. Oa Font Service No fix yet Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2025-70042 An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master. Thermakube Mitigation only Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2026-3818 A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebService/GetDBData.jsp. This mani… Easy7 Cms Mitigation only Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2026-3813 A vulnerability was identified in opencc JFlow up to 5badc00db382d7cb82dad231e6a866b18e0addfe. Affected by this vulnerability is the function Calcula… Jflow Mitigation only Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2025-40639 A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases thr… Eventobot Mitigation only Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2026-24713 Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users a… Iotdb 1.3.7 / 2.0.7+ Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2026-24015 A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrad… Iotdb 1.3.7 / 2.0.7+ Fix from $2,3002026-03-09 CRITICAL 9.1 CVE-2025-41765 Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary d… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $2,3002026-03-09 CRITICAL 9.1 CVE-2025-41764 Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary u… Universal Bacnet Router Firmware 6.0.1.0+ Fix from $2,3002026-03-09 CRITICAL 9.8 CVE-2026-3823 EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to co… Atop Ehg2408 Firmware 3.36+ Fix from $2,3002026-03-09