Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-29093 WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 112… Avideo 24.0+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28501 WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objec… Avideo 24.0+ Fix from $2,3002026-03-06 CRITICAL 9.1 CVE-2026-28497 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer … Tinyweb 2.03+ Fix from $2,3002026-03-06 CRITICAL 9.0 CVE-2025-59543 Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious… Chamilo Lms 1.11.34+ Fix from $2,3002026-03-06 CRITICAL 9.0 CVE-2025-59542 Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious… Chamilo Lms 1.11.34+ Fix from $2,3002026-03-06 CRITICAL 9.0 CVE-2025-55289 Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (Verison 1.11.32) allows an att… Chamilo Lms 1.11.34+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28710 Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linu… Cyber Protect 17.0.41186+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-22552 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent … Epower.ie Mitigation only Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-26125 Payment Orchestrator Service Elevation of Privilege Vulnerability Payment Orchestrator Service No fix yet Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-21536 Microsoft Devices Pricing Program Remote Code Execution Vulnerability Devices Pricing Program No fix yet Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-28479 OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox configurations, which is deprecat… Openclaw 2026.2.15+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28474 OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist valid… Openclaw 2026.2.6+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28472 OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity ch… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28470 OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbit… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 CRITICAL 9.9 CVE-2026-28466 OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke par… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-28462 OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and … Openclaw 2026.2.13+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28454 OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST r… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28453 OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files out… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 CRITICAL 9.3 CVE-2026-28451 OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that allow attackers to fetch attack… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 CRITICAL 9.4 CVE-2026-28448 OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enfor… Openclaw 2026.2.1+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28446 OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound all… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-28395 OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and ena… Openclaw 2026.2.12+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28393 OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaSc… Openclaw 2026.2.14+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28392 OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler that incorrectly authorizes any … Openclaw 2026.2.14+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28391 OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configurat… Openclaw 2026.2.2+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-21622 Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows Account Takeover. Password … Hexpm 2026-03-05+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28443 OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint has a SQL injection in the sor… Openreplay 1.20.0+ Fix from $2,3002026-03-05 CRITICAL 10.0 CVE-2026-0848 NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamic… Nltk after 3.9.2 Fix from $2,3002026-03-05 CRITICAL 9.3 CVE-2025-70948 A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an a… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.0 CVE-2025-55208 Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `Social Networks`. Through it, … Chamilo Lms 1.11.34+ Fix from $2,3002026-03-05