Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-28353 Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed v… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2025-29165 An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component Dir 1253 Firmware Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-27944EPSS 22% Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and … Nginx Ui 2.3.3+ Fix from $2,3002026-03-05 CRITICAL 9.3 CVE-2026-25921 Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack,… Gogs 0.14.2+ Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-24457 An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's… Openmq after 6.5.1 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2025-70233 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2025-70232 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2025-70231 D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verification codes in /goform/formLogin… Dir 513 Firmware Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2025-70230 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2025-70229 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSchedule. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2025-13476 Rakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking exte… Viber after 25.8.1.0 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-30793 Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter UR… Rustdesk after 1.4.5 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-30789 Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-clie… Rustdesk after 1.4.5 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-30783 A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop… Rustdesk after 1.4.5 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-2599 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-21628 A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution. Astroid Framework after 3.3.10 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-2743 Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transf… Seppmail after 15.0.2.1 Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-25702 A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via… Linux Enterprise Server Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-1678 dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, a… Zephyr after 4.3.0 Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-2418 The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticat… Mitigation only Fix from $2,3002026-03-05 CRITICAL 10.0 CVE-2026-29128 IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-29053 Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the s… Ghost 6.19.1+ Fix from $2,3002026-03-05 CRITICAL 9.3 CVE-2026-28115 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attractive Donations System - Easy St… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.1 CVE-2026-28114 Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell … Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28105 Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue affects Good Energy: from n/a t… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28074 Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue affects Pizza House: from n/a t… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-28043 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Healer - Doctor, Cl… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.0 CVE-2026-27984 Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options allows Code Injection.This is… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-27983 Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escalation.This issue affects LMS E… Mitigation only Fix from $2,3002026-03-05 CRITICAL 9.8 CVE-2026-27439 Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through <… Mitigation only Fix from $2,3002026-03-05