Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-26002 Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible… Open Ondemand 3.1.16 / 4.0.9+ Fix from $2,3002026-03-04 CRITICAL 9.1 CVE-2026-29000EPSS 6% pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs… Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-70222 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuthCode. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.0 CVE-2025-66024 The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vu… Blog Application 9.15.7+ Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-70225 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curtime parameter to the goform/formEasySetupWWConfig component Dir 513 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-70221 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-46108 D-link Dir-513 A1FW110 is vulnerable to Buffer Overflow in the function formTcpipSetup. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.6 CVE-2026-3545 Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape… Chrome 145.0.7632.159 / 145.0.7632.160+ Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-70219 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the goform/formDeviceReboot. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-70226 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formEasySetupWizard. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-70223 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAdvNetwork. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 10.0 CVE-2026-20131 KEVEPSS 31% A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot… Secure Firewall Management Center Mitigation only Fix from $2,3002026-03-04 CRITICAL 10.0 CVE-2026-20079EPSS 36% A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to byp… Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-70220 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formAutoDetecWAN_wizard4. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-70218 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via POST to the goform/formAdvFirewall component. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2019-25506 FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthenticated attackers to bypass au… Freesms after 2.1.2 Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2019-25499 Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code … Simplejobscript after 1.66 Fix from $2,3002026-03-04 CRITICAL 9.1 CVE-2026-28783 Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerou… Craft Cms 4.17.0 / 5.9.0+ Fix from $2,3002026-03-04 CRITICAL 9.1 CVE-2026-28697 Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution… Craft Cms 4.17.0 / 5.9.0+ Fix from $2,3002026-03-04 CRITICAL 9.6 CVE-2025-69969 A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism … Pebble Prism Ultra Firmware 2.5.8+ Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-66944 SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in t… Databasir after 1.0.7 Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-66678 An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitr… Hardware Read \& Write Utility after 1.25.11.26 Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-26478 A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially craf… Tichome Mini Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2025-59786 2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in… Access Commander 3.5+ Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-27446EPSS 10% Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker c… Artemis after 2.44.0 Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-27441 SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution. Seppmail 15.0.1+ Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-29119 International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admi… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-28778 International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-28777 International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated att… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-28776 International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-04