Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-28775 An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series Sup… Sfx2100 Firmware Mitigation only Fix from $2,3002026-03-04 CRITICAL 9.8 CVE-2026-3266 Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF t… Filr 25.1.3+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-27971EPSS 5% Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ … Qwik 1.19.1+ Fix from $2,3002026-03-03 CRITICAL 9.1 CVE-2026-26279 Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disable… Froxlor 2.3.4+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-3224 Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticate… Devolutions Server 2025.3.16.0+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-3204 Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error… Devolutions Server after 2025.3.16.0 Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-3130 Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission t… Devolutions Server 2025.3.16.0+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-2590 Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.… Remote Desktop Manager after 2025.3.30.0 Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-27012 OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authent… Openstamanager after 2.9.8 Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-24898 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token dis… Openemr 8.0.0+ Fix from $2,3002026-03-03 CRITICAL 9.9 CVE-2026-24848EPSS 6% OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() … Openemr 7.0.4+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-3485 A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument… Dir 868l Firmware Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-70240 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-70239 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-70234 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-70241 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-70237 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-70236 Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter. Dir 513 Firmware Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.1 CVE-2025-66945 A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /api/extra… Zdir after 4.6.2 Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-14923 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.2 IBM WebSphere Application Server Liberty could provide weaker than expected secu… Websphere Application Server 26.0.0.3+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2024-55026 An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary command… Easyweb Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2024-55024 An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attack… Easyweb Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2024-55020 A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to… Easyweb Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-3136 An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execut… Cloud Build 2026-1-26+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-24103 A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi. Ac15 Firmware Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-22891 A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9… Libbiosig Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-70821 renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component Renren Security after 5.5.0 Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-57622 An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_da… Mitigation only Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2025-59059 Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to… Ranger 2.8.0+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-22886 OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default adminis… Openmq Mitigation only Fix from $2,3002026-03-03