Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-24114 An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate `pPortMapIndex` may lead to buffer overflows when using `strcpy`. W20e Firmware Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-24113 An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value … W20e Firmware Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-24111 An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInf… W20e Firmware Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-24109 An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `picName`. When this val… W20e Firmware Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-24108 An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by controlling the value of `nptr`. When this value … W20e Firmware Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-24107 An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSystemCmd`… W20e Firmware Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-23600 A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS). Autopass License Server 9.19+ Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2025-50192 Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soa… Chamilo Lms 1.11.30+ Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2025-50190 Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter wi… Chamilo Lms 1.11.30+ Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2025-50187 Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote C… Chamilo Lms 1.11.28+ Fix from $2,3002026-03-02 CRITICAL 9.1 CVE-2026-3432 On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided … Sim 0.5.74+ Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3431 On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or hos… Sim 0.5.74+ Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2025-14532 DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which c… Dorbycms after 5.0 Fix from $2,3002026-03-02 CRITICAL 9.3 CVE-2025-12462 A Blind SQL injection vulnerability has been identified in DobryCMS.  A remote unauthenticated attacker is able to inject SQL syntax into URL path in… Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.4 CVE-2025-30044 In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlo… Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.0 CVE-2025-30035 The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the… Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.3 CVE-2026-2584 A critical SQL Injection (SQLi) vulnerability has been identified in the authentication module of the system. An unauthenticated, remote attacker (AV… Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3422 U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary… U Office Force 29.50+ Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3413 A flaw has been found in itsourcecode University Management System 1.0. This vulnerability affects unknown code of the file /admin_single_student.php… University Management System Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3000 IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the … Idexpert after 2.8.4.250925 Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-2999 IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the … Idexpert after 2.8.4.250925 Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3411 A security vulnerability has been detected in itsourcecode University Management System 1.0. Affected by this issue is some unknown functionality of … University Management System Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3410 A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file … Society Management System Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3406 A vulnerability was found in projectworlds Online Art Gallery Shop 1.0. The impacted element is an unknown function of the file /admin/registration.p… Online Art Gallery Shop Mitigation only Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3400 A security flaw has been discovered in Tenda AC15 up to 15.13.07.13. Affected by this issue is some unknown functionality of the file /goform/TextEdi… Ac15 Firmware after 15.13.07.13 Fix from $2,3002026-03-02 CRITICAL 9.8 CVE-2026-3395 A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/previe… Maxsite Cms 109.2+ Fix from $2,3002026-03-01 CRITICAL 9.8 CVE-2026-28562 wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause relies on ineffective esc_sql… Wpforo Forum 2.4.15+ Fix from $2,3002026-02-28 CRITICAL 9.8 CVE-2026-28517EPSS 6% openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves … Opendcim Patch available Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-28411 WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal … Wegia 3.6.5+ Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-28408 WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the pr… Wegia 3.6.5+ Fix from $2,3002026-02-27