Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-28268 Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password re… Vikunja 2.1.0+ Fix from $2,3002026-02-27 CRITICAL 9.1 CVE-2026-28231 pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer overflow in the encode path bu… Pillow Heif 1.3.0+ Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-27707 Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and prior to version 3.1.0, an au… Seerr 3.1.0+ Fix from $2,3002026-02-27 CRITICAL 9.1 CVE-2026-2880 A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-scoped middleware (for example,… Fastify\/middie 9.2.0+ Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-27755 SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability that allows attackers to forge … Sl902 Swtgw124as Firmware after 200.1.20 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-27751 SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a default credentials vulnerability that allows remote attackers to obtain adminis… Sl902 Swtgw124as Firmware after 200.1.20 Fix from $2,3002026-02-27 CRITICAL 9.1 CVE-2019-25489 Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug… Airbnb Clone Script No fix yet Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-2293 A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization optio… Nest Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-2750 Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affec… Web 24.04.24 / 24.10.20+ Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-2751 Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (S… Centreon Web 24.04.24. / 24.10.20+ Fix from $2,3002026-02-27 CRITICAL 9.3 CVE-2025-15498 Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an unauthenticated attacker to b… Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2025-11252 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. W… Windesk.fm after 27022026 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-24352 PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This… Pluxml Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2025-11251 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software Industry and Trade Inc. E-Comm… Woyio Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21660 A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD ve… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21659 Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Q… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-2251 Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal … Freeflow Core 8.1.0+ Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21658 Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls … Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21657 Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21656 Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insuffic… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-21654 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum H… Frick Controls Quantum Hd Firmware after 10.22 Fix from $2,3002026-02-27 CRITICAL 9.1 CVE-2026-1626 An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypt… Lms1000 Firmware 2.4.1+ Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2025-12981 The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation … Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-3301 A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file … N300rh Firmware Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-3289 A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the… Publiccms Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-3287 A security flaw has been discovered in youlaitech youlai-mall 2.0.0. This affects the function listPagedSpuForApp of the file mall-pms/pms-boot/src/m… Youlai Mall Mitigation only Fix from $2,3002026-02-27 CRITICAL 9.1 CVE-2026-28370 In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code executi… Vitrage 12.01 / 13.0.1+ Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-24497 Stack-based Buffer Overflow vulnerability in SimTech Systems, Inc. ThinkWise allows Remote Code Inclusion.This issue affects ThinkWise: from 7 throug… Thinkwise 23+ Fix from $2,3002026-02-27 CRITICAL 9.1 CVE-2026-22877 An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the… Xweb 300d Pro Firmware after 1.12.1 Fix from $2,3002026-02-27 CRITICAL 9.8 CVE-2026-20797 A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corrup… Xweb 300d Pro Firmware after 1.12.1 Fix from $2,3002026-02-27