Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-2624 Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows… Antikor Next Generation Firewall 2.0.1301+ Fix from $2,3002026-02-25 CRITICAL 9.1 CVE-2026-0704 In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked va… Octopus Server 2025.3.14715+ Fix from $2,3002026-02-25 CRITICAL 9.9 CVE-2025-62878 A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriti… Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3164 A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The m… News Portal Project Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3153 A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the file /register.php. Such manipu… Document Management System Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3152 A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/teacher-salary.php… College Management System Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3151 A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of the file /login/login.php. The… College Management System Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-25785 Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacke… Lanscope Endpoint Manager 9.4.8.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3148 A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. … Simple And Nice Shopping Cart Script Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27744 The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for publ… Tickets 4.3.3+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27743 The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_s… Referer Spam 1.3.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27641 Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remo… Flask Reuploaded 1.5.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27637 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses … Freescout 1.8.206+ Fix from $2,3002026-02-25 CRITICAL 10.0 CVE-2026-27597 Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boun… Enclave 2.11.1+ Fix from $2,3002026-02-25 CRITICAL 9.9 CVE-2026-27626 OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety chec… Olivetin after 3000.10.0 Fix from $2,3002026-02-25 CRITICAL 9.1 CVE-2026-27607 RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy condi… Rustfs Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27606 Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present i… Rollup 2.80.0 / 3.30.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3135 A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.p… News Portal Project Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3134 A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admi… News Portal Project Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3133 A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processing of the file /loging.php of … Document Management System Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-22553 All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that… Masterscada Mitigation only Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-21410 InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potenti… Masterscada Mitigation only Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-26342 Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficien… Smart\+ Firmware after 1.181.5 Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-26341 Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed d… Smart\+ Firmware after 1.181.5 Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-26222 Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCH… Altec Doclink Mitigation only Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-27590 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split ind… Caddy 2.11.1+ Fix from $2,3002026-02-24 CRITICAL 9.1 CVE-2026-27588 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-i… Caddy 2.11.1+ Fix from $2,3002026-02-24 CRITICAL 9.1 CVE-2026-27587 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-… Caddy 2.11.1+ Fix from $2,3002026-02-24 CRITICAL 9.1 CVE-2026-27586 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` … Caddy 2.11.1+ Fix from $2,3002026-02-24 CRITICAL 9.1 CVE-2026-27515 Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web managemen… 10g08 0800gsm Firmware Mitigation only Fix from $2,3002026-02-24