Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-25898 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and … Imagemagick 6.9.13-40 / 7.1.2-15+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-25897 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer O… Imagemagick 6.9.13-40 / 7.1.2-15+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-3046 A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unkno… E Logbook With Health Monitoring System For Covid 19 Mitigation only Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-3042 A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of the file /admin/index.php. P… Event Management System Mitigation only Fix from $2,3002026-02-24 CRITICAL 9.1 CVE-2024-58041 Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earlier for Perl uses the rand() … Smolder after 1.51 Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-3062 Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access… Chrome 145.0.7632.116 / 145.0.7632.117+ Fix from $2,3002026-02-23 CRITICAL 9.1 CVE-2026-3061 Out of bounds read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafted … Chrome 145.0.7632.116 / 145.0.7632.117+ Fix from $2,3002026-02-23 CRITICAL 9.8 CVE-2026-3025 A flaw has been found in ShuoRen Smart Heating Integrated Management Platform 1.0.0. Affected by this vulnerability is an unknown functionality of th… Smart Heating Integrated Management Platform Mitigation only Fix from $2,3002026-02-23 CRITICAL 10.0 CVE-2026-23693 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose t… Mitigation only Fix from $2,3002026-02-23 CRITICAL 9.8 CVE-2025-70327 TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executa… X5000r Firmware Mitigation only Fix from $2,3002026-02-23 CRITICAL 9.1 CVE-2025-70043 An issue pertaining to CWE-295: Improper Certificate Validation was discovered in Ayms node-To master. The application disables TLS/SSL certificate v… No fix yet Fix from $2,3002026-02-23 CRITICAL 9.8 CVE-2026-2983 A vulnerability was determined in SourceCodester Student Result Management System 1.0. The impacted element is an unknown function of the file /admin… Student Result Management System Mitigation only Fix from $2,3002026-02-23 CRITICAL 9.3 CVE-2025-41002 SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the dat… Mitigation only Fix from $2,3002026-02-23 CRITICAL 9.1 CVE-2026-23552 Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not v… Camel 4.18.0+ Fix from $2,3002026-02-23 CRITICAL 9.8 CVE-2026-2964 A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of t… Webaudiorecorder.js Mitigation only Fix from $2,3002026-02-23 CRITICAL 9.8 CVE-2026-24494 SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attack… Mitigation only Fix from $2,3002026-02-23 CRITICAL 9.1 CVE-2026-2588 Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems. Sodium.xs casts a STRLEN (size_t) to unsigned lo… Crypt\ after 2.001 Fix from $2,3002026-02-23 CRITICAL 9.8 CVE-2026-2954 A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of t… Ujcms Mitigation only Fix from $2,3002026-02-22 CRITICAL 9.8 CVE-2019-25459 Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database querie… Emlak Mitigation only Fix from $2,3002026-02-22 CRITICAL 9.8 CVE-2019-25458 Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting … Firma Rehberi Mitigation only Fix from $2,3002026-02-22 CRITICAL 9.1 CVE-2019-25456 Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code… Emlak No fix yet Fix from $2,3002026-02-22 CRITICAL 9.1 CVE-2026-2953 A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete o… Ujcms No fix yet Fix from $2,3002026-02-22 CRITICAL 9.8 CVE-2026-2952EPSS 7% A flaw has been found in Vaelsys 4.1.0. This vulnerability affects unknown code of the file /tree/tree_server.php of the component HTTP POST Request … Vaelsys Mitigation only Fix from $2,3002026-02-22 CRITICAL 9.8 CVE-2026-2944EPSS 6% A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1.01. Affected is the function system of the file … Online Store Management System Mitigation only Fix from $2,3002026-02-22 CRITICAL 9.8 CVE-2026-2912 A vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessment… Online Reviewer System Mitigation only Fix from $2,3002026-02-22 CRITICAL 9.1 CVE-2026-2894 A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/lo… Funadmin 7.1.0+ Fix from $2,3002026-02-21 CRITICAL 9.8 CVE-2026-2867 A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing … Vehicle Management System Mitigation only Fix from $2,3002026-02-21 CRITICAL 9.9 CVE-2026-27574 OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's n… Oneuptime 10.0.5+ Fix from $2,3002026-02-21 CRITICAL 9.8 CVE-2026-2865 A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroll… Agri Trading Online Shopping System Mitigation only Fix from $2,3002026-02-21 CRITICAL 9.1 CVE-2026-27471 ERP is a free and open source Enterprise Resource Planning tool. In versions up to 15.98.0 and 16.0.0-rc.1 and through 16.6.0, certain endpoints lack… Erpnext 15.98.1 / 16.6.1+ Fix from $2,3002026-02-21