Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-27211 Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary host file exfiltration (cons… Cloud Hypervisor 50.1+ Fix from $2,3002026-02-21 CRITICAL 9.1 CVE-2026-27197 Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML… Sentry 26.2.0+ Fix from $2,3002026-02-21 CRITICAL 9.8 CVE-2026-27194 D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter e… D Tale after 3.19.1 Fix from $2,3002026-02-21 CRITICAL 9.8 CVE-2026-27168 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. All versions are vulnerable to… Sail after 0.9.10 Fix from $2,3002026-02-21 CRITICAL 9.8 CVE-2026-2039 GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authenticatio… Archiver Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-2038 GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication… Archiver Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2019-25441EPSS 8% thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting mal… Thesystem Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.9 CVE-2026-27112 Kargo manages and automates the promotion of software artifacts. From 1.7.0 to before v1.7.8, v1.8.11, and v1.9.3, the batch resource creation endpoi… Kargo 1.7.8 / 1.8.11+ Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-27190 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process impl… Deno 2.6.8+ Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2026-25896 fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From… Fast Xml Parser 5.3.5+ Fix from $2,3002026-02-20 CRITICAL 10.0 CVE-2021-35402 PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.1 CVE-2019-25444 Fiverr Clone Script 1.2.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting S… Fiverr Clone Script No fix yet Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-2848 A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file… Simple Responsive Tourism Website Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-2333 Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted networ… Opds Talon Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.1 CVE-2026-26747 A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php… Monica No fix yet Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-26725 An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate privileges via the AccessID p… Print Shop Pro Webdesk Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.4 CVE-2026-26722 An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of th… Global Facilities Management Software No fix yet Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-26093 Improper Neutralization of Special Elements used in a Command ('Command Injection') in Owl opds 2.2.0.4 allows Command Injection via a crafted networ… Opds Talon Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-25715 The web management interface of the device allows the administrator username and password to be set to blank values. Once applied, the device permi… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.4 CVE-2025-70833 An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administra… Smanga Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.3 CVE-2026-24956 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download Manager Addons for Elementor … Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-22384 Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay … Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-70831 A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properly saniti… Smanga Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69405 Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-store allows Object Injection.T… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69404 Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issue affects Extreme Store: from… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.9 CVE-2025-69403 Unrestricted Upload of File with Dangerous Type vulnerability in Bravis-Themes Bravis Addons bravis-addons allows Using Malicious Files.This issue af… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69382 Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object Injection.This issue affects Th… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69372 Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue affects SevenHills: from n/a… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69371 Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue affects KindlyCare: from n/a… Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2025-69370 Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects Capella: from n/a through <=… Mitigation only Fix from $2,3002026-02-20