Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-67304 In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL database user. In the default… Ruckus Network Director 4.5.0.56+ Fix from $2,3002026-02-19 CRITICAL 9.1 CVE-2026-26057 Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. A vulnerabilit… Skill Scanner 1.0.2+ Fix from $2,3002026-02-19 CRITICAL 9.3 CVE-2026-2409 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Delinea Cloud Suite allows Argument Injection.T… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-26339 Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the argument injection vulnerability… Alfresco Transform Service 4.2.3 / 5.2.4+ Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-26338 Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) through the document processing… Alfresco Transform Service 4.3 / 5.3.0+ Fix from $2,3002026-02-19 CRITICAL 9.9 CVE-2026-26030 Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t… Semantic Kernel 1.39.4+ Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-71243EPSS 5% The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Execution (RCE) vulnerability. … Saisies 5.11.1+ Fix from $2,3002026-02-19 CRITICAL 9.1 CVE-2025-55853 SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or externa… Webpdf 10.0.2+ Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-9953 Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Softw… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-8350 Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS al… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-15559 An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and dow… Worktime after 11.8.8 Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-23549 Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: fro… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-23542 Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Resta… Mitigation only Fix from $2,3002026-02-19 CRITICAL 10.0 CVE-2026-2731 Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers t… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-2691 A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/m… Event Management System Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-2690 A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax… Event Management System Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-2689 A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /admin/manage_booking.php. The … Event Management System Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-25242 Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global Re… Gogs 0.14.1+ Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-1994 The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is du… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-1405 The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-0926EPSS 9% The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'parameters[templ… Mitigation only Fix from $2,3002026-02-19 CRITICAL 10.0 CVE-2025-15586 OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in … Patch available Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-13851 The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-13563 The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_l… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-12882 The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin all… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-2686 A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file /cgi-bin/session_login.cgi. … Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-2684 A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function o… Electronic Archives System after 3.2.210802 Fix from $2,3002026-02-19 CRITICAL 9.1 CVE-2026-24126 Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key… Weblate 5.16+ Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2026-2682 A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /… Electronic Archives System after 3.2.210802 Fix from $2,3002026-02-18 CRITICAL 9.1 CVE-2026-25548 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerabil… Invoiceplane 1.7.1+ Fix from $2,3002026-02-18