Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-27180 MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compromise via update URL poisoning… Majordomo Patch available Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2026-27179 MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. The commands_search.inc.php fil… Majordomo Patch available Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2026-27175EPSS 7% MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param variable from user input is … Majordomo Patch available Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2026-27174EPSS 7% MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console feature. An include order bug in… Majordomo Patch available Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2019-25365 ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to execute arbitrary code by over… Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2019-25364 MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers … Mailcarrier Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2019-25362 WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting th… Wmv To Avi Mpeg Dvd Wmv Convertor Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2019-25361 Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code.… Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2019-25360 Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code b… Aida64 Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.0 CVE-2026-0573 An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sensitive authorizatio… Enterprise Server 3.14.22 / 3.15.17+ Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2025-70152 code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.p… Scholars Tracking System Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2025-70150 CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attacker… Membership Management System Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2025-70149 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter. Membership Management System Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.1 CVE-2025-70146 Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attacke… Online Time Table Generator No fix yet Fix from $2,3002026-02-18 CRITICAL 9.4 CVE-2025-70141 SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authe… Customer Support System No fix yet Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2025-70998 UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowin… 810 Firmware Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2025-65791 ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() f… Zoneminder Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.5 CVE-2025-15579 Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerability could lead to remote cod… Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2026-2329EPSS 40% An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage … Gxp1610 Firmware 1.0.7.81+ Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2026-2654 A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExec… Smolagents after 1.24.0 Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2026-1435 Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new… Graylog Mitigation only Fix from $2,3002026-02-18 CRITICAL 9.8 CVE-2026-1670 The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password… Mitigation only Fix from $2,3002026-02-17 CRITICAL 10.0 CVE-2026-22769 KEVEPSS 13% Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as a… Recoverpoint For Virtual Machines 6.0+ Fix from $2,3002026-02-17 CRITICAL 9.8 CVE-2025-33089 IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized actions due to the use of hard … Concert 2.2.0+ Fix from $2,3002026-02-17 CRITICAL 9.1 CVE-2025-66614 Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.… Tomcat 9.0.113 / 10.1.50+ Fix from $2,3002026-02-17 CRITICAL 9.9 CVE-2025-59793 Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to uploa… Trufusion Enterprise 7.10.5.0+ Fix from $2,3002026-02-17 CRITICAL 9.8 CVE-2026-23647 Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication … Mitigation only Fix from $2,3002026-02-17 CRITICAL 9.9 CVE-2025-70830 A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execu… Mitigation only Fix from $2,3002026-02-17 CRITICAL 9.8 CVE-2026-2616 A vulnerability has been found in Beetel 777VR1 up to 01.00.09. The impacted element is an unknown function of the component Web Management Interface… 777vr1 Firmware after 01.00.09_55 Fix from $2,3002026-02-17 CRITICAL 9.6 CVE-2026-22208 OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerability via an unrestricted Lua i… Patch available Fix from $2,3002026-02-17