Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2026-26220 LightLLM version 1.1.0 and prior contain an unauthenticated remote code execution vulnerability in PD (prefill-decode) disaggregation mode. The PD ma… Mitigation only Fix from $2,3002026-02-17 CRITICAL 9.8 CVE-2026-2439 Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions:… Concierge\ 0.8.5+ Fix from $2,3002026-02-16 CRITICAL 9.8 CVE-2025-15578 Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available … Maypole after 2.13 Fix from $2,3002026-02-16 CRITICAL 10.0 CVE-2026-2577 The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require … Mitigation only Fix from $2,3002026-02-16 CRITICAL 9.8 CVE-2026-2550 A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipul… Mitigation only Fix from $2,3002026-02-16 CRITICAL 9.8 CVE-2026-2532 A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the file backend/app/api/v1/endpoint… Deepaudit after 3.0.3 Fix from $2,3002026-02-16 CRITICAL 9.8 CVE-2026-2529EPSS 8% A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wirel… Wl Wn579a3 Firmware after 2021-02-19 Fix from $2,3002026-02-16 CRITICAL 9.8 CVE-2026-2528EPSS 8% A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Delete_Mac_list of the file /cgi-… Wl Wn579a3 Firmware after 2021-02-19 Fix from $2,3002026-02-16 CRITICAL 9.8 CVE-2026-2527EPSS 8% A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bin/login.cgi. Executing a mani… Wl Wn579a3 Firmware after 2021-02-19 Fix from $2,3002026-02-16 CRITICAL 9.8 CVE-2026-2522 A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is an unknown function of the file /src/mme/esm-build.c of the component … Open5gs after 2.7.6 Fix from $2,3002026-02-16 CRITICAL 9.8 CVE-2026-2521 A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_response of the component SGW-C… Open5gs after 2.7.6 Fix from $2,3002026-02-15 CRITICAL 9.8 CVE-2026-26366 eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissionin… Enet Smart Home Mitigation only Fix from $2,3002026-02-15 CRITICAL 9.3 CVE-2025-32058 The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface throu… Mitigation only Fix from $2,3002026-02-15 CRITICAL 9.8 CVE-2026-1490 The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an auth… Mitigation only Fix from $2,3002026-02-15 CRITICAL 9.8 CVE-2025-8572 The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient… Mitigation only Fix from $2,3002026-02-14 CRITICAL 9.8 CVE-2026-1306 The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJ… Mitigation only Fix from $2,3002026-02-14 CRITICAL 9.8 CVE-2026-24853 Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the 8080 port, and shows Host/IP… Caido 0.55.0+ Fix from $2,3002026-02-13 CRITICAL 9.8 CVE-2026-26273 Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.6.2 and earlier. The applicat… Known 1.6.3+ Fix from $2,3002026-02-13 CRITICAL 9.8 CVE-2025-69633 A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through 1.2.6 (Fixed in version 1.2.7… Mitigation only Fix from $2,3002026-02-13 CRITICAL 9.8 CVE-2026-26335 Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web application and stored in C:\\Pr… Verasmart 2022.0+ Fix from $2,3002026-02-13 CRITICAL 9.8 CVE-2026-26333 Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The service publishes default Objec… Verasmart 2022.0+ Fix from $2,3002026-02-13 CRITICAL 9.8 CVE-2026-26190EPSS 37% Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, w… Milvus 2.5.27 / 2.6.10+ Fix from $2,3002026-02-13 CRITICAL 10.0 CVE-2025-69770 A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via upl… Mitigation only Fix from $2,3002026-02-13 CRITICAL 9.9 CVE-2026-26268 Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicio… Cursor 2.5+ Fix from $2,3002026-02-13 CRITICAL 9.8 CVE-2026-26221 Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTService.exe). An attack… Mitigation only Fix from $2,3002026-02-13 CRITICAL 9.8 CVE-2026-23112 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_i… Linux Kernel 5.10.250 / 5.15.200+ Fix from $2,3002026-02-13 CRITICAL 9.8 CVE-2019-25337 OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php end… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2019-25327 Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary co… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2019-25321 FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handle… Ftp Navigator after 8.03 Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2019-25319 Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exce… Mitigation only Fix from $2,3002026-02-12