Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-26068 emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadata (Transport, Hostname) is ac… Emp3r0r 3.21.1+ Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2026-1358 Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maximum privileges. This could al… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2026-26011 navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulnerability exists in Nav2 AMCL'… Nav2 after 1.3.11 Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2026-25996 Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String … Inspektor Gadget 0.49.1+ Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2026-24895 FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters durin… Frankenphp 1.11.2+ Fix from $2,3002026-02-12 CRITICAL 9.2 CVE-2026-24044 Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Com… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2025-70314 webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable Webfsd Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.1 CVE-2026-26219 newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or com… Newbee Mall after 1.0.0 Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2026-26218 newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable defau… Newbee Mall after 1.0.0 Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2025-70981 CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter. Cordys Crm Mitigation only Fix from $2,3002026-02-12 CRITICAL 10.0 CVE-2026-26216 Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks para… Crawl4ai 0.8.0+ Fix from $2,3002026-02-12 CRITICAL 9.0 CVE-2025-69634 Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2025-14014 Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Lt… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2025-10969 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Com… E Commerce Package after 2025-11-27 Fix from $2,3002026-02-12 CRITICAL 9.4 CVE-2025-15573 The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.sola… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2025-14892 The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the tar… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.8 CVE-2026-1729 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not p… Mitigation only Fix from $2,3002026-02-12 CRITICAL 9.3 CVE-2026-26215 manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticate… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.0 CVE-2026-20677 A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.… Ipados 14.8.4 / 18.7.5+ Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2025-67135 Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack. Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-26021 set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package … Set In 2.0.5+ Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-25994 PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH … Pjsip after 2.16 Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2020-37186 Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration ins… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2020-37184 Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attackers to execute arbitrary cod… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2020-37183 Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriti… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2020-37181 Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structured Exception Handler (SEH) th… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2020-37176 Torrent 3GP Converter 1.51 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exceptio… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2020-37172 AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password reco… Avideo Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2020-37153 ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management … Astpp Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2025-69872 DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can … Mitigation only Fix from $2,3002026-02-11