Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-70085 An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Sou… Opensatkit Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2025-69874 nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outsi… Nanotar after 0.2.0 Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-25084 Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs. Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-24789 An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication. Mitigation only Fix from $2,3002026-02-11 CRITICAL 10.0 CVE-2025-64075 A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass au… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-2249 METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing … Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-2248 METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing … Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2025-12059 Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platfor… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.4 CVE-2025-8668 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering D… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2025-8025 Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Func… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2025-66277 A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerab… Qts Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.1 CVE-2025-7659 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could … GitLab 18.6.6 / 18.7.4+ Fix from $2,3002026-02-11 CRITICAL 9.8 CVE-2026-1357EPSS 33% The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions u… Mitigation only Fix from $2,3002026-02-11 CRITICAL 9.9 CVE-2026-26009 Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server te… Patch available Fix from $2,3002026-02-10 CRITICAL 9.8 CVE-2026-25993 EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds path / request_path val… Evershop after 2.1.0 Fix from $2,3002026-02-10 CRITICAL 9.8 CVE-2026-21531 Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. Azure Conversation Authoring Client Library Mitigation only Fix from $2,3002026-02-10 CRITICAL 9.8 CVE-2026-1774 CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability. Mitigation only Fix from $2,3002026-02-10 CRITICAL 9.6 CVE-2025-52436EPSS 6% An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox… Fortisandbox 4.4.8 / 5.0.2+ Fix from $2,3002026-02-10 CRITICAL 9.8 CVE-2026-23906 Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * d… Druid 36.0.0+ Fix from $2,3002026-02-10 CRITICAL 9.8 CVE-2025-11242 Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Si… No fix yet Fix from $2,3002026-02-10 CRITICAL 9.8 CVE-2026-2096 Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete dat… Agentflow Mitigation only Fix from $2,3002026-02-10 CRITICAL 9.8 CVE-2026-2095 Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functiona… Agentflow Mitigation only Fix from $2,3002026-02-10 CRITICAL 9.6 CVE-2026-0509 SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls with… Netweaver As Abap Kernel Mitigation only Fix from $2,3002026-02-10 CRITICAL 9.9 CVE-2026-0488 An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthoriz… Netweaver Application Server Abap Mitigation only Fix from $2,3002026-02-10 CRITICAL 9.1 CVE-2026-25939EPSS 11% FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability i… Fuxa 1.2.11+ Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-25938 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA a… Fuxa 1.2.11+ Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-25895EPSS 11% FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows an unauthenticated, remote at… Fuxa 1.2.10+ Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-25894 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allows an unauthenticated, remote… Fuxa 1.2.10+ Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-25893 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an u… Fuxa 1.2.10+ Fix from $2,3002026-02-09 CRITICAL 9.1 CVE-2026-25923 my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application f… My Little Forum 20260208.1+ Fix from $2,3002026-02-09