Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-25881 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototype… Sandboxjs 0.8.31+ Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-25875 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorization middleware trusts client-co… Placipy Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-25814 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query parameters are passed directl… Placipy Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.1 CVE-2026-25811 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application derives the tenant identifier direc… Placipy Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.1 CVE-2026-25876 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/results.routes.ts verify aut… Placipy Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.1 CVE-2026-25810 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the backend/src/routes/student.submission.routes.ts… Placipy Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-25809 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation endpoint does not validate the … Placipy Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.1 CVE-2026-25057 MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able to upload a zip file to creat… Markus 2.9.1+ Fix from $2,3002026-02-09 CRITICAL 9.1 CVE-2026-24679 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array i… Freerdp 3.22.0+ Fix from $2,3002026-02-09 CRITICAL 9.1 CVE-2026-24677 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts server-controlled dimensions and … Freerdp 3.22.0+ Fix from $2,3002026-02-09 CRITICAL 9.4 CVE-2025-66630 Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying crypto/rand implementation can… Fiber 2.52.11+ Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2025-6830 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Passw… Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-25848 In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible Hub 2025.3.119807+ Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2225 A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component … News Portal Project Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.1 CVE-2026-2234 C&Cm@il developed by HGiga has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read and modify any user's mail … Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2223 A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the f… Online Reviewer System Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-22906 User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining the configuration file can de… Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-22904 Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie v… Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-22903 An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overfl… Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2221 A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the … Online Reviewer System Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2220 A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assess… Online Reviewer System Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.9 CVE-2026-1868 GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6… Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2217 A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php… Event Management System Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-1615 Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions… Patch available Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2212 A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Admini… Online Music Site Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2211 A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCate… Online Music Site Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.6 CVE-2025-66606 A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly encode URLs. An attacker co… Fast\/tools Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2025-66603 A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OPTIONS method. An attacker cou… Fast\/tools Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2025-66602 A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access by IP address. When a worm t… Fast\/tools Mitigation only Fix from $2,3002026-02-09 CRITICAL 9.8 CVE-2026-2199 A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/sy… Online Reviewer System Mitigation only Fix from $2,3002026-02-09