Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-2058 A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of … Cloudclassroom Php Project Mitigation only Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2025-64111 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to… Gogs 0.13.4+ Fix from $2,3002026-02-06 CRITICAL 9.1 CVE-2019-25298 html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP p… Html5 Snmp No fix yet Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2026-2057 A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. … Medical Center Portal Management System Mitigation only Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2026-2018 A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This … School Management System Mitigation only Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2026-2017 A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurityHandler of the file /goform/w… W30ap Firmware after 1.0.0.11 Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2026-2014 A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /ramonsys/billing/ind… School Management System Mitigation only Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2026-2013 A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. S… School Management System Mitigation only Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2026-2012 A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /ramonsys/facul… School Management System Mitigation only Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2026-2011 A vulnerability was found in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /ramonsys/enrollment… School Management System Mitigation only Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2026-21643 KEVEPSS 94% An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an u… Forticlientems Mitigation only Fix from $2,3002026-02-06 CRITICAL 9.8 CVE-2026-24302 Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. Azure Arc Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-24300 Azure Front Door Elevation of Privilege Vulnerability Azure Front Door No fix yet Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-1963 A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage… Wekan 8.21+ Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-1962 A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the comp… Wekan 8.21+ Fix from $2,3002026-02-05 CRITICAL 9.3 CVE-2026-0106 In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege … Android Mitigation only Fix from $2,3002026-02-05 CRITICAL 10.0 CVE-2025-68121 During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the r… Go 1.24.13 / 1.25.7+ Fix from $2,3002026-02-05 CRITICAL 9.0 CVE-2025-68723 Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exis… Axigen Mail Server 10.5.57 / 10.6.26+ Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2020-37138 10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to e… Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2020-37137 PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code … Phpfusion Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2020-37129 Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Atta… Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2020-37126 Free Desktop Clock 3.0 contains a stack overflow vulnerability in the Time Zones display name input that allows attackers to overwrite Structured Exc… Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2020-37125EPSS 6% Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands thr… Ew 7438rpn Mini Firmware Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2020-37124 B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SE… Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2020-37123 Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Atta… Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2020-37120 Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attackers to overwrite Structured Exc… Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2020-37119 Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overw… Nsauditor Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2026-23796 Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This… Quick.cart Mitigation only Fix from $2,3002026-02-05 CRITICAL 9.8 CVE-2025-62616 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio… Autogpt Platform 0.6.34+ Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2025-62615 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio… Autogpt Platform 0.6.34+ Fix from $2,3002026-02-04