Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.2 CVE-2026-25547 @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a de… Mitigation only Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2026-25526 JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJav… Jinjava 2.7.6 / 2.8.3+ Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2026-25519 OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and elections of an assembly. Prior to v… Openslides 4.2.29+ Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2025-13375 IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privile… Mitigation only Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2026-25505 Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for sign… Bambuddy 0.1.7+ Fix from $2,3002026-02-04 CRITICAL 9.6 CVE-2026-25481 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-4… Langroid 0.59.32+ Fix from $2,3002026-02-04 CRITICAL 9.1 CVE-2026-25139 RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded de… Riot after 2025.10 Fix from $2,3002026-02-04 CRITICAL 9.1 CVE-2026-22247 GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through … Glpi 11.0.5+ Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2025-64712 The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, a… Unstructured 0.18.18+ Fix from $2,3002026-02-04 CRITICAL 9.9 CVE-2026-25115 n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to bre… N8n 2.4.8+ Fix from $2,3002026-02-04 CRITICAL 9.9 CVE-2026-25053 n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users… N8n 1.123.0 / 2.5.0+ Fix from $2,3002026-02-04 CRITICAL 9.9 CVE-2026-25052 n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenti… N8n 1.123.18 / 2.5.0+ Fix from $2,3002026-02-04 CRITICAL 9.9 CVE-2026-25049 n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify w… N8n 1.123.17 / 2.5.2+ Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2025-5329 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation … Mitigation only Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2025-59818 This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file. Tcis 3 Firmware 9.2.3.3+ Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2026-1813 A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUp… Bolo Solo after 2.6.4 Fix from $2,3002026-02-04 CRITICAL 10.0 CVE-2026-1633 The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthent… Mitigation only Fix from $2,3002026-02-04 CRITICAL 9.8 CVE-2026-1812 A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the file src/main/java/org/b3log/so… Bolo Solo after 2.6.4 Fix from $2,3002026-02-03 CRITICAL 9.1 CVE-2026-1632 MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthen… Mitigation only Fix from $2,3002026-02-03 CRITICAL 10.0 CVE-2026-25150 Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function w… Qwik 1.19.0+ Fix from $2,3002026-02-03 CRITICAL 9.3 CVE-2026-1341 Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control. Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37090 School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upl… School Erp Pro Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37089 School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries throu… School Erp Pro Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37080 webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delet… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37075 LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows remote attackers to execute ar… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37074 Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wiza… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37071 CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a … Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37070 CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attac… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37069 Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Atta… Ftp Utility Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37068 Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Atta… Ftp Utility Mitigation only Fix from $2,3002026-02-03