Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-37067 Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attacker… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37066 GoldWave 5.70 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting malicious input in the File Open U… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37065 StreamRipper32 version 2.6 contains a buffer overflow vulnerability in the Station/Song Section that allows attackers to overwrite memory by manipula… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.3 CVE-2025-65078 An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be … Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-62799 Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.… Debian Linux 2.6.11 / 3.3.1+ Fix from $2,3002026-02-03 CRITICAL 10.0 CVE-2025-10878 A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parame… Fikir Odalari Adminpando after 1.0.1 Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25241 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<packa… Pearweb 1.33.0+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25240 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::ma… Pearweb 1.33.0+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25238 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription d… Pearweb 1.33.0+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25237 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug u… Pearweb 1.33.0+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25236 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to… Pearweb 1.33.0+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-25234 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion … Pearweb 1.33.0+ Fix from $2,3002026-02-03 CRITICAL 9.1 CVE-2026-25233 PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead… Pearweb 1.33.0+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-69983 FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-suppl… Fuxa Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-69981 FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allow… Fuxa Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-69971 FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to sign and veri… Fuxa Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.3 CVE-2025-69970 FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' flag is commented out by defa… Fuxa Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-67188 A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg interface of the /lib/cste_mo… A950rg Firmware Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-67187 A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists in the setIpQosRules interface… A950rg Firmware Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-67186 TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /lib/cste_modules/firewall.so.… A950rg Firmware Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-65875 An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a… Fpdf Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-63624 SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows a remote attacker to execute… Iot Smart Water Meter Firmware Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-61506 An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpo… Mediacrush after 1.0.1 Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-57529 YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to insufficient input validatio… Cpas Audit Management System after 4.9 Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-52626 A Potential Command Injection vulnerability in HCL AION.  An This can allow unintended command execution, potentially leading to unauthorized actio… Aion Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2020-37110 60CycleCMS 2.5.2 contains an SQL injection vulnerability in news.php and common/lib.php that allows attackers to manipulate database queries through … 60cyclecms Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.6 CVE-2026-1568 Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allo… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-5319 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics and Communication Technologies… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.3 CVE-2026-1432 SQL injection vulnerability in the Buroweb platform version 2505.0.12, specifically in the 'tablon' component. This vulnerability is present in sever… Mitigation only Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-67856 A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges… Moodle 4.1.22 / 4.4.12+ Fix from $2,3002026-02-03