Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-24465 Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code execution. Wab S300iw Pd Firmware 1.13 / 5.5.02+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2026-24936 When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation vulnerability in a specific CGI progr… Data Master 5.1.2.re51+ Fix from $2,3002026-02-03 CRITICAL 9.8 CVE-2025-67484 Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFormatXml.Php. This issue affec… Mediawiki 1.39.16 / 1.43.6+ Fix from $2,3002026-02-03 CRITICAL 10.0 CVE-2026-25142 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain proto… Sandboxjs 0.8.27+ Fix from $2,3002026-02-02 CRITICAL 9.1 CVE-2026-25137EPSS 10% The NixOs Odoo package is an open source ERP and CRM system. From 21.11 to before 25.11 and 26.05, every NixOS based Odoo setup publicly exposes the … Patch available Fix from $2,3002026-02-02 CRITICAL 9.3 CVE-2026-24471 continuwuity is a Matrix homeserver written in Rust. This vulnerability allows an attacker with a malicious remote server to cause the local server t… No fix yet Fix from $2,3002026-02-02 CRITICAL 9.0 CVE-2026-23997 FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cross-Site Scripting (XSS) vulne… Facturascripts 2025.71+ Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2026-22778 vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multim… Vllm 0.14.1+ Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2025-66480 Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component re… Im Server 1.4.3+ Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2022-50981 An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is … Mitigation only Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2025-8587 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Technology R&D Industry and Trade… Skspro after 2026-07-01 Fix from $2,3002026-02-02 CRITICAL 9.1 CVE-2024-5986 A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploi… Mitigation only Fix from $2,3002026-02-02 CRITICAL 9.6 CVE-2024-2356 A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically withi… Patch available Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2026-20418 In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additiona… Matter after 1.4 Fix from $2,3002026-02-02 CRITICAL 9.3 CVE-2026-20407 In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with … Nbiot Sdk after 3.8 Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2025-15030 The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to re… Mitigation only Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2026-25202 The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects M… Magicinfo 9 Server 21.1090.1+ Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2026-25200 A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in … Magicinfo 9 Server 21.1090.1+ Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2026-1740 A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the compo… A8004t Firmware Mitigation only Fix from $2,3002026-02-02 CRITICAL 9.3 CVE-2026-25069 SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log file API endpoints. An unauth… Mitigation only Fix from $2,3002026-02-01 CRITICAL 9.8 CVE-2020-37057 Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through th… Online Exam System Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2020-37056 Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating reque… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2020-37052 AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system … Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2020-37050 Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with care… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2020-37043 10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR, and DEP protections through c… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2020-37027 Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the ext… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2019-25232 NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary she… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2026-25141 Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7… Orval 7.21.0 / 8.2.0+ Fix from $2,3002026-01-30 CRITICAL 9.6 CVE-2026-25130 Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple… Patch available Fix from $2,3002026-01-30 CRITICAL 9.2 CVE-2026-1723 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti… Mitigation only Fix from $2,3002026-01-30