Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-50981 An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is … Mitigation only Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2025-8587 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Technology R&D Industry and Trade… Skspro after 2026-07-01 Fix from $2,3002026-02-02 CRITICAL 9.1 CVE-2024-5986 A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploi… Mitigation only Fix from $2,3002026-02-02 CRITICAL 9.6 CVE-2024-2356 A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically withi… Patch available Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2026-20418 In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additiona… Matter after 1.4 Fix from $2,3002026-02-02 CRITICAL 9.3 CVE-2026-20407 In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with … Nbiot Sdk after 3.8 Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2025-15030 The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to re… Mitigation only Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2026-25202 The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects M… Magicinfo 9 Server 21.1090.1+ Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2026-25200 A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in … Magicinfo 9 Server 21.1090.1+ Fix from $2,3002026-02-02 CRITICAL 9.8 CVE-2026-1740 A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the compo… A8004t Firmware Mitigation only Fix from $2,3002026-02-02 CRITICAL 9.3 CVE-2026-25069 SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log file API endpoints. An unauth… Mitigation only Fix from $2,3002026-02-01 CRITICAL 9.8 CVE-2020-37057 Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through th… Online Exam System Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2020-37056 Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating reque… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2020-37052 AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system … Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2020-37050 Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with care… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2020-37043 10-Strike Bandwidth Monitor 3.9 contains a buffer overflow vulnerability that allows attackers to bypass SafeSEH, ASLR, and DEP protections through c… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2020-37027 Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the ext… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2019-25232 NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary she… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2026-25141 Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7… Orval 7.21.0 / 8.2.0+ Fix from $2,3002026-01-30 CRITICAL 9.6 CVE-2026-25130 Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple… Patch available Fix from $2,3002026-01-30 CRITICAL 9.2 CVE-2026-1723 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injecti… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2025-51958 aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system commands via lib/plugins/runcomm… Runcommand Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2026-1701 A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown processing of the file /enro… School Management System Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2026-1688 A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an unknown function of the file /… Directory Management System Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.2 CVE-2025-7964 After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zi… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.5 CVE-2025-26385 Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability… Mitigation only Fix from $2,3002026-01-30 CRITICAL 10.0 CVE-2026-24729 An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allow… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.3 CVE-2026-24728 A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 al… Mitigation only Fix from $2,3002026-01-30 CRITICAL 9.8 CVE-2026-1340 KEVEPSS 86% A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Endpoint Manager Mobile after 12.7.0.0 Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2026-1281 KEVEPSS 82% A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Endpoint Manager Mobile after 12.5.0.0 Fix from $2,3002026-01-29