Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-24770 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a … Ragflow after 0.23.1 Fix from $2,3002026-01-27 CRITICAL 9.9 CVE-2026-24740 Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restrict… Dozzle 9.0.3+ Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2025-21589 An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacke… Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-24858 KEVEPSS 86% An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Fort… Fortianalyzer 7.4.10 / 7.4.11+ Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2025-14988 A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the… No fix yet Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-24881 In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflo… Gnupg 2.5.17 / 5.0.1+ Fix from $2,3002026-01-27 CRITICAL 9.1 CVE-2026-22264 Suricata is a network IDS, IPS and NSM engine. Prior to version 8.0.3 and 7.0.14, an unsigned integer overflow can lead to a heap use-after-free cond… Suricata 7.0.14 / 8.0.3+ Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-22262 Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14,… Suricata 7.0.14 / 8.0.3+ Fix from $2,3002026-01-27 CRITICAL 9.9 CVE-2026-22039 Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bo… Kyverno 1.15.3 / 1.16.3+ Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2025-69564 code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password,… Mobile Shop Management System Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2025-69563 code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter. Mobile Shop Management System Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2025-69562 code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter. Mobile Shop Management System Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2025-69559 code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php. Computer Book Store Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.1 CVE-2026-24874 Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before … Xray Monolith 2025.12.30+ Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-24872 improper pointer arithmetic vulnerability in ProjectSkyfire SkyFire_548.This issue affects SkyFire_548: before 5.4.8-stable5. Patch available Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2026-24871 Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects Minecraft-Rcon-Mana… Patch available Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-24832 Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3. Ix Ray Engine 1.6 1.3+ Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2025-69565 code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php. Mobile Shop Management System Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2025-68670 xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from im… Debian Linux 0.10.5+ Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2021-47901 Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected e… Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2021-47900 Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system comm… Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2020-36948 VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attac… Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2020-36941 Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server he… Knockpy Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2020-36940 Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows attackers to crash the applica… Mitigation only Fix from $2,3002026-01-27 CRITICAL 9.9 CVE-2026-1470EPSS 19% n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated… N8n 1.123.17 / 2.4.5+ Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-24830 Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2. Patch available Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2026-24826 Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability i… Patch available Fix from $2,3002026-01-27 CRITICAL 9.1 CVE-2026-24346 Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web applicat… Ezcast Pro Dongle Ii Firmware Mitigation only Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2026-24823 Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in FASTSHIFT X-TRACK (Software/X-Track/USER… Patch available Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2026-24822 Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files… Patch available Fix from $2,3002026-01-27