Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2026-24821 Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files lparser.C… Patch available Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2026-24816 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in datavane tis (tis-console/src/main/java/com/qlangtech/tis/runtime/module/acti… Patch available Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2026-24815 Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangt… Patch available Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2026-24814 Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with program files s… Patch available Fix from $2,3002026-01-27 CRITICAL 9.3 CVE-2026-24812 Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inftrees.C. This issue affects root:… Patch available Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-24811 Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root. Root after 6.34.08 Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2026-24810 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in rethinkdb (src/cjson modules). This vulnerability is associat… Patch available Fix from $2,3002026-01-27 CRITICAL 9.2 CVE-2026-24804 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7603e/src/mt7603_wifi/common mod… Patch available Fix from $2,3002026-01-27 CRITICAL 9.2 CVE-2026-24803 Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7615d/src/mt_wifi/embedded/secur… Patch available Fix from $2,3002026-01-27 CRITICAL 10.0 CVE-2026-24800 Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in tildearrow furnace (extern/zlib modules)… Patch available Fix from $2,3002026-01-27 CRITICAL 9.3 CVE-2026-24798 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GaijinEntertainment DagorEngine (prog/3rdPartyLibs/miniupnpc… Patch available Fix from $2,3002026-01-27 CRITICAL 9.2 CVE-2026-24794 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in CardboardPowered cardboard (src/main/java/org/cardboardpower… Patch available Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-24793 Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in azerothcore azerothcore-wotlk (deps/zlib… Azerothcore after 4.0.0 Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-1361 ASDA-Soft Stack-based Buffer Overflow Vulnerability Asda Soft after 7.2.2.0 Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2026-24479EPSS 8% HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduo… Hustoj 26.01.24+ Fix from $2,3002026-01-27 CRITICAL 9.1 CVE-2026-24400 AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML… Assertj 3.27.7+ Fix from $2,3002026-01-26 CRITICAL 10.0 CVE-2026-22709 vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitizatio… Vm2 3.10.2+ Fix from $2,3002026-01-26 CRITICAL 9.3 CVE-2026-22696 dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 in… Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2026-1443 A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/Adm… Online Music Site Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2026-24436 Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authenti… W30e Firmware after 16.01.0.19 Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2026-24429 Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication … W30e Firmware after 16.01.0.19 Fix from $2,3002026-01-26 CRITICAL 9.9 CVE-2025-70982 Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive … Springblade Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.9 CVE-2016-15057 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum… Continuum Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.2 CVE-2025-59108 By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the password was not enforced. Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.2 CVE-2025-59103 The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware re… Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.3 CVE-2025-59097 The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done in a graphical user interfac… Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.3 CVE-2025-59091 Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. Th… Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.3 CVE-2025-59090 On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, net… Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2026-1423 A vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /admi… Online Examination System Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2026-1422 A vulnerability was found in code-projects Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /ind… Online Examination System Mitigation only Fix from $2,3002026-01-26