Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-1420 A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /goform/WifiExtraSet. This manipulation of the argument… Ac23 Firmware Mitigation only Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2026-1414 A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impacts the function getInformation… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2026-1413 A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2026-1412 A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown funct… Operation And Maintenance Security Management System after 3.0.12 Fix from $2,3002026-01-26 CRITICAL 9.8 CVE-2025-13374 The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX a… Mitigation only Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2025-13952 A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in t… Ddk 25.3+ Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2026-22586 Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Ce… Marketing Cloud Engagement 2026-01-21+ Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2026-22585 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Cen… Marketing Cloud Engagement 2026-01-21+ Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2026-22583 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPages… Marketing Cloud Engagement 2026-01-21+ Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2026-22582 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeU… Marketing Cloud Engagement 2026-01-21+ Fix from $2,3002026-01-24 CRITICAL 9.8 CVE-2025-70457 A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The appli… Modern Image Gallery App Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.4 CVE-2025-52025 An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backend thru 2025-05-28. The vulner… Gemscms Backend after 2025-05-28 Fix from $2,3002026-01-23 CRITICAL 9.4 CVE-2025-52024 A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated us… Gemscms Backend after 2025-05-28 Fix from $2,3002026-01-23 CRITICAL 9.1 CVE-2025-70985 Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope. Ruoyi No fix yet Fix from $2,3002026-01-23 CRITICAL 9.9 CVE-2025-70983 Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges. Springblade Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-24423 KEVEPSS 88% SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. … Smartermail 100.0.9511+ Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2025-67229 An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauthenticated, on-path attacker t… Builder 0.32.1+ Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2022-25369EPSS 41% An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a l… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2021-47891 Unified Remote 3.9.0.2463 contains a remote code execution vulnerability that allows attackers to send crafted network packets to execute arbitrary c… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.1 CVE-2025-66719 An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/… Nrf Patch available Fix from $2,3002026-01-23 CRITICAL 10.0 CVE-2025-4320 Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technolo… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.4 CVE-2025-4319 Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Softw… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-1364 IAQS and I6 developed by JNC has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly operate system adminis… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-1363 IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticated remote attackers to gain a… Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0794 ALGO 8180 IP Audio Alerter SIP Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0793 ALGO 8180 IP Audio Alerter InformaCast Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to … 8180 Ip Audio Alerter Firmware Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0792 ALGO 8180 IP Audio Alerter SIP INVITE Alert-Info Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote at… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0791 ALGO 8180 IP Audio Alerter SIP INVITE Replaces Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote atta… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0787 ALGO 8180 IP Audio Alerter SAC Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… 8180 Ip Audio Alerter Firmware Mitigation only Fix from $2,3002026-01-23 CRITICAL 9.8 CVE-2026-0773 Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi… Mitigation only Fix from $2,3002026-01-23