Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-69762 Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote … Ax3 Firmware Mitigation only Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2021-47875 GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buf… Mitigation only Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2021-47854 DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execu… Mitigation only Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2021-47851 Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands through an unauthenticated HTTP e… Mini Mouse Mitigation only Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2021-47748 Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell commands through SQL query manip… Graphql Engine Mitigation only Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2026-20045 KEV A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME… Unified Communications Manager 14su5+ Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2026-24061 KEVEPSS 98% telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. Debian Linux after 2.7 Fix from $2,3002026-01-21 CRITICAL 9.8 CVE-2025-15521 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account takeove… Mitigation only Fix from $2,3002026-01-21 CRITICAL 9.9 CVE-2026-0933 SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--com… Wrangler 3.114.17 / 4.59.1+ Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2026-21969 Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal). The support… Agile Product Lifecycle Management For Process Mitigation only Fix from $2,3002026-01-20 CRITICAL 10.0 CVE-2026-21962 KEVEPSS 42% Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy P… HTTP Server Patch available Fix from $2,3002026-01-20 CRITICAL 10.0 CVE-2026-21636 A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even … Node.js 25.3.0+ Fix from $2,3002026-01-20 CRITICAL 9.1 CVE-2025-55130 A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink… Node.js 20.20.0 / 22.22.0+ Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2025-56005EPSS 17% An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the… Ply No fix yet Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2025-55423 A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port… N104s R1 Firmware after 12.07.6 Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2025-65482 An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a craft… Xdocreport after 2.0.3 Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2025-64087 A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows attackers to execu… Xdocreport after 2.1.0 Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2025-36418 IBM ApplinX 11.1 is vulnerable due to a privilege escalation vulnerability due to improper verification of JWT tokens. An attacker may be able to cra… Applinx Mitigation only Fix from $2,3002026-01-20 CRITICAL 9.9 CVE-2026-22844EPSS 13% A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote … Mitigation only Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2025-14533 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This i… Mitigation only Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2026-1221 PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote att… Mitigation only Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2026-0907EPSS 8% Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page.… Chrome 144.0.7559.59 / 144.0.7559.60+ Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2026-0906 Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) vi… Chrome 144.0.7559.59 / 144.0.7559.60+ Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2026-0905 Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially o… Chrome 144.0.7559.59 / 144.0.7559.60+ Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2026-23947 Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vul… Orval 7.19.0 / 8.0.2+ Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2026-23876 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffe… Imagemagick 6.9.13-38 / 7.1.2-13+ Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2026-22770 ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of d… Imagemagick 7.1.2-13+ Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2026-1202 A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file crmeb/app/api/controller/v1/Log… Crmeb after 5.6.3 Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2026-1179 A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the component HTTP GET Parameter H… Ksoa Mitigation only Fix from $2,3002026-01-19 CRITICAL 9.8 CVE-2026-23944 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthenticated requests could be prox… Arcane 1.13.2+ Fix from $2,3002026-01-19