Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-1125EPSS 15% A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings.… Dir 823x Firmware Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1124 A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report… Ksoa Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.9 CVE-2026-0863EPSS 9% Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted… N8n after 2.4.2 Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1123 A vulnerability was identified in Yonyou KSOA 9.0. Affected is an unknown function of the file /worksheet/work_mod.jsp of the component HTTP GET Para… Ksoa Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1122 A vulnerability was determined in Yonyou KSOA 9.0. This impacts an unknown function of the file /worksheet/work_info.jsp of the component HTTP GET Pa… Ksoa Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1121 A vulnerability was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp of the component HTTP GET Para… Ksoa Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1120 A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component H… Ksoa Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1119 A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/delete_activity.p… Society Management System Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1118 A vulnerability was detected in itsourcecode Society Management System 1.0. Impacted is an unknown function of the file /admin/add_activity.php. Perf… Society Management System Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1107 A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Av… Eyoucms Mitigation only Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1105 A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of … Easycms after 1.6 Fix from $2,3002026-01-18 CRITICAL 9.8 CVE-2026-1062 A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java.… Teamwork Management System after 2.28.0 Fix from $2,3002026-01-17 CRITICAL 9.8 CVE-2026-1061 A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/… Teamwork Management System after 2.28.0 Fix from $2,3002026-01-17 CRITICAL 9.8 CVE-2026-1059 A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknow… Warehouse Management System after 2021-11-15 Fix from $2,3002026-01-17 CRITICAL 9.8 CVE-2025-10484 The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, … Mitigation only Fix from $2,3002026-01-17 CRITICAL 9.8 CVE-2025-15403 The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'a… Mitigation only Fix from $2,3002026-01-17 CRITICAL 10.0 CVE-2026-23800 Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from 2.5.2 be… Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2026-23744EPSS 45% MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vu… Inspector 1.4.3+ Fix from $2,3002026-01-16 CRITICAL 9.3 CVE-2012-10064 Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-co… No fix yet Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14894 Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME val… Filemanager 1.0.0+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-59870 HCL MyXalytics  is affected by improper management of a static JWT signing secret in the web application, where the secret lacks rotation , introduci… Myxalytics Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-60021EPSS 25% Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to … Brpc 1.15.0+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2026-0975 Delta Electronics DIAView has Command Injection vulnerability. Diaview 4.4.0+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2026-1021 Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload a… Police Statistics Database System after 1.0.2 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2026-1019 Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, m… Police Statistics Database System after 1.0.3 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-62582 Delta Electronics DIAView has multiple vulnerabilities. Diaview 4.4.0+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-62581 Delta Electronics DIAView has multiple vulnerabilities. Diaview 4.4.0+ Fix from $2,3002026-01-16 CRITICAL 10.0 CVE-2025-61937 The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” s… Process Optimization 2025+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14237 Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network … Mf455dw Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14236 Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment… Mf455dw Firmware after 06.02 Fix from $2,3002026-01-16