Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-14235 Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the netw… Mf656cdw Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14234 Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segme… Mf455dw Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14233 Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network… Lbp1238 Ii Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14232 Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network… Mf455dw Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14231 Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the networ… Lbp1238 Ii Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2021-47812 GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code thro… Grav Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.1 CVE-2021-47811 Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Atta… Grocery Crud 2.0.1+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2021-47798 NoteBurner 2.35 contains a buffer overflow vulnerability in the license code input field that allows attackers to crash the application. Attackers ca… Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2021-47796 Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. … Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2021-47785 Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote code execution. Attackers can cr… Ether Mp3 Cd Burner Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2026-22864 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning… Deno 2.5.6+ Fix from $2,3002026-01-15 CRITICAL 9.4 CVE-2025-67822 A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenti… Mivoice Mx One 7.8+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2023-7334 Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code exe… T\+ after 16.000.000.0283 Fix from $2,3002026-01-15 CRITICAL 9.3 CVE-2011-10041 Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file … Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2025-70892 Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly … Cyber Cafe Management System Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.3 CVE-2026-23746 Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 … Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2026-23527 H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerabilit… H3 1.15.5+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2026-23519 RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as … Cmov 0.4.4+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2026-22249 Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write … Docmost 0.24.0+ Fix from $2,3002026-01-15 CRITICAL 9.1 CVE-2025-67647 SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a serve… Adapter Node 2.49.5 / 5.5.1+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2025-66417 GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven… Glpi 11.0.3+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2025-62193 Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret express… Patch available Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2025-67079 File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library vi… Agora Project 25.10+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47819 ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code exe… Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47781 Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of service condition through a malic… Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47774 Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. A… Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47772 10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code … Network Inventory Explorer Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47753 phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file… Cms Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.9 CVE-2025-67084 File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can late… Invoiceplane 1.6.4+ Fix from $2,3002026-01-15 CRITICAL 9.1 CVE-2026-22910 The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. Thi… Tdc X401gl Firmware Mitigation only Fix from $2,3002026-01-15