Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-1021 Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload a… Police Statistics Database System after 1.0.2 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2026-1019 Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, m… Police Statistics Database System after 1.0.3 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-62582 Delta Electronics DIAView has multiple vulnerabilities. Diaview 4.4.0+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-62581 Delta Electronics DIAView has multiple vulnerabilities. Diaview 4.4.0+ Fix from $2,3002026-01-16 CRITICAL 10.0 CVE-2025-61937 The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” s… Process Optimization 2025+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14237 Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network … Mf455dw Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14236 Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment… Mf455dw Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14235 Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the netw… Mf656cdw Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14234 Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segme… Mf455dw Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14233 Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network… Lbp1238 Ii Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14232 Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network… Mf455dw Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2025-14231 Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the networ… Lbp1238 Ii Firmware after 06.02 Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2021-47812 GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configuration and execute PHP code thro… Grav Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.1 CVE-2021-47811 Grocery Crud 1.6.4 contains a SQL injection vulnerability in the order_by parameter that allows remote attackers to manipulate database queries. Atta… Grocery Crud 2.0.1+ Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2021-47798 NoteBurner 2.35 contains a buffer overflow vulnerability in the license code input field that allows attackers to crash the application. Attackers ca… Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2021-47796 Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attackers to access a Linux shell. … Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2021-47785 Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote code execution. Attackers can cr… Ether Mp3 Cd Burner Mitigation only Fix from $2,3002026-01-16 CRITICAL 9.8 CVE-2026-22864 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning… Deno 2.5.6+ Fix from $2,3002026-01-15 CRITICAL 9.4 CVE-2025-67822 A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenti… Mivoice Mx One 7.8+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2023-7334 Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code exe… T\+ after 16.000.000.0283 Fix from $2,3002026-01-15 CRITICAL 9.3 CVE-2011-10041 Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file … Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2025-70892 Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly … Cyber Cafe Management System Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.3 CVE-2026-23746 Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to 6.10.5, and prior to 6.11.1 … Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2026-23527 H3 is a minimal H(TTP) framework built for high performance and portability. Prior to 1.15.5, there is a critical HTTP Request Smuggling vulnerabilit… H3 1.15.5+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2026-23519 RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as … Cmov 0.4.4+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2026-22249 Docmost is an open-source collaborative wiki and documentation software. From 0.21.0 to before 0.24.0, Docmost is vulnerable to Arbitrary File Write … Docmost 0.24.0+ Fix from $2,3002026-01-15 CRITICAL 9.1 CVE-2025-67647 SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, SvelteKit is vulnerable to a serve… Adapter Node 2.49.5 / 5.5.1+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2025-66417 GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQL injection through the inven… Glpi 11.0.3+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2025-62193 Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret express… Patch available Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2025-67079 File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL engine of the Imagick library vi… Agora Project 25.10+ Fix from $2,3002026-01-15