Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-47819 ProjeQtOr Project Management 9.1.4 contains a file upload vulnerability that allows guest users to upload malicious PHP files with arbitrary code exe… Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47781 Cmder Console Emulator 1.3.18 contains a buffer overflow vulnerability that allows attackers to trigger a denial of service condition through a malic… Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47774 Kingdia CD Extractor 3.0.2 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code. A… Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47772 10-Strike Network Inventory Explorer Pro 9.31 contains a buffer overflow vulnerability in the text file import functionality that allows remote code … Network Inventory Explorer Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2021-47753 phpKF CMS 3.00 Beta y6 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary code by bypassing file… Cms Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.9 CVE-2025-67084 File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files into attachments, which can late… Invoiceplane 1.6.4+ Fix from $2,3002026-01-15 CRITICAL 9.1 CVE-2026-22910 The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. Thi… Tdc X401gl Firmware Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.1 CVE-2026-22909 Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potential… Tdc X401gl Firmware Mitigation only Fix from $2,3002026-01-15 CRITICAL 9.1 CVE-2026-22908 Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confi… Tdc X401gl Firmware 1.4.0+ Fix from $2,3002026-01-15 CRITICAL 9.1 CVE-2026-22907 An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data. Tdc X401gl Firmware 1.4.0+ Fix from $2,3002026-01-15 CRITICAL 9.1 CVE-2026-22859 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑suppli… Freerdp 3.20.1+ Fix from $2,3002026-01-14 CRITICAL 9.1 CVE-2026-22858 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding pa… Freerdp 3.20.1+ Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2026-22857 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap use-after-free occurs in irp_thread_func because the IRP is … Freerdp 3.20.1+ Fix from $2,3002026-01-14 CRITICAL 9.1 CVE-2026-22855 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path wh… Freerdp 3.20.1+ Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2026-22854 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlle… Freerdp 3.20.1+ Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2026-22853 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the o… Freerdp 3.20.1+ Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2026-22852 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in … Freerdp 3.20.1+ Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2026-22708 Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce… Cursor 2.3+ Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2025-70968 FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE(). Freeimage Mitigation only Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2025-37184 A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requireme… Edgeconnect Sd Wan Orchestrator 9.3.6 / 9.4.3+ Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2026-22238 The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this… Bluvoyix Mitigation only Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2026-22237 The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit th… Bluvoyix Mitigation only Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2026-22236 The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit th… Bluvoyix Mitigation only Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2026-23550EPSS 21% Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: fr… Mitigation only Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2025-14502 The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the templa… Mitigation only Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2025-14301 The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is d… Mitigation only Fix from $2,3002026-01-14 CRITICAL 10.0 CVE-2026-22686 Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in… Enclave 2.7.0+ Fix from $2,3002026-01-14 CRITICAL 9.8 CVE-2023-54339 Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter… Webgrind after 1.1 Fix from $2,3002026-01-13 CRITICAL 9.1 CVE-2023-54337 Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the applicatio… Multi Server No fix yet Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2023-54335EPSS 5% eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request.… Extplorer after 2.1.14 Fix from $2,3002026-01-13