Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-54334 Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitr… Explorer\+\+ Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2023-54330 Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute a… Inbit Messenger after 4.9.0 Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2023-54329 Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands b… Inbit Messenger after 4.9.0 Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50935 Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50926 WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Atta… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50925 Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed We… Reflect Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50922 Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a s… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50919 Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrar… Tdarr Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50912 ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. A… Impresscms Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50910 Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password … Beehive Forum Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50895 Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exp… Aerocms Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50893 VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload … Wallpaper Admin Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2022-50892 VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating login credentials.… Wallpaper Admin Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2020-36911EPSS 11% Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privilege… Covenant after 0.5 Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-23478 Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attack… Cal.com 6.0.7+ Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-22871 GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, there is a path traversal vulnerability exists in GuardDog's safe_extract… Guarddog 2.7.1+ Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-22869 Eigent is a multi-agent Workforce. A critical security vulnerability in the CI workflow (.github/workflows/ci.yml) allows arbitrary code execution fr… Eigent 0.0.78+ Fix from $2,3002026-01-13 CRITICAL 9.1 CVE-2025-37168 Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exp… Arubaos 8.10.0.21 / 8.13.1.1+ Fix from $2,3002026-01-13 CRITICAL 10.0 CVE-2025-68271 OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.0 to 6.10.1, OpenC3 … Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2026-20963 KEVEPSS 32% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19127.20442+ Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2025-64155EPSS 43% An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.… Fortisiem 7.1.9 / 7.2.7+ Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2025-47855 An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 thr… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2025-25249 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiO… Fortios 6.4.17 / 7.0.6+ Fix from $2,3002026-01-13 CRITICAL 9.1 CVE-2025-25176 Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of… Ddk 25.3+ Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2025-69992 phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server witho… News Portal Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2025-69991 phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php. News Portal No fix yet Fix from $2,3002026-01-13 CRITICAL 9.1 CVE-2025-69990 phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be dele… News Portal No fix yet Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2025-68811 In the Linux kernel, the following vulnerability has been resolved: svcrdma: use rc_pageoff for memcpy byte offset svc_rdma_copy_inline_range added… Mitigation only Fix from $2,3002026-01-13 CRITICAL 9.1 CVE-2025-68809 In the Linux kernel, the following vulnerability has been resolved: ksmbd: vfs: fix race on m_flags in vfs_cache ksmbd maintains delete-on-close an… No fix yet Fix from $2,3002026-01-13 CRITICAL 9.8 CVE-2025-68794 In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-aligned positions iomap_adjust… No fix yet Fix from $2,3002026-01-13