Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-71256 nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71254 nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in … No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71248 Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * f… Patch available Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-71238 DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Sinc… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71237 Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates i… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71231 IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after b… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-66747 Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the o… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-44945 A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user w… Patch available Fix from $2,3002026-08-05 CRITICAL 9.0 CVE-2026-10090 A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernet… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-10059 A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exp… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71214 The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraS… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-71213 Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when capt… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71207 The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.6 CVE-2026-70376 Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.ph… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-64566 In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_sk… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-61486 ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this pro… Lucy No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-61484 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th… Lucy Mitigation only Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-5581 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-4431 The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_pos… No fix yet Fix from $2,3002026-08-05 CRITICAL 10.0 CVE-2026-16940 The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-15360 The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthen… Mitigation only Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-15210 The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.3 CVE-2026-9273 The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading t… Mitigation only Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-45537 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concate… Patch available Fix from $2,3002026-08-04 CRITICAL 9.1 CVE-2026-45100 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in … Patch available Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-70554 MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-control… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.1 CVE-2026-67979 Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary … Mitigation only Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-66902 Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable sub… Patch available Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-45538 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longe… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-70553 MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application co… No fix yet Fix from $2,3002026-08-04