Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-18615 A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-b… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18614 A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18613 A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the c… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18612 A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-41452 Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrit… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.1 CVE-2026-39932 OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that al… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18602 A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc o… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.1 CVE-2026-18248 @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.1 CVE-2026-9487 XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolve… \ 0.71+ Fix from $2,3002026-08-03 CRITICAL 9.1 CVE-2026-9390 XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions … \ 0.71+ Fix from $2,3002026-08-03 CRITICAL 10.0 CVE-2026-69085 SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is … No fix yet Fix from $2,3002026-08-03 CRITICAL 10.0 CVE-2026-69084 SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-wr… No fix yet Fix from $2,3002026-08-03 CRITICAL 10.0 CVE-2026-69083 SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-64827 Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18601 A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the compon… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18108 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypte… Net\ 0.86+ Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-2346 Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affe… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.3 CVE-2026-18574 An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an una… No fix yet Fix from $2,3002026-08-03 CRITICAL 10.0 CVE-2026-33591 A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially … No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18589 A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of th… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18588 A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the arg… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.1 CVE-2026-16534 The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions du… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.1 CVE-2026-16532 The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing u… Mitigation only Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-16300 The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the pass… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-16250 The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowi… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-16060 The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, re… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.4 CVE-2026-15930 The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value … No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-12872 The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authenticatio… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.1 CVE-2026-14557 The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-ver… Mitigation only Fix from $2,3002026-08-03 CRITICAL 9.1 CVE-2026-12965 The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, a… No fix yet Fix from $2,3002026-08-03