Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Cups HIGH 7.5
CVE-2026-34980

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-expos…

Fix: after 2.4.16
Fix from $1,950 2026-04-03
Ragflow HIGH 8.8
CVE-2026-28797

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerab…

Fix: after 0.24.0
Fix from $1,950 2026-04-03
Unclassified HIGH 7.5
CVE-2020-37216

Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper hand…

Mitigation only
Fix from $1,950 2026-04-03
Core Flight System HIGH 7.0
CVE-2026-5473

A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipul…

Fix: after 7.0.0
Fix from $1,950 2026-04-03
Vllm HIGH 7.1
CVE-2026-34760

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, Librosa defaults to using nump…

Fix: 0.18.0+
Fix from $1,950 2026-04-02
Signal K Server MEDIUM 6.5
CVE-2026-35038

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerabi…

Fix: 2.24.0+
Fix from $1,600 2026-04-02
Phpmyfaq MEDIUM 6.1
CVE-2026-32629

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address that…

Fix: 4.1.1+
Fix from $1,600 2026-04-02
Secure Email Gateway CRITICAL 9.1
CVE-2026-29143

SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an a…

Fix: 15.0.3+
Fix from $2,300 2026-04-02
Secure Email Gateway MEDIUM 5.3
CVE-2026-29144

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike…

Fix: 15.0.3+
Fix from $1,600 2026-04-02
Secure Email Gateway MEDIUM 5.3
CVE-2026-29137

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.

Fix: 15.0.3+
Fix from $1,600 2026-04-02
Secure Email Gateway MEDIUM 5.3
CVE-2026-29141

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].

Fix: 15.0.3+
Fix from $1,600 2026-04-02
Secure Email Gateway CRITICAL 9.1
CVE-2026-29133

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.

Fix: 15.0.3+
Fix from $2,300 2026-04-02
Secure Email Gateway HIGH 7.5
CVE-2026-29135

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization.

Fix: 15.0.3+
Fix from $1,950 2026-04-02
Aiohttp MEDIUM 5.3
CVE-2026-34525

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohtt…

Fix: 3.13.4+
Fix from $1,600 2026-04-01
Onnx HIGH 8.6
CVE-2026-34445

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in…

Fix: 1.21.0+
Fix from $1,950 2026-04-01
Unclassified CRITICAL 9.8
CVE-2026-20093

A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker …

Mitigation only
Fix from $2,300 2026-04-01
Loan Management System MEDIUM 6.5
CVE-2026-30523

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allow…

No fix yet
Fix from $1,600 2026-04-01
Freescout MEDIUM 6.1
CVE-2026-34442

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout ve…

Fix: 1.8.211+
Fix from $1,600 2026-03-31
Unclassified HIGH 8.3
CVE-2025-14213

Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket …

Mitigation only
Fix from $1,950 2026-03-31
Nginx Ui MEDIUM 6.5
CVE-2026-33029

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration a…

Fix: 2.3.4+
Fix from $1,600 2026-03-30
Openairinterface HIGH 7.5
CVE-2026-30077

OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for p…

Mitigation only
Fix from $1,950 2026-03-30
Mrcms MEDIUM 5.3
CVE-2026-29909

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks au…

No fix yet
Fix from $1,600 2026-03-30
Node.js MEDIUM 6.5
CVE-2026-21712

A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain n…

Fix: after 25.8.1
Fix from $1,600 2026-03-30
Unclassified HIGH 7.5
CVE-2026-4987

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up…

Mitigation only
Fix from $1,950 2026-03-28
Ecdsa MEDIUM 5.3
CVE-2026-33936

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signatur…

Fix: 0.19.2+
Fix from $1,600 2026-03-27
Forge HIGH 7.5
CVE-2026-33894

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 sig…

Fix: 1.4.0+
Fix from $1,950 2026-03-27
Statamic MEDIUM 6.5
CVE-2026-33882

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the markdown preview endpoint could be ma…

Fix: 5.73.16 / 6.7.2+
Fix from $1,600 2026-03-27
Web Based Pharmacy Product Management System HIGH 7.5
CVE-2026-30576

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to va…

No fix yet
Fix from $1,950 2026-03-27
Web Based Pharmacy Product Management System HIGH 7.5
CVE-2026-30575

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to va…

No fix yet
Fix from $1,950 2026-03-27
Openbao MEDIUM 6.1
CVE-2026-33758

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authenticatio…

Fix: 2.5.2+
Fix from $1,600 2026-03-27