Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-30623EPSS 6%

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP serv…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-30618

xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker …

Mitigation only
Fix from $2,300 2026-07-15
Unclassified MEDIUM 6.1
CVE-2026-26719

Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request contain…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified CRITICAL 9.1
CVE-2026-26718

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2025-65720

An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted H…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified HIGH 8.7
CVE-2026-56679

9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.1
CVE-2026-55399

CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with valid credentials to the Secure A…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-51380

Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially e…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified MEDIUM 6.9
CVE-2026-55398

CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with intimate knowledge of and tot…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 5.3
CVE-2026-33684

WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in sign…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 6.9
CVE-2026-33444

CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate knowledge of and total control o…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 6.7
CVE-2026-40953

CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and admini…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 5.4
CVE-2026-62355

TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine …

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 5.4
CVE-2026-62353

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() inc…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 7.5
CVE-2026-62351

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompress…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.2
CVE-2026-62350

TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could …

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.3
CVE-2026-62349

TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c t…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.4
CVE-2026-62348

TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-priv…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 5.9
CVE-2026-54443

Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 8.2
CVE-2026-46485

Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated …

Mitigation only
Fix from $1,950 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-46421

The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL da…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified HIGH 7.8
CVE-2026-15895

OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.5
CVE-2026-15746

Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use wit…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 7.5
CVE-2026-12997

The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_file…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.9
CVE-2026-61643

FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that po…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 7.8
CVE-2026-56687

Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attacker with local access could po…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.1
CVE-2026-56087

Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potential…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-50562

FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted …

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-14960

Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified MEDIUM 6.2
CVE-2026-14961

Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sensitive IOCTL functionality. T…

Mitigation only
Fix from $1,600 2026-07-15