Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1607 HIGH 7.0
CVE-2026-68820 KEV

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Adaptive Security Appliance Software HIGH 8.6
CVE-2026-20349 KEV

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall T…

No fix yet
Fix from $4,900 2026-08-11
Metabase CRITICAL 10.0
CVE-2026-72898 KEVEPSS 10%

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access …

Fix: 0.58.24 / 0.59.21+
Fix from $5,750 2026-08-10
macOS CRITICAL 9.8
CVE-2026-65400 KEV

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2…

Fix: 14.8.9 / 15.7.9+
Fix from $2,300 2026-08-06
N Central HIGH 8.1
CVE-2026-18577 KEV

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Fix: 2026.3+
Fix from $1,950 2026-08-02
N Central HIGH 7.4
CVE-2026-18556 KEV

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-centra…

Fix: after 2026.1
Fix from $1,950 2026-08-01
Vcenter Server CRITICAL 9.8
CVE-2026-59310 KEV

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i…

No fix yet
Fix from $2,300 2026-07-30
Secure Firewall Management Center MEDIUM 5.3
CVE-2026-20316 KEV

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log…

Fix: after 10.0.1
Fix from $1,600 2026-07-29
Teamcity CRITICAL 9.8
CVE-2026-63077 KEVEPSS 11%

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Fix: 2025.11.7 / 2026.1.3+
Fix from $2,300 2026-07-27
Velocloud Orchestrator CRITICAL 10.0
CVE-2026-16812 KEV

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…

Fix: 5.2.3.14 / 6.1.3.4+
Fix from $2,300 2026-07-27
Multi Domain Security Management CRITICAL 9.8
CVE-2026-16232 KEVEPSS 73%

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicati…

No fix yet
Fix from $2,300 2026-07-22
WordPress CRITICAL 9.8
CVE-2026-63030 KEVEPSS 96%

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…

Fix: 6.9.5 / 7.0.2+
Fix from $2,300 2026-07-17
WordPress MEDIUM 5.9
CVE-2026-60137 KEVEPSS 73%

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…

Fix: 6.8.6 / 6.9.5+
Fix from $1,600 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-9198 KEVEPSS 17%

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Dd Wrt HIGH 8.1
CVE-2021-27137 KEVEPSS 16%

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticat…

Fix: 45724+
Fix from $1,950 2026-07-16
Sma6210 Firmware HIGH 7.2
CVE-2026-15410 KEVEPSS 76%

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

Mitigation only
Fix from $1,950 2026-07-14
Sma6210 Firmware CRITICAL 10.0
CVE-2026-15409 KEVEPSS 74%

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

Mitigation only
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.1
CVE-2026-55040 KEV

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-58644 KEVEPSS 45%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-56164 KEVEPSS 22%

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-56155 KEV

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locall…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-50522 KEVEPSS 77%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Forms CRITICAL 9.8
CVE-2026-56291 KEVEPSS 76%

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to…

Fix: 2.4.1+
Fix from $2,300 2026-07-09
Coldfusion CRITICAL 10.0
CVE-2026-48282 KEVEPSS 99%

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Mitigation only
Fix from $2,300 2026-06-30
Page Builder Ck CRITICAL 9.8
CVE-2026-56290 KEVEPSS 83%

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerabl…

Fix: 3.6.0+
Fix from $2,300 2026-06-29
Langflow HIGH 8.4
CVE-2026-55255 KEVEPSS 29%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabili…

Fix: 1.9.1+
Fix from $1,950 2026-06-23
Icagenda CRITICAL 9.8
CVE-2026-48939 KEVEPSS 83%

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP…

Fix: 3.9.15 / 4.0.8+
Fix from $2,300 2026-06-20
Sp Page Builder CRITICAL 9.8
CVE-2026-48908 KEVEPSS 88%

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and executio…

Fix: 6.6.2+
Fix from $2,300 2026-06-20
Flexplm CRITICAL 9.8
CVE-2026-12569 KEVEPSS 30%

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t…

Fix: 11.0m030+
Fix from $2,300 2026-06-18
Catalyst Sd Wan Manager MEDIUM 6.5
CVE-2026-20262 KEVEPSS 28%

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a fi…

Fix: 20.9.9.2 / 20.12.7.2+
Fix from $1,600 2026-06-15