Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pan Os CRITICAL 9.1
CVE-2026-0257 KEVEPSS 94%

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass se…

Fix: 10.2.7+
Fix from $2,300 2026-05-13
Mistralai CRITICAL 9.6
CVE-2026-45321 KEV

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. Th…

Mitigation only
Fix from $2,300 2026-05-12
Openshift Ai HIGH 8.8
CVE-2026-42271 KEVEPSS 83%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use…

Fix: 1.83.7 / 2.25.8+
Fix from $1,950 2026-05-08
Litellm CRITICAL 9.8
CVE-2026-42208 KEVEPSS 89%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query…

Fix: 1.83.7+
Fix from $2,300 2026-05-08
Endpoint Manager Mobile HIGH 7.2
CVE-2026-6973 KEVEPSS 34%

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative…

Fix: 12.6.1.1+
Fix from $1,950 2026-05-07
Pan Os CRITICAL 9.8
CVE-2026-0300 KEVEPSS 32%

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an un…

Mitigation only
Fix from $2,300 2026-05-06
Wp Squared CRITICAL 9.8
CVE-2026-41940 KEVEPSS 98%

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to …

Fix: 86.0.41 / 110.0.97+
Fix from $2,300 2026-04-29
Linux Kernel HIGH 7.8
CVE-2026-31431 KEVEPSS 100%

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi…

Fix: 4.12.89 / 4.13.66+
Fix from $1,950 2026-04-22
Defender Antimalware Platform HIGH 7.8
CVE-2026-33825 KEVEPSS 7%

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Fix: 4.18.26030.3011+
Fix from $1,950 2026-04-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-33824 KEVEPSS 56%

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $2,300 2026-04-14
Sharepoint Server MEDIUM 6.5
CVE-2026-32201 KEVEPSS 23%

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Fix: 16.0.19725.20210+
Fix from $1,600 2026-04-14
Fortisandbox CRITICAL 9.8
CVE-2026-39808 KEVEPSS 91%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

Fix: after 4.4.9
Fix from $2,300 2026-04-14
Acrobat Dc HIGH 8.6
CVE-2026-34621 KEVEPSS 7%

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes (…

Fix: 24.001.30360 / 24.001.30362+
Fix from $1,950 2026-04-11
Tomcat HIGH 7.5
CVE-2026-34486 KEVEPSS 83%

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. …

Mitigation only
Fix from $1,950 2026-04-09
Marimo CRITICAL 9.8
CVE-2026-39987 KEVEPSS 97%

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks au…

Fix: 0.23.0+
Fix from $2,300 2026-04-09
Activemq HIGH 8.8
CVE-2026-34197 KEVEPSS 97%

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach…

Fix: 5.19.4 / 6.2.3+
Fix from $1,950 2026-04-07
Forticlientems CRITICAL 9.8
CVE-2026-35616 KEVEPSS 91%

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized …

Patch available
Fix from $2,300 2026-04-04
Chrome HIGH 8.8
CVE-2026-5281 KEV

Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitra…

Fix: 146.0.7680.177+
Fix from $1,950 2026-04-01
Trueconf HIGH 7.8
CVE-2026-3502 KEVEPSS 6%

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update del…

Fix: 8.5.3.884+
Fix from $1,950 2026-03-30
Trivy HIGH 8.8
CVE-2026-33634 KEVEPSS 59%

Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push …

Fix: 0.2.6 / 0.35.0+
Fix from $1,950 2026-03-23
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2026-3055 KEVEPSS 84%

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

Fix: 13.1-37.262 / 13.1-62.23+
Fix from $2,300 2026-03-23
Langflow CRITICAL 9.8
CVE-2026-33017 KEVEPSS 96%

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

Fix: 1.8.2+
Fix from $2,300 2026-03-20
Chrome HIGH 8.8
CVE-2026-3910 KEV

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a…

Fix: 146.0.7680.75+
Fix from $1,950 2026-03-13
Chrome HIGH 8.8
CVE-2026-3909 KEV

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HT…

Fix: 146.0.7680.80+
Fix from $1,950 2026-03-13
Eds5032 Firmware CRITICAL 9.8
CVE-2025-67038 KEVEPSS 14%

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. …

Mitigation only
Fix from $2,300 2026-03-11
Secure Firewall Management Center CRITICAL 10.0
CVE-2026-20131 KEVEPSS 31%

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot…

Mitigation only
Fix from $2,300 2026-03-04
Sm7675p Firmware HIGH 7.8
CVE-2026-21385 KEV

Memory corruption while using alignments for memory allocation.

Patch available
Fix from $1,950 2026-03-02
Aria Operations HIGH 8.1
CVE-2026-22719 KEVEPSS 17%

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comm…

Fix: 5.2.3 / 8.18.6+
Fix from $1,950 2026-02-25
Catalyst Sd Wan Manager HIGH 7.5
CVE-2026-20133 KEVEPSS 31%

A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system…

Fix: 20.9.8.2 / 20.12.5.3+
Fix from $1,950 2026-02-25
Catalyst Sd Wan Manager HIGH 7.5
CVE-2026-20128 KEVEPSS 7%

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain D…

Fix: 20.9.8.2 / 20.12.5.3+
Fix from $1,950 2026-02-25