Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-0257 KEVEPSS 94% Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass se… Pan Os 10.2.7+ Fix from $2,3002026-05-13 CRITICAL 9.6 CVE-2026-45321 KEV On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. Th… Mistralai Mitigation only Fix from $2,3002026-05-12 HIGH 8.8 CVE-2026-42271 KEVEPSS 83% LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use… Openshift Ai 1.83.7 / 2.25.8+ Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-42208 KEVEPSS 89% LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query… Litellm 1.83.7+ Fix from $2,3002026-05-08 HIGH 7.2 CVE-2026-6973 KEVEPSS 34% An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative… Endpoint Manager Mobile 12.6.1.1+ Fix from $1,9502026-05-07 CRITICAL 9.8 CVE-2026-0300 KEVEPSS 32% A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an un… Pan Os Mitigation only Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-41940 KEVEPSS 98% cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to … Wp Squared 86.0.41 / 110.0.97+ Fix from $2,3002026-04-29 HIGH 7.8 CVE-2026-31431 KEVEPSS 100% In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commi… Linux Kernel 4.12.89 / 4.13.66+ Fix from $1,9502026-04-22 HIGH 7.8 CVE-2026-33825 KEVEPSS 7% Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. Defender Antimalware Platform 4.18.26030.3011+ Fix from $1,9502026-04-14 CRITICAL 9.8 CVE-2026-33824 KEVEPSS 56% Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $2,3002026-04-14 MEDIUM 6.5 CVE-2026-32201 KEVEPSS 23% Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Sharepoint Server 16.0.19725.20210+ Fix from $1,6002026-04-14 CRITICAL 9.8 CVE-2026-39808 KEVEPSS 91% A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4… Fortisandbox after 4.4.9 Fix from $2,3002026-04-14 HIGH 8.6 CVE-2026-34621 KEVEPSS 7% Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes (… Acrobat Dc 24.001.30360 / 24.001.30362+ Fix from $1,9502026-04-11 HIGH 7.5 CVE-2026-34486 KEVEPSS 83% Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. … Tomcat Mitigation only Fix from $1,9502026-04-09 CRITICAL 9.8 CVE-2026-39987 KEVEPSS 97% marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks au… Marimo 0.23.0+ Fix from $2,3002026-04-09 HIGH 8.8 CVE-2026-34197 KEVEPSS 97% Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apach… Activemq 5.19.4 / 6.2.3+ Fix from $1,9502026-04-07 CRITICAL 9.8 CVE-2026-35616 KEVEPSS 91% A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized … Forticlientems Patch available Fix from $2,3002026-04-04 HIGH 8.8 CVE-2026-5281 KEV Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitra… Chrome 146.0.7680.177+ Fix from $1,9502026-04-01 HIGH 7.8 CVE-2026-3502 KEVEPSS 6% TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update del… Trueconf 8.5.3.884+ Fix from $1,9502026-03-30 HIGH 8.8 CVE-2026-33634 KEVEPSS 59% Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push … Trivy 0.2.6 / 0.35.0+ Fix from $1,9502026-03-23 CRITICAL 9.8 CVE-2026-3055 KEVEPSS 84% Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread Netscaler Application Delivery Controller 13.1-37.262 / 13.1-62.23+ Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-33017 KEVEPSS 96% Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id… Langflow 1.8.2+ Fix from $2,3002026-03-20 HIGH 8.8 CVE-2026-3910 KEV Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a… Chrome 146.0.7680.75+ Fix from $1,9502026-03-13 HIGH 8.8 CVE-2026-3909 KEV Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HT… Chrome 146.0.7680.80+ Fix from $1,9502026-03-13 CRITICAL 9.8 CVE-2025-67038 KEVEPSS 14% An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. … Eds5032 Firmware Mitigation only Fix from $2,3002026-03-11 CRITICAL 10.0 CVE-2026-20131 KEVEPSS 31% A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot… Secure Firewall Management Center Mitigation only Fix from $2,3002026-03-04 HIGH 7.8 CVE-2026-21385 KEV Memory corruption while using alignments for memory allocation. Sm7675p Firmware Patch available Fix from $1,9502026-03-02 HIGH 8.1 CVE-2026-22719 KEVEPSS 17% VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary comm… Aria Operations 5.2.3 / 8.18.6+ Fix from $1,9502026-02-25 HIGH 7.5 CVE-2026-20133 KEVEPSS 31% A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system… Catalyst Sd Wan Manager 20.9.8.2 / 20.12.5.3+ Fix from $1,9502026-02-25 HIGH 7.5 CVE-2026-20128 KEVEPSS 7% A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain D… Catalyst Sd Wan Manager 20.9.8.2 / 20.12.5.3+ Fix from $1,9502026-02-25