Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Linux Kernel CRITICAL 9.8
CVE-2026-52989

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currentl…

Fix: 5.11 / 5.16+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-52986

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strtoul Replace unsafe port parsi…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-52982

In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.1
CVE-2026-52958

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding os…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-52955

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.8
CVE-2026-56121

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code exe…

Patch available
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-56111

Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in…

Patch available
Fix from $2,300 2026-06-24
N8n CRITICAL 9.6
CVE-2026-56351

n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inje…

Fix: 2.4.0+
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-56237

Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, …

Mitigation only
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-52931

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender vars batadv_tp_recv_ack() and …

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-52924

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only…

Fix: 5.10.259 / 5.15.210+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-52914

In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a runnin…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.8
CVE-2026-12417

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in ver…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.8
CVE-2026-12416

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is …

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12851

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12850

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12849

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 10.0
CVE-2026-12848

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 10.0
CVE-2026-12847

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 10.0
CVE-2026-12846

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-12486

Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 10.0
CVE-2026-12485

GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.6
CVE-2026-54588

Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` requ…

Mitigation only
Fix from $2,300 2026-06-23
Unclassified CRITICAL 9.6
CVE-2026-11807

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not v…

Mitigation only
Fix from $2,300 2026-06-23
Traefik CRITICAL 10.0
CVE-2026-53622

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration se…

Fix: 3.7.3+
Fix from $2,300 2026-06-23
Traefik CRITICAL 10.0
CVE-2026-48491

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting prote…

Fix: 3.7.3+
Fix from $2,300 2026-06-23
Traefik CRITICAL 10.0
CVE-2026-48020

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPre…

Fix: 2.11.48 / 3.6.19+
Fix from $2,300 2026-06-23
Crawl4ai CRITICAL 10.0
CVE-2026-53753

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature us…

Fix: 0.8.7+
Fix from $2,300 2026-06-23
Claude Code CRITICAL 9.1
CVE-2026-54316

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the We…

Fix: 2.1.163+
Fix from $2,300 2026-06-23
Unclassified CRITICAL 9.3
CVE-2026-54257

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs inc…

Mitigation only
Fix from $2,300 2026-06-23