Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server CRITICAL 9.1
CVE-2026-9006

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an a…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-22
I CRITICAL 9.8
CVE-2026-9072

IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-i…

Fix: after 7.6
Fix from $2,300 2026-06-22
Websphere Application Server CRITICAL 9.1
CVE-2026-8646

IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-22
Langflow CRITICAL 9.8
CVE-2026-7664

IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t…

Fix: after 1.8.4
Fix from $2,300 2026-06-22
Storage Protect CRITICAL 9.1
CVE-2026-12628

IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker…

Fix: 8.2.1.1+
Fix from $2,300 2026-06-22
Unclassified CRITICAL 9.2
CVE-2026-7166

Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘em…

Mitigation only
Fix from $2,300 2026-06-22
Unclassified CRITICAL 9.4
CVE-2026-7165

The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of othe…

Mitigation only
Fix from $2,300 2026-06-22
Libxml2 CRITICAL 9.8
CVE-2026-6653

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service …

Fix: after 2.11.0
Fix from $2,300 2026-06-22
Langflow CRITICAL 10.0
CVE-2026-10561

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass tha…

Fix: after 1.9.3
Fix from $2,300 2026-06-22
Unclassified CRITICAL 9.4
CVE-2026-56422

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreig…

Patch available
Fix from $2,300 2026-06-22
Unclassified CRITICAL 9.1
CVE-2026-11373

Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is…

Patch available
Fix from $2,300 2026-06-22
Unclassified CRITICAL 9.4
CVE-2026-11746

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication…

Mitigation only
Fix from $2,300 2026-06-22
Unclassified CRITICAL 9.6
CVE-2026-56397

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ar…

Mitigation only
Fix from $2,300 2026-06-21
Unclassified CRITICAL 9.6
CVE-2026-56395

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ar…

Mitigation only
Fix from $2,300 2026-06-21
Imagemagick CRITICAL 9.1
CVE-2026-56367

ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coder…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $2,300 2026-06-21
Crawl4ai CRITICAL 9.8
CVE-2026-56265

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers …

Fix: 0.8.7+
Fix from $2,300 2026-06-21
Litellm CRITICAL 9.8
CVE-2026-12773

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_s…

Fix: 1.59.9+
Fix from $2,300 2026-06-21
Prefect CRITICAL 9.9
CVE-2026-5366

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class.…

Mitigation only
Fix from $2,300 2026-06-20
Unclassified CRITICAL 9.8
CVE-2024-58351

Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the fro…

Mitigation only
Fix from $2,300 2026-06-20
Unclassified CRITICAL 9.8
CVE-2022-50972

WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands thro…

Mitigation only
Fix from $2,300 2026-06-20
Unclassified CRITICAL 9.8
CVE-2019-25763

WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized acces…

Mitigation only
Fix from $2,300 2026-06-20
Unclassified CRITICAL 9.5
CVE-2026-48909

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to …

Mitigation only
Fix from $2,300 2026-06-20
Icagenda CRITICAL 9.8
CVE-2026-48939 KEVEPSS 20%

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP…

Fix: 3.9.15 / 4.0.8+
Fix from $2,300 2026-06-20
Sp Page Builder CRITICAL 9.8
CVE-2026-48908 KEVEPSS 15%

A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and executio…

Fix: 6.6.2+
Fix from $2,300 2026-06-20
Unclassified CRITICAL 9.1
CVE-2026-9265

Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRI…

Patch available
Fix from $2,300 2026-06-20
Unclassified CRITICAL 9.8
CVE-2026-11551

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due …

Mitigation only
Fix from $2,300 2026-06-20
Unclassified CRITICAL 9.1
CVE-2026-56081

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address …

Mitigation only
Fix from $2,300 2026-06-19
Unclassified CRITICAL 9.4
CVE-2026-56073

Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modi…

Mitigation only
Fix from $2,300 2026-06-19
Exchange Online CRITICAL 9.6
CVE-2026-48582

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-06-19
Azure Active Directory CRITICAL 10.0
CVE-2026-45480

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-06-19