Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Proxysql CRITICAL 9.8
CVE-2026-48773

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vu…

Fix: 3.0.9+
Fix from $2,300 2026-06-19
Proxysql CRITICAL 10.0
CVE-2026-48772

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY U…

Fix: 3.0.9+
Fix from $2,300 2026-06-19
Ac7 Firmware CRITICAL 9.8
CVE-2026-51846

In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to rem…

Mitigation only
Fix from $2,300 2026-06-19
Ac7 Firmware CRITICAL 9.8
CVE-2026-51845

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.

Mitigation only
Fix from $2,300 2026-06-19
Ac7 Firmware CRITICAL 9.8
CVE-2026-51844

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.

Mitigation only
Fix from $2,300 2026-06-19
Ac7 Firmware CRITICAL 9.8
CVE-2026-51843

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.

Mitigation only
Fix from $2,300 2026-06-19
Instrumentstudio CRITICAL 9.1
CVE-2026-9142

There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopbac…

Fix: 2.18.0+
Fix from $2,300 2026-06-19
Apisix CRITICAL 9.3
CVE-2026-49871

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manag…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Apisix CRITICAL 9.1
CVE-2026-49230

Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to aut…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Instrumentstudio CRITICAL 9.8
CVE-2026-48137

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary…

Fix: 2.18.0+
Fix from $2,300 2026-06-19
Apisix CRITICAL 9.1
CVE-2026-44087

Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack s…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Apisix CRITICAL 9.1
CVE-2026-39999

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configur…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Heif Image Extension CRITICAL 9.1
CVE-2025-62821

Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the report…

No fix yet
Fix from $2,300 2026-06-19
Hub CRITICAL 9.8
CVE-2026-56141

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable rest…

Fix: 2024.2.148429 / 2024.3.148430+
Fix from $2,300 2026-06-19
Hub CRITICAL 9.8
CVE-2026-50242

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct data…

Fix: 2024.2.148429 / 2024.3.148430+
Fix from $2,300 2026-06-19
Unclassified CRITICAL 9.4
CVE-2026-44939

A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitiz…

Mitigation only
Fix from $2,300 2026-06-19
Unclassified CRITICAL 9.1
CVE-2026-8713

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete…

Mitigation only
Fix from $2,300 2026-06-19
Unclassified CRITICAL 9.8
CVE-2026-7515

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. …

Mitigation only
Fix from $2,300 2026-06-19
Unclassified CRITICAL 9.8
CVE-2026-54414

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitr…

No fix yet
Fix from $2,300 2026-06-19
Unclassified CRITICAL 9.8
CVE-2026-40624

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary c…

Mitigation only
Fix from $2,300 2026-06-19
Pgadmin 4 CRITICAL 9.0
CVE-2026-12046

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/updat…

Fix: 9.16+
Fix from $2,300 2026-06-19
Dynamics 365 CRITICAL 9.9
CVE-2026-47647

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.1
CVE-2026-49454

Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures becaus…

Patch available
Fix from $2,300 2026-06-18
Unclassified CRITICAL 10.0
CVE-2026-49257

mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to…

Patch available
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.9
CVE-2026-49252

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vul…

Patch available
Fix from $2,300 2026-06-18
Coturn CRITICAL 9.8
CVE-2026-43994

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_g…

Fix: 4.10.0+
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-47846

Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via …

Mitigation only
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-54390

JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicio…

Mitigation only
Fix from $2,300 2026-06-18
Haproxy CRITICAL 9.1
CVE-2026-55203

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer …

Fix: after 3.4.0
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-54103

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic D…

Mitigation only
Fix from $2,300 2026-06-18