Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ir915l Fq39 S Firmware CRITICAL 9.8
CVE-2026-38717

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability…

Fix: 1.0.0.r20044+
Fix from $2,300 2026-06-18
Ir915l Fq39 S Firmware CRITICAL 9.8
CVE-2026-38716

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability…

Fix: 1.0.0.r20044+
Fix from $2,300 2026-06-18
Ir915l Fq39 S Firmware CRITICAL 9.8
CVE-2026-38715

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability…

Fix: 1.0.0.r20044+
Fix from $2,300 2026-06-18
Ir915l Fq39 S Firmware CRITICAL 9.8
CVE-2026-38714

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability…

Fix: 1.0.0.r20044+
Fix from $2,300 2026-06-18
4diac Forte CRITICAL 9.8
CVE-2026-9158

In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling poin…

Fix: after 3.1.0
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-8024

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access t…

Mitigation only
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-54419

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) conta…

Mitigation only
Fix from $2,300 2026-06-18
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11718

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the …

Fix: after 1.3.0
Fix from $2,300 2026-06-18
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11717

An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When veri…

Fix: after 1.3.0
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.3
CVE-2025-10560

Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. …

Mitigation only
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.6
CVE-2026-55742

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admi…

Mitigation only
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.8
CVE-2026-55740

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulner…

Mitigation only
Fix from $2,300 2026-06-18
Flexplm CRITICAL 9.8
CVE-2026-12569 KEVEPSS 41%

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t…

Fix: 11.0m030+
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.3
CVE-2026-48768

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses uns…

Mitigation only
Fix from $2,300 2026-06-18
Unclassified CRITICAL 9.1
CVE-2026-54388

Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forward…

Patch available
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.1
CVE-2026-54387

Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding b…

Patch available
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.1
CVE-2026-48814

Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MC…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.1
CVE-2026-55196

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote att…

Patch available
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-53805

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /…

Patch available
Fix from $2,300 2026-06-17
Connext Professional CRITICAL 9.1
CVE-2026-3894

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7…

Fix: 7.7.0+
Fix from $2,300 2026-06-17
Connext Micro CRITICAL 9.1
CVE-2026-30803

Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: …

Fix: 4.3.0+
Fix from $2,300 2026-06-17
Ai Toolkit CRITICAL 9.1
CVE-2026-20266

In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splun…

Fix: 5.7.4+
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-53874

picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval call…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-53873

picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 10.0
CVE-2026-3490

picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function th…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.1
CVE-2026-36418

JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSel…

Mitigation only
Fix from $2,300 2026-06-17
Identity Services Engine CRITICAL 9.1
CVE-2026-20181EPSS 9%

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating syst…

Fix: 3.3.0+
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2025-71325

picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments …

Patch available
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2025-71323

picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and access…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2025-71321

picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.…

Mitigation only
Fix from $2,300 2026-06-17