Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-50886

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted …

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.6
CVE-2026-50883

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a craft…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-50880

An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted req…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-50873

An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via upload…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-50872

An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensit…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-50871

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to …

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-50869

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.1
CVE-2026-49952

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain …

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-48114

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticate…

Patch available
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.1
CVE-2026-45390

In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired be…

No fix yet
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.1
CVE-2026-45388

In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation w…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-39196

Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition f…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-39006

An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38812

RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an aut…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38329

Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.p…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38065

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38064

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38063

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38062

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38061

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-38060

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-36537

ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-s…

Mitigation only
Fix from $2,300 2026-06-15
Remotion CRITICAL 9.1
CVE-2026-30121

remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.

Mitigation only
Fix from $2,300 2026-06-15
Remotion CRITICAL 9.8
CVE-2026-30120

remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.

Mitigation only
Fix from $2,300 2026-06-15
Core Privileged Access Manager Server CRITICAL 9.8
CVE-2026-9862

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker w…

Fix: 8.1.0.23 / 9.0.0.5+
Fix from $2,300 2026-06-15
Unclassified CRITICAL 10.0
CVE-2026-52704

Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. …

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2018-25436

WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to…

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.3
CVE-2026-5482

Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, …

Mitigation only
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.2
CVE-2026-49757

Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. As…

Patch available
Fix from $2,300 2026-06-15
Unclassified CRITICAL 9.8
CVE-2026-8935

The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any fro…

Mitigation only
Fix from $2,300 2026-06-15