Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-11526

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Ima…

Patch available
Fix from $2,300 2026-06-14
Unclassified CRITICAL 9.8
CVE-2026-12183

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287)…

Mitigation only
Fix from $2,300 2026-06-13
Unclassified CRITICAL 9.4
CVE-2026-11624

The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebindi…

Patch available
Fix from $2,300 2026-06-13
Openclaw CRITICAL 9.8
CVE-2026-53838

OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope dec…

Fix: 2026.5.27+
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.1
CVE-2026-53609

ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation p…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.1
CVE-2026-53519

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13, fallbackToFrontend in the da…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.9
CVE-2026-46716

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMem…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-41157

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound write in the GPU user-space d…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.3
CVE-2026-44990

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the def…

Mitigation only
Fix from $2,300 2026-06-12
Workplace CRITICAL 9.8
CVE-2026-53407

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unau…

Fix: 7.0.3 / 7.0.4+
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-28742

Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is re…

Mitigation only
Fix from $2,300 2026-06-12
Simplehelp CRITICAL 10.0
CVE-2026-48558 KEVEPSS 12%

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. Whe…

Fix: 5.5.16+
Fix from $2,300 2026-06-12
MariaDB CRITICAL 9.1
CVE-2026-44172

MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, …

Mitigation only
Fix from $2,300 2026-06-12
MariaDB CRITICAL 9.8
CVE-2026-44170

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11…

Fix: 10.6.26 / 10.11.17+
Fix from $2,300 2026-06-12
Board Service CRITICAL 9.8
CVE-2026-50085

The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authent…

Mitigation only
Fix from $2,300 2026-06-12
Iam\/sso Gateway CRITICAL 9.8
CVE-2026-50086

The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing key without authentication. Thi…

Mitigation only
Fix from $2,300 2026-06-12
Iam\/sso Gateway CRITICAL 9.8
CVE-2026-50083

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Creden…

Mitigation only
Fix from $2,300 2026-06-12
Netty CRITICAL 10.0
CVE-2026-47691

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `…

Fix: 4.1.135 / 4.2.15+
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-6853

Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mob…

Mitigation only
Fix from $2,300 2026-06-12
Jmespath CRITICAL 9.8
CVE-2026-54133

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications wi…

Fix: 2.9.1+
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-53787EPSS 6%

Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticate…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-47210

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the h…

Patch available
Fix from $2,300 2026-06-12
Unclassified CRITICAL 10.0
CVE-2026-47208

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to wr…

Patch available
Fix from $2,300 2026-06-12
Unclassified CRITICAL 10.0
CVE-2026-47140

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_thread…

Patch available
Fix from $2,300 2026-06-12
Unclassified CRITICAL 10.0
CVE-2026-47137

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.…

Patch available
Fix from $2,300 2026-06-12
Unclassified CRITICAL 10.0
CVE-2026-47131

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffe…

Patch available
Fix from $2,300 2026-06-12
Netty CRITICAL 10.0
CVE-2026-45674

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's D…

Fix: 4.1.135 / 4.2.15+
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-10557

The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and all devices. These credentials…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-11849

The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers…

Mitigation only
Fix from $2,300 2026-06-12
Cxf CRITICAL 9.8
CVE-2026-50628

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12