Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cxf CRITICAL 9.1
CVE-2026-50627

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Cxf CRITICAL 9.8
CVE-2026-49875

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.4
CVE-2026-11535

An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’…

No fix yet
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-48611

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthoriz…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.9
CVE-2026-47370

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices run…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.9
CVE-2026-47369

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices run…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.9
CVE-2026-47367

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agen…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.9
CVE-2026-47365

Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant…

Mitigation only
Fix from $2,300 2026-06-12
Unclassified CRITICAL 9.8
CVE-2026-45060

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.8
CVE-2026-42846

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.8
CVE-2026-49060

Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App …

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.3
CVE-2026-42647

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. …

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.3
CVE-2026-39494

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind …

Mitigation only
Fix from $2,300 2026-06-11
Chrome CRITICAL 9.6
CVE-2026-12027

Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process …

Fix: 149.0.7827.115+
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.0
CVE-2026-41005

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity P…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.4
CVE-2026-49973

Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial…

Patch available
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.5
CVE-2026-47174

In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The build workflow runs on pull…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.5
CVE-2026-47172

Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the repository has a privileged de…

Mitigation only
Fix from $2,300 2026-06-11
Idira Secrets Manager Edge CRITICAL 9.1
CVE-2026-45177

Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauth…

Fix: 1.8+
Fix from $2,300 2026-06-11
MariaDB CRITICAL 9.8
CVE-2026-49261

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8…

Fix: 10.6.27 / 10.11.18+
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.1
CVE-2026-9648

The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alterna…

Patch available
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.9
CVE-2026-11839

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web S…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.8
CVE-2026-38581

SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFor…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.8
CVE-2026-7852

Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects Lim…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.8
CVE-2026-11561

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Inform…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.4
CVE-2026-4764

A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user wit…

Mitigation only
Fix from $2,300 2026-06-11
Spring For Graphql CRITICAL 9.8
CVE-2026-41699

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious…

Fix: 1.3.9 / 1.4.5.1+
Fix from $2,300 2026-06-11
Peoplesoft Enterprise Peopletools CRITICAL 9.8
CVE-2026-35273 KEVEPSS 95%

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions t…

Mitigation only
Fix from $2,300 2026-06-11
Unclassified CRITICAL 9.6
CVE-2026-46703

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted …

Mitigation only
Fix from $2,300 2026-06-10
Unclassified CRITICAL 10.0
CVE-2026-46695

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted …

Patch available
Fix from $2,300 2026-06-10