Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1607 CRITICAL 9.8
CVE-2026-47291EPSS 23%

Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $2,300 2026-06-09
Windows 11 23h2 CRITICAL 9.8
CVE-2026-45657EPSS 15%

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

Fix: 10.0.20348.5256 / 10.0.22631.7219+
Fix from $2,300 2026-06-09
Visual Studio Code CRITICAL 9.6
CVE-2026-47281

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Fix: 1.123.1+
Fix from $2,300 2026-06-09
Windows 10 1607 CRITICAL 9.1
CVE-2026-45602

No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $2,300 2026-06-09
Windows 10 1607 CRITICAL 9.8
CVE-2026-44815

Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $2,300 2026-06-09
Windows 10 21h2 CRITICAL 9.6
CVE-2026-42904

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.

Fix: 10.0.19044.7417 / 10.0.19045.7417+
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.8
CVE-2026-38615

DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.

Mitigation only
Fix from $2,300 2026-06-09
OpenSSL CRITICAL 9.1
CVE-2026-34182

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of Au…

Fix: 3.0.21 / 3.4.6+
Fix from $2,300 2026-06-09
Nuance Powerscribe 360 CRITICAL 9.8
CVE-2026-26142

Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.8
CVE-2026-8025

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform…

Mitigation only
Fix from $2,300 2026-06-09
Fortisandbox CRITICAL 9.8
CVE-2026-25089 KEVEPSS 76%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0…

Fix: 4.4.9 / 5.0.6+
Fix from $2,300 2026-06-09
Standalone Sentry CRITICAL 9.8
CVE-2026-10523EPSS 52%

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated at…

Fix: 10.5.2 / 10.6.2+
Fix from $2,300 2026-06-09
Standalone Sentry CRITICAL 10.0
CVE-2026-10520 KEVEPSS 100%

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie…

Fix: 10.5.2 / 10.6.2+
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.8
CVE-2026-7486

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injectio…

Mitigation only
Fix from $2,300 2026-06-09
Linux Kernel CRITICAL 9.8
CVE-2026-46325

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current …

Fix: 6.18.14 / 6.19.4+
Fix from $2,300 2026-06-09
Linux Kernel CRITICAL 9.3
CVE-2026-46316

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased e…

Fix: 6.12.93 / 6.18.35+
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.8
CVE-2017-20251

WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitra…

Mitigation only
Fix from $2,300 2026-06-09
Sinec Ins CRITICAL 9.8
CVE-2026-46749

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation …

Fix: after 1.0
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.3
CVE-2026-10731

SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-…

Mitigation only
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.1
CVE-2025-10263

Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Corte…

Mitigation only
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.1
CVE-2009-10007

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does…

Patch available
Fix from $2,300 2026-06-09
Dbi CRITICAL 9.8
CVE-2026-9698

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleEr…

Fix: 1.648+
Fix from $2,300 2026-06-09
Qumagie CRITICAL 9.8
CVE-2026-44083

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vuln…

Fix: 2.9.0+
Fix from $2,300 2026-06-09
Zephyr CRITICAL 9.8
CVE-2026-5067

A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Ke…

Fix: after 4.3.0
Fix from $2,300 2026-06-09
Spring Framework CRITICAL 9.8
CVE-2026-41855

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.conver…

Fix: 5.3.49 / 6.1.28+
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.9
CVE-2026-44748

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and …

Mitigation only
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.0
CVE-2026-40128

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates fil…

Mitigation only
Fix from $2,300 2026-06-09
Unclassified CRITICAL 9.8
CVE-2026-27671

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated …

Mitigation only
Fix from $2,300 2026-06-09
Chrome CRITICAL 9.6
CVE-2026-11697

Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox …

Fix: 149.0.7827.103+
Fix from $2,300 2026-06-09
Chrome CRITICAL 9.6
CVE-2026-11671

Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted…

Fix: 149.0.7827.103+
Fix from $2,300 2026-06-09