Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.4
CVE-2026-46399

HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file ove…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.3
CVE-2026-46396

HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.3
CVE-2026-46395

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backe…

Mitigation only
Fix from $2,300 2026-06-05
Uds Identity Config CRITICAL 9.8
CVE-2026-46389

UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In …

Fix: 0.26.1+
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.8
CVE-2026-10580

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all ve…

Mitigation only
Fix from $2,300 2026-06-05
Termix CRITICAL 9.0
CVE-2026-45750

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fi…

Fix: 2.3.2+
Fix from $2,300 2026-06-05
Termix CRITICAL 9.8
CVE-2026-45748

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint…

Fix: 2.3.2+
Fix from $2,300 2026-06-05
Termix CRITICAL 9.0
CVE-2026-45746

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manage…

Fix: 2.3.2+
Fix from $2,300 2026-06-05
Termix CRITICAL 9.9
CVE-2026-45744

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/fi…

Fix: 2.3.2+
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.1
CVE-2026-36500

An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted reques…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.8
CVE-2025-71318

NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.8
CVE-2025-71317

NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated…

Mitigation only
Fix from $2,300 2026-06-05
Datadog\ CRITICAL 9.1
CVE-2026-9270

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric inje…

Fix: after 0.07
Fix from $2,300 2026-06-05
Datadog\ CRITICAL 9.8
CVE-2026-11362

DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allo…

Fix: after 0.07
Fix from $2,300 2026-06-05
Dbi CRITICAL 9.8
CVE-2026-10879

DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL pla…

Fix: 1.648+
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.8
CVE-2026-6274

Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. C…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified CRITICAL 10.0
CVE-2026-49777

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Im…

Mitigation only
Fix from $2,300 2026-06-05
Jce CRITICAL 9.8
CVE-2026-48907 KEVEPSS 78%

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in …

Fix: 2.9.99.5+
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.8
CVE-2026-7763

A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 al…

Mitigation only
Fix from $2,300 2026-06-05
Unclassified CRITICAL 9.8
CVE-2026-7762

A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 …

Mitigation only
Fix from $2,300 2026-06-05
Chrome CRITICAL 9.6
CVE-2026-11293

Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-05
Chrome CRITICAL 9.6
CVE-2026-11282

Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbo…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-05
Chrome CRITICAL 9.6
CVE-2026-11250

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process t…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-05
Azure Horizondb CRITICAL 9.8
CVE-2026-48567

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-11213

Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the …

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-11207

Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a san…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-11198

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandb…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-11167

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-11165

Use after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a craf…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-11163

Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04