Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.6
CVE-2026-10974

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbo…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-10972

Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a craf…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-10971

Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromis…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-10966

Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via …

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-10931

Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-10892

Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-10886

Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Chrome CRITICAL 9.6
CVE-2026-10881

Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 149.0.7827.53+
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.6
CVE-2024-27892

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in…

No fix yet
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.6
CVE-2024-27890

Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in…

No fix yet
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2025-71316

SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker cou…

Mitigation only
Fix from $2,300 2026-06-04
Libinput CRITICAL 9.8
CVE-2026-50292

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root …

Fix: 1.30.4 / 1.31.3+
Fix from $2,300 2026-06-04
Netty Incubator Codec Ohttp CRITICAL 9.1
CVE-2026-48040

The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C libr…

Fix: 0.0.22+
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2026-25550

Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed o…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2026-10880

OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorp…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2025-67447

The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does n…

Mitigation only
Fix from $2,300 2026-06-04
Fory CRITICAL 9.1
CVE-2026-50076

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remo…

Fix: 1.1.0+
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2025-67446

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.9
CVE-2026-43986

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that re…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2026-36182

GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credenti…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.0
CVE-2026-10868

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::…

Patch available
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.6
CVE-2026-35906

An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary …

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2026-35905

T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2026-35904

Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauth…

Mitigation only
Fix from $2,300 2026-06-04
Connection Manager For Objectscale CRITICAL 9.8
CVE-2026-8037 KEVEPSS 100%

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary com…

Fix: 7.2.54.18 / 7.2.63.2+
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2019-25741

Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2019-25738

WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress o…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2019-25729

PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting P…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2019-25727

WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive f…

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.8
CVE-2026-4104

Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allo…

Mitigation only
Fix from $2,300 2026-06-04