Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Connect M6e 5g Firmware CRITICAL 9.1
CVE-2026-50225

The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-50214

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost networ…

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-50211

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to int…

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.4
CVE-2026-50208

High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Mi…

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49191

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49188

The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execu…

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49186

The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +…

Mitigation only
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware CRITICAL 9.8
CVE-2026-49185

The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.

Mitigation only
Fix from $2,300 2026-06-04
Unclassified CRITICAL 9.9
CVE-2026-41283

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which…

Mitigation only
Fix from $2,300 2026-06-04
Linux Kernel CRITICAL 9.1
CVE-2026-46266

In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reporte…

Fix: 6.6.128 / 6.12.75+
Fix from $2,300 2026-06-03
Linux Kernel CRITICAL 9.1
CVE-2026-46244

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), wh…

Fix: 6.6.142 / 6.12.92+
Fix from $2,300 2026-06-03
Unclassified CRITICAL 9.0
CVE-2026-36748

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

Mitigation only
Fix from $2,300 2026-06-03
Unclassified CRITICAL 9.8
CVE-2026-36576

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arb…

Mitigation only
Fix from $2,300 2026-06-03
Transformers CRITICAL 9.6
CVE-2026-5241

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execu…

Patch available
Fix from $2,300 2026-06-03
Universal Gateway Firmware CRITICAL 9.8
CVE-2026-35075

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

Fix: 6_00_07+
Fix from $2,300 2026-06-03
Mina CRITICAL 9.8
CVE-2026-47065

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the seri…

Mitigation only
Fix from $2,300 2026-06-03
T Mac Plus CRITICAL 9.9
CVE-2025-14771

Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Mitigation only
Fix from $2,300 2026-06-03
Alf CRITICAL 9.1
CVE-2026-35482

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox esca…

Fix: 2.0-M5-2606+
Fix from $2,300 2026-06-02
Librechat CRITICAL 9.6
CVE-2026-32625

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) s…

Fix: 0.8.4+
Fix from $2,300 2026-06-02
Authentik CRITICAL 9.8
CVE-2026-49448

authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an em…

Fix: 2025.12.6 / 2026.2.4+
Fix from $2,300 2026-06-02
Authentik CRITICAL 9.3
CVE-2026-42849

authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow …

Fix: 2025.12.5 / 2026.2.3+
Fix from $2,300 2026-06-02
Unclassified CRITICAL 9.8
CVE-2026-5076

The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plug…

Mitigation only
Fix from $2,300 2026-06-02
Unclassified CRITICAL 9.8
CVE-2026-38967

CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.

Patch available
Fix from $2,300 2026-06-02
Openclaude CRITICAL 9.8
CVE-2026-42074

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableS…

Fix: 0.5.1+
Fix from $2,300 2026-06-02
Unclassified CRITICAL 9.8
CVE-2026-0611

Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability thro…

Mitigation only
Fix from $2,300 2026-06-02
Unclassified CRITICAL 9.8
CVE-2026-47117

OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used …

Patch available
Fix from $2,300 2026-06-02
Sitefinity CRITICAL 9.8
CVE-2026-7198

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access…

Fix: 15.4.8630+
Fix from $2,300 2026-06-02
Misp CRITICAL 10.0
CVE-2026-10611

An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with …

Fix: 2.5.39+
Fix from $2,300 2026-06-02
Unclassified CRITICAL 9.3
CVE-2026-42684

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection.…

Mitigation only
Fix from $2,300 2026-06-02
Unclassified CRITICAL 9.3
CVE-2026-34906

Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoin…

Mitigation only
Fix from $2,300 2026-06-02