Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-53209

Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from …

Mitigation only
Fix from $2,300 2026-06-02
Unclassified CRITICAL 9.8
CVE-2026-8206

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in al…

Mitigation only
Fix from $2,300 2026-06-02
Unclassified CRITICAL 9.8
CVE-2026-25879

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM…

Mitigation only
Fix from $2,300 2026-06-01
Unclassified CRITICAL 10.0
CVE-2026-40965

Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic…

Mitigation only
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.8
CVE-2018-25427

Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized inp…

Mitigation only
Fix from $2,300 2026-06-01
Websphere Application Server CRITICAL 9.0
CVE-2026-9319

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS en…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Websphere Application Server CRITICAL 9.0
CVE-2026-9311

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Websphere Application Server CRITICAL 9.1
CVE-2026-8644

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-06-01
Aiter CRITICAL 9.8
CVE-2026-49121

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function …

Fix: after 0.1.14
Fix from $2,300 2026-06-01
Capsule CRITICAL 9.1
CVE-2026-22872

Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantR…

Fix: 0.13.0+
Fix from $2,300 2026-06-01
Unclassified CRITICAL 10.0
CVE-2026-45132

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) expose…

Patch available
Fix from $2,300 2026-06-01
Unclassified CRITICAL 10.0
CVE-2026-45131

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes …

Patch available
Fix from $2,300 2026-06-01
Cline CRITICAL 9.6
CVE-2026-44211

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijac…

Fix: after 2.13.0
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.3
CVE-2026-42672

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind …

Mitigation only
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.4
CVE-2026-8931

A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.

Mitigation only
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.8
CVE-2026-48879

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

No fix yet
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.6
CVE-2026-48866

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal…

Mitigation only
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.1
CVE-2026-42682

Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue aff…

Mitigation only
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.8
CVE-2026-42680

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This is…

Mitigation only
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.2
CVE-2026-0826EPSS 32%

In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote co…

Mitigation only
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.8
CVE-2026-7858

A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Colla…

Mitigation only
Fix from $2,300 2026-06-01
Solr CRITICAL 9.8
CVE-2026-44825

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a …

Fix: after 9.10.1
Fix from $2,300 2026-06-01
Airflow CRITICAL 9.1
CVE-2026-42252

Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(b…

Fix: 3.2.2+
Fix from $2,300 2026-06-01
Otrs CRITICAL 9.1
CVE-2026-48188

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which …

Fix: 2026.4.1+
Fix from $2,300 2026-06-01
Unclassified CRITICAL 9.8
CVE-2026-10187EPSS 7%

A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.s…

Mitigation only
Fix from $2,300 2026-05-31
Deltasql CRITICAL 9.8
CVE-2018-25412

Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST reque…

Mitigation only
Fix from $2,300 2026-05-30
Unclassified CRITICAL 9.8
CVE-2026-45697

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (wi…

Patch available
Fix from $2,300 2026-05-29
Freerdp CRITICAL 9.8
CVE-2026-45700

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write whe…

Fix: 3.26.0+
Fix from $2,300 2026-05-29
Cpp Httplib CRITICAL 9.9
CVE-2026-45372

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming reque…

Fix: 0.44.0+
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.1
CVE-2026-9051

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attack…

Mitigation only
Fix from $2,300 2026-05-29