Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-47744

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.1
CVE-2026-44650

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-44649

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-7786

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials …

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.1
CVE-2026-5386

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset th…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.3
CVE-2026-45668

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malic…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45661

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45633

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /dock…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45632

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. …

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 10.0
CVE-2026-45631

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-se…

Patch available
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.0
CVE-2026-45630

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTra…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45629

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment We…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.6
CVE-2026-45628

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template lit…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45625

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endp…

Mitigation only
Fix from $2,300 2026-05-29
Cli CRITICAL 9.1
CVE-2026-48501

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF …

Fix: 2.93.0+
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45663

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upl…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-44962

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into X…

Mitigation only
Fix from $2,300 2026-05-29
Tew 432brp Firmware CRITICAL 9.8
CVE-2026-10064

A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Perfor…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.1
CVE-2026-4290

The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoin…

Mitigation only
Fix from $2,300 2026-05-29
Tew 432brp Firmware CRITICAL 9.8
CVE-2026-10063

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manip…

Mitigation only
Fix from $2,300 2026-05-29
Tew 432brp Firmware CRITICAL 9.8
CVE-2026-10062

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSe…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-10042

manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle…

Patch available
Fix from $2,300 2026-05-29
Freepbx CRITICAL 9.8
CVE-2026-46376

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP)…

Fix: 16.0.45 / 17.0.7+
Fix from $2,300 2026-05-29
Tew 432brp Firmware CRITICAL 9.8
CVE-2026-10061EPSS 5%

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argum…

Mitigation only
Fix from $2,300 2026-05-29
Tew 432brp Firmware CRITICAL 9.8
CVE-2026-10060EPSS 5%

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulat…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 10.0
CVE-2026-9508

Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly expo…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 10.0
CVE-2026-8326

Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories a…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45312

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (ra…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.3
CVE-2026-45043

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoi…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.8
CVE-2026-10071

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web she…

Mitigation only
Fix from $2,300 2026-05-29