Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-44672

mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3…

Mitigation only
Fix from $2,300 2026-05-28
Unclassified CRITICAL 9.3
CVE-2026-8980

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the pa…

Mitigation only
Fix from $2,300 2026-05-28
Unclassified CRITICAL 9.3
CVE-2026-8979

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the …

Mitigation only
Fix from $2,300 2026-05-28
Flowintel CRITICAL 9.9
CVE-2026-9813

FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/ca…

Fix: 3.3.0+
Fix from $2,300 2026-05-28
Linux Kernel CRITICAL 9.8
CVE-2026-46195

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DACL pointers parse_sec_desc()…

Fix: 6.6.140 / 6.12.88+
Fix from $2,300 2026-05-28
Linux Kernel CRITICAL 9.1
CVE-2026-46185

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data() Since smb2_check_message()…

Fix: 6.1.175 / 6.6.140+
Fix from $2,300 2026-05-28
Linux Kernel CRITICAL 9.1
CVE-2026-46155

In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound_op() If a server sends a tr…

Fix: 6.6.140 / 6.12.88+
Fix from $2,300 2026-05-28
Linux Kernel CRITICAL 9.8
CVE-2026-46137

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This mptcp_pm_add_timer() help…

Fix: 5.10.259 / 5.15.210+
Fix from $2,300 2026-05-28
Linux Kernel CRITICAL 9.8
CVE-2026-46135

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_…

Fix: 6.12.88 / 6.18.30+
Fix from $2,300 2026-05-28
Linux Kernel CRITICAL 9.1
CVE-2026-46119

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth message processing If a (potenti…

Fix: 5.15.209 / 6.1.175+
Fix from $2,300 2026-05-28
Linux Kernel CRITICAL 9.8
CVE-2026-46115

In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biovec_phys_mergeable biovec_phys_mergeable() is used…

Fix: 6.6.140 / 6.12.88+
Fix from $2,300 2026-05-28
Openshift Container Platform CRITICAL 9.8
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check …

Fix: 4.21.0+
Fix from $2,300 2026-05-28
Unclassified CRITICAL 9.0
CVE-2026-32999

Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitr…

Mitigation only
Fix from $2,300 2026-05-28
Unclassified CRITICAL 9.4
CVE-2026-32998

This vulnerability in Veeam Service Provider Console allows for remote code execution.

No fix yet
Fix from $2,300 2026-05-28
Unclassified CRITICAL 9.4
CVE-2026-9739

Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` …

Patch available
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-45083

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer…

Patch available
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-8364

Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL …

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-8363

A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-8362

A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.9
CVE-2026-45102

OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm module as an isolation primitive.…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-44888

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplie…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-44887

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitra…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-44590

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.0
CVE-2026-48150

Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAdmin middleware, which passes …

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.9
CVE-2026-46425

Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCI…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 10.0
CVE-2026-45087EPSS 13%

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalf…

Mitigation only
Fix from $2,300 2026-05-27
Nx Console CRITICAL 9.8
CVE-2026-48027 KEV

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and remove…

Mitigation only
Fix from $2,300 2026-05-27
Free5gc CRITICAL 10.0
CVE-2026-44330

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanagement route group without inbo…

Fix: 4.2.2+
Fix from $2,300 2026-05-27
Free5gc CRITICAL 10.0
CVE-2026-44329

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/b…

Fix: 4.2.2+
Fix from $2,300 2026-05-27
Free5gc CRITICAL 10.0
CVE-2026-44327

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2…

Fix: 4.2.2+
Fix from $2,300 2026-05-27