Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Free5gc CRITICAL 9.4
CVE-2026-44326

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound …

Fix: 4.2.2+
Fix from $2,300 2026-05-27
Free5gc CRITICAL 9.4
CVE-2026-44315

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAu…

Fix: 4.2.2+
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.4
CVE-2026-49103

Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detacha…

Patch available
Fix from $2,300 2026-05-27
Go Git CRITICAL 9.6
CVE-2026-45570

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remot…

Fix: 5.19.1+
Fix from $2,300 2026-05-27
Aspera High Speed Transfer Endpoint CRITICAL 9.8
CVE-2026-8175

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…

Fix: after 4.4.6
Fix from $2,300 2026-05-27
Aspera High Speed Transfer Server For Cloud Pak For Integration CRITICAL 9.1
CVE-2026-7876

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage …

Fix: 1.5.20+
Fix from $2,300 2026-05-27
Langflow CRITICAL 9.8
CVE-2026-7524

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

Fix: after 1.9.1
Fix from $2,300 2026-05-27
Linux Kernel CRITICAL 9.1
CVE-2026-46043

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv rxe_rcv() curr…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-05-27
Linux Kernel CRITICAL 9.8
CVE-2026-46039

In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length check Fix potential integer over…

Fix: 6.17 / 6.18.27+
Fix from $2,300 2026-05-27
Linux Kernel CRITICAL 9.8
CVE-2026-45988

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a RESPONSE packet gets a tempor…

Fix: 6.6.140 / 6.12.86+
Fix from $2,300 2026-05-27
Linux Kernel CRITICAL 9.8
CVE-2026-45972

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in smb2_open_file() Zero out @er…

Fix: 6.1.165 / 6.6.128+
Fix from $2,300 2026-05-27
Linux Kernel CRITICAL 9.8
CVE-2026-45898

In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by removing work_list The commit e1168…

Fix: 6.12.75 / 6.18.14+
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-35090

In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can connect to the modem via a telepho…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-35087

Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executi…

Mitigation only
Fix from $2,300 2026-05-27
Operations Analytics Log Analysis CRITICAL 9.8
CVE-2024-40684

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-42761

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommer…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-42758

Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affe…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.9
CVE-2026-42757

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-igni…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.9
CVE-2026-42756

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Imag…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-42755

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allow…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.9
CVE-2026-42748

Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-42747

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-buil…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-42740

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Inj…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-42731

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This i…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.3
CVE-2026-42727

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommer…

Mitigation only
Fix from $2,300 2026-05-27
Unclassified CRITICAL 10.0
CVE-2026-8054

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and…

Patch available
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.1
CVE-2026-49002

Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system dat…

No fix yet
Fix from $2,300 2026-05-27
Diskstation Manager CRITICAL 9.8
CVE-2025-13392

Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-…

Fix: 7.2.2-72806-5+
Fix from $2,300 2026-05-27
Beestation Os CRITICAL 9.8
CVE-2025-12686

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allo…

Fix: 1.3.2+
Fix from $2,300 2026-05-27
Unclassified CRITICAL 9.8
CVE-2026-8760

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplet…

Mitigation only
Fix from $2,300 2026-05-27