Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-8450

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(…

Patch available
Fix from $2,300 2026-05-27
Dozzle CRITICAL 9.6
CVE-2026-44985

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: f…

Fix: 10.5.2+
Fix from $2,300 2026-05-26
Velocity.js CRITICAL 9.8
CVE-2026-44966

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was disc…

Fix: after 2.1.5
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.2
CVE-2026-44895

GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer…

Mitigation only
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.3
CVE-2026-44451

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluate…

Mitigation only
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.9
CVE-2026-44450

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist o…

Mitigation only
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.1
CVE-2026-44449

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirnam…

Mitigation only
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.1
CVE-2026-44444

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts…

Mitigation only
Fix from $2,300 2026-05-26
Fastnetmon CRITICAL 9.8
CVE-2026-48689

FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary…

Fix: after 1.2.9
Fix from $2,300 2026-05-26
Engineering Lifecycle Management CRITICAL 9.8
CVE-2026-3660

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that woul…

Mitigation only
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-9170

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation.

Mitigation only
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.1
CVE-2026-8856

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configura…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
HTTP Server CRITICAL 9.8
CVE-2026-8855

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client au…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
Websphere Application Server CRITICAL 9.8
CVE-2026-8633

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Se…

Fix: after 9.0.5.27
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.8
CVE-2026-7251

Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 mo…

Mitigation only
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.3
CVE-2026-47202

Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to r…

Mitigation only
Fix from $2,300 2026-05-26
Twenty CRITICAL 9.9
CVE-2026-46624

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL …

Fix: 1.16.7+
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.8
CVE-2026-44668

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Stru…

Mitigation only
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-48904

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-48902

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-48899

An improper access check allows privilege escalation through the com_users batch task.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-48898

An improper access check allows privilege escalation through the com_users batch task.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Fastnetmon CRITICAL 9.8
CVE-2026-48691

FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4Unicas…

Fix: after 1.2.9
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.0
CVE-2026-45721

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without …

Mitigation only
Fix from $2,300 2026-05-26
Vowpal Wabbit CRITICAL 9.9
CVE-2026-44723

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly i…

Fix: 2026-05-04+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-40383

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-35223

An improper access check allows unauthorized access to com_config webservice endpoints.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-35222

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Joomla\! CRITICAL 9.8
CVE-2026-35221

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

Fix: 5.4.6 / 6.1.1+
Fix from $2,300 2026-05-26
Unclassified CRITICAL 9.2
CVE-2026-2264

A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and ex…

Mitigation only
Fix from $2,300 2026-05-26