Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Crypto CRITICAL 9.1
CVE-2026-39830

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked gor…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Unclassified CRITICAL 9.3
CVE-2026-9264

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration thr…

Mitigation only
Fix from $2,300 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34910 KEVEPSS 87%

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command …

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34909 KEVEPSS 64%

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying…

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34908 KEVEPSS 85%

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized ch…

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Unifi Os Server CRITICAL 9.1
CVE-2026-33000

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices t…

Fix: 5.0.8+
Fix from $2,300 2026-05-22
Unclassified CRITICAL 9.8
CVE-2026-6960

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_s…

Mitigation only
Fix from $2,300 2026-05-21
Fory CRITICAL 9.8
CVE-2026-48207

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur…

Fix: 1.0.0+
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.3
CVE-2026-39531

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind …

Mitigation only
Fix from $2,300 2026-05-21
Apex One CRITICAL 9.8
CVE-2025-71211

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte…

Fix: 14.0.0.14136 / 14.0.20315+
Fix from $2,300 2026-05-21
Apex One CRITICAL 9.8
CVE-2025-71210

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte…

Fix: 14.0.0.14136 / 14.0.20315+
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.8
CVE-2026-5118

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin a…

Mitigation only
Fix from $2,300 2026-05-21
Linux Kernel CRITICAL 9.8
CVE-2026-43501

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rc…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.1
CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability vi…

No fix yet
Fix from $2,300 2026-05-21
Mattermost Server CRITICAL 9.9
CVE-2026-4858

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which …

Fix: 10.11.15 / 11.4.5+
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.9
CVE-2026-44050

A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute…

Mitigation only
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.8
CVE-2026-6279

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions…

Mitigation only
Fix from $2,300 2026-05-21
Unclassified CRITICAL 10.0
CVE-2026-9152

A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiri…

Mitigation only
Fix from $2,300 2026-05-21
Litespeed Cpanel Plugin CRITICAL 9.8
CVE-2026-48172 KEVEPSS 19%

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best…

Fix: 2.4.7 / 5.3.1.0+
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.1
CVE-2026-47372

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is …

Patch available
Fix from $2,300 2026-05-20
Linux Imaging And Printing CRITICAL 9.8
CVE-2026-8631

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalati…

Fix: 3.26.4+
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-9141

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-9139

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.4
CVE-2026-9129

A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.4
CVE-2026-9102

A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file uploa…

Mitigation only
Fix from $2,300 2026-05-20
Drupal CRITICAL 9.8
CVE-2026-9082 KEVEPSS 88%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This …

Fix: 10.4.10 / 10.5.10+
Fix from $2,300 2026-05-20
Unclassified CRITICAL 10.0
CVE-2026-45444

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files. This issue a…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.4
CVE-2026-39405

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with cour…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.3
CVE-2026-33137

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. I…

Patch available
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.3
CVE-2026-23734EPSS 20%

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by u…

Patch available
Fix from $2,300 2026-05-20