Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Secure Workload CRITICAL 10.0
CVE-2026-20223

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to acces…

Fix: 3.10.8.3 / 4.0.3.17+
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.1
CVE-2026-8598

An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and expose…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.5
CVE-2026-8467

Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpol…

Patch available
Fix from $2,300 2026-05-20
Twig CRITICAL 9.9
CVE-2026-24425

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with te…

Fix: 3.26.0+
Fix from $2,300 2026-05-20
Bind CRITICAL 9.8
CVE-2026-3593

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 thr…

Fix: 9.20.23 / 9.21.22+
Fix from $2,300 2026-05-20
Bigfix Service Management CRITICAL 9.8
CVE-2025-31973

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images …

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.0
CVE-2026-22314

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component en…

Mitigation only
Fix from $2,300 2026-05-20
Unbound CRITICAL 10.0
CVE-2026-42960

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSet…

Fix: 1.25.1+
Fix from $2,300 2026-05-20
Unbound CRITICAL 9.8
CVE-2026-33278

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible …

Fix: 1.25.1+
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.3
CVE-2026-9065

SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'p…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.3
CVE-2026-9059

NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/…

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-7637

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input i…

Mitigation only
Fix from $2,300 2026-05-20
Triton Inference Server CRITICAL 9.8
CVE-2026-24214

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit o…

Fix: 26.03+
Fix from $2,300 2026-05-20
Triton Inference Server CRITICAL 9.8
CVE-2026-24213

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit…

Fix: 26.03+
Fix from $2,300 2026-05-20
Triton Inference Server CRITICAL 9.8
CVE-2026-24207

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerab…

Fix: 26.03+
Fix from $2,300 2026-05-20
Triton Inference Server CRITICAL 9.8
CVE-2026-24206

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerab…

Fix: 26.03+
Fix from $2,300 2026-05-20
Tensorrt Llm CRITICAL 9.8
CVE-2026-24163

NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful explo…

Fix: 1.2+
Fix from $2,300 2026-05-20
Tensorrt Llm CRITICAL 9.8
CVE-2026-24142

NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability m…

Fix: 1.2+
Fix from $2,300 2026-05-20
Tensorrt Llm CRITICAL 9.8
CVE-2025-33255

NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit…

Fix: 1.2+
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-7284

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all …

Mitigation only
Fix from $2,300 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-6555

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an arra…

Mitigation only
Fix from $2,300 2026-05-20
Date Ical CRITICAL 9.8
CVE-2026-8495

Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15.

Fix: 4.0.15+
Fix from $2,300 2026-05-19
Unclassified CRITICAL 10.0
CVE-2026-34234

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is…

Mitigation only
Fix from $2,300 2026-05-19
Kitty CRITICAL 9.8
CVE-2026-33642

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds…

Fix: 0.47.0+
Fix from $2,300 2026-05-19
Scadabr CRITICAL 9.8
CVE-2026-8605

In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.

Mitigation only
Fix from $2,300 2026-05-19
Scadabr CRITICAL 9.8
CVE-2026-8603

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

Mitigation only
Fix from $2,300 2026-05-19
Scadabr CRITICAL 9.1
CVE-2026-8602

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET req…

Mitigation only
Fix from $2,300 2026-05-19
Unclassified CRITICAL 9.8
CVE-2026-36829

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session…

Mitigation only
Fix from $2,300 2026-05-19
Unclassified CRITICAL 9.8
CVE-2026-37281

An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbit…

Patch available
Fix from $2,300 2026-05-19
Unclassified CRITICAL 9.8
CVE-2026-31072

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via In…

Mitigation only
Fix from $2,300 2026-05-19