Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 10.0
CVE-2026-33712

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allo…

Mitigation only
Fix from $2,300 2026-05-22
Sunshine CRITICAL 9.8
CVE-2026-32253

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed…

Fix: 2026.516.143833+
Fix from $2,300 2026-05-22
Net CRITICAL 9.6
CVE-2026-39821

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--exampl…

Fix: 0.55.0+
Fix from $2,300 2026-05-22
Avantra CRITICAL 9.1
CVE-2026-8673

Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avan…

Fix: 25.3.0+
Fix from $2,300 2026-05-22
Avantra CRITICAL 9.6
CVE-2026-8670

Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session IDs (aka Session Replay). This…

Fix: 25.3.1+
Fix from $2,300 2026-05-22
Cxf CRITICAL 9.8
CVE-2026-44930

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certi…

Fix: 3.6.11 / 4.1.6+
Fix from $2,300 2026-05-22
Unclassified CRITICAL 9.2
CVE-2026-9054

An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel panic.

Mitigation only
Fix from $2,300 2026-05-22
Crypto CRITICAL 10.0
CVE-2026-46595

Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than pu…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-42508EPSS 7%

Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are check…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39834

When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the w…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39833

The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign …

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39831

The Verify() method for FIDO/U2F security key types ([email protected], [email protected]) did not check the User Presence …

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39832

When adding a key to a remote agent constraint extensions such as [email protected] were not serialized in the request. Destinatio…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Crypto CRITICAL 9.1
CVE-2026-39830

A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked gor…

Fix: 0.52.0+
Fix from $2,300 2026-05-22
Unclassified CRITICAL 9.3
CVE-2026-9264

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration thr…

Mitigation only
Fix from $2,300 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34910 KEVEPSS 87%

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command …

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34909 KEVEPSS 64%

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying…

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Unifi Os Server CRITICAL 10.0
CVE-2026-34908 KEVEPSS 85%

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized ch…

Fix: 5.0.8 / 5.1.12+
Fix from $2,300 2026-05-22
Unifi Os Server CRITICAL 9.1
CVE-2026-33000

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices t…

Fix: 5.0.8+
Fix from $2,300 2026-05-22
Unclassified CRITICAL 9.8
CVE-2026-6960

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_s…

Mitigation only
Fix from $2,300 2026-05-21
Fory CRITICAL 9.8
CVE-2026-48207

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks dur…

Fix: 1.0.0+
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.3
CVE-2026-39531

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind …

Mitigation only
Fix from $2,300 2026-05-21
Apex One CRITICAL 9.8
CVE-2025-71211

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte…

Fix: 14.0.0.14136 / 14.0.20315+
Fix from $2,300 2026-05-21
Apex One CRITICAL 9.8
CVE-2025-71210

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte…

Fix: 14.0.0.14136 / 14.0.20315+
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.8
CVE-2026-5118

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin a…

Mitigation only
Fix from $2,300 2026-05-21
Linux Kernel CRITICAL 9.8
CVE-2026-43501

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rc…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.1
CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability vi…

No fix yet
Fix from $2,300 2026-05-21
Mattermost Server CRITICAL 9.9
CVE-2026-4858

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which …

Fix: 10.11.15 / 11.4.5+
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.9
CVE-2026-44050

A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute…

Mitigation only
Fix from $2,300 2026-05-21
Unclassified CRITICAL 9.8
CVE-2026-6279

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions…

Mitigation only
Fix from $2,300 2026-05-21