Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Edge Chromium CRITICAL 9.8
CVE-2026-45495

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Fix: 148.0.3967.70+
Fix from $2,300 2026-05-18
Unclassified CRITICAL 9.1
CVE-2026-45230

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allow…

Patch available
Fix from $2,300 2026-05-18
Azure Local CRITICAL 10.0
CVE-2026-42822

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

Fix: 2604.2.25645+
Fix from $2,300 2026-05-18
Unclassified CRITICAL 9.1
CVE-2023-24215

Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator cred…

Mitigation only
Fix from $2,300 2026-05-18
Unclassified CRITICAL 10.0
CVE-2026-45829EPSS 12%

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run…

Mitigation only
Fix from $2,300 2026-05-18
Dify CRITICAL 9.4
CVE-2026-41948EPSS 7%

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin D…

Fix: after 1.14.1
Fix from $2,300 2026-05-18
Dify CRITICAL 9.1
CVE-2026-41947EPSS 6%

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configuratio…

Fix: after 1.14.1
Fix from $2,300 2026-05-18
Sglang CRITICAL 9.8
CVE-2026-7304

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabl…

Mitigation only
Fix from $2,300 2026-05-18
Sglang CRITICAL 9.1
CVE-2026-7302

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files…

Mitigation only
Fix from $2,300 2026-05-18
Sglang CRITICAL 9.8
CVE-2026-7301

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming…

Mitigation only
Fix from $2,300 2026-05-18
Unclassified CRITICAL 9.3
CVE-2026-4320

Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulat…

Mitigation only
Fix from $2,300 2026-05-18
Unclassified CRITICAL 9.8
CVE-2026-8721

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *,…

Mitigation only
Fix from $2,300 2026-05-17
Unclassified CRITICAL 9.8
CVE-2026-8507

Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING…

Patch available
Fix from $2,300 2026-05-17
Hive CRITICAL 9.1
CVE-2026-8757

A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.…

Fix: after 0.11.0
Fix from $2,300 2026-05-17
Unclassified CRITICAL 9.8
CVE-2018-25335

WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by…

Mitigation only
Fix from $2,300 2026-05-17
Gitbucket CRITICAL 9.8
CVE-2018-25332

GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting we…

Fix: 4.24.0+
Fix from $2,300 2026-05-17
Unclassified CRITICAL 9.8
CVE-2018-25320

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands …

Mitigation only
Fix from $2,300 2026-05-17
H2o CRITICAL 9.8
CVE-2026-8751

A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Mod…

Fix: after 7402
Fix from $2,300 2026-05-17
Unclassified CRITICAL 9.8
CVE-2021-47952

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing ma…

Mitigation only
Fix from $2,300 2026-05-16
Unclassified CRITICAL 9.8
CVE-2020-37239

libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature ove…

Mitigation only
Fix from $2,300 2026-05-16
Unclassified CRITICAL 9.8
CVE-2020-37228

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting …

Mitigation only
Fix from $2,300 2026-05-16
Open Webui CRITICAL 9.8
CVE-2026-44566

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp,…

Fix: 0.1.124+
Fix from $2,300 2026-05-15
Radare2 CRITICAL 9.8
CVE-2026-8696

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cau…

Fix: after 6.1.4
Fix from $2,300 2026-05-15
Open Webui CRITICAL 9.1
CVE-2026-44551

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint d…

Fix: 0.9.0+
Fix from $2,300 2026-05-15
Coremqtt CRITICAL 9.1
CVE-2026-8686

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a c…

Mitigation only
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.8
CVE-2026-46364

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha()…

Patch available
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.1
CVE-2026-45010

phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/check endpoint, which accepts…

Mitigation only
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.8
CVE-2021-47965

WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers …

Mitigation only
Fix from $2,300 2026-05-15
Radare2 CRITICAL 9.8
CVE-2026-8695

radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption b…

Fix: after 6.1.4
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.8
CVE-2026-44717

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mat…

Mitigation only
Fix from $2,300 2026-05-15