Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Traefik CRITICAL 9.9
CVE-2026-44774

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant wi…

Fix: 2.11.46 / 3.6.17+
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.1
CVE-2026-44699

LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key f…

Mitigation only
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.3
CVE-2026-42155

Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo…

Mitigation only
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.1
CVE-2026-41258

OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateC…

Mitigation only
Fix from $2,300 2026-05-15
Turborepo CRITICAL 9.8
CVE-2026-45772

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arb…

Fix: 2.9.14+
Fix from $2,300 2026-05-15
Unclassified CRITICAL 10.0
CVE-2026-2031

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remo…

Mitigation only
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.2
CVE-2026-7182

Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the ht…

Mitigation only
Fix from $2,300 2026-05-15
Pdf Export Module CRITICAL 10.0
CVE-2026-41553

PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. …

Fix: 0.7.6+
Fix from $2,300 2026-05-15
Daemon Tools CRITICAL 9.8
CVE-2026-8398 KEV

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distrib…

Mitigation only
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.8
CVE-2026-5229

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trustin…

Patch available
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.2
CVE-2026-0481

Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to …

Mitigation only
Fix from $2,300 2026-05-15
Unclassified CRITICAL 9.3
CVE-2026-44666

HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.3
CVE-2026-44212

PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the …

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.1
CVE-2026-8634

Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repo…

Patch available
Fix from $2,300 2026-05-14
Chrome CRITICAL 9.6
CVE-2026-8580

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Fix: 148.0.7778.168+
Fix from $2,300 2026-05-14
Chrome CRITICAL 9.6
CVE-2026-8511

Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pa…

Fix: 148.0.7778.168+
Fix from $2,300 2026-05-14
Fleet CRITICAL 9.8
CVE-2026-26191

Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafte…

Fix: 4.81.0+
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.0
CVE-2026-45375

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version f…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.4
CVE-2026-44670

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTM…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.4
CVE-2026-44592

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone …

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.4
CVE-2026-44588

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-l…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 10.0
CVE-2026-44523

Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value.…

Mitigation only
Fix from $2,300 2026-05-14
Mdserver Web CRITICAL 9.8
CVE-2026-41315

mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to…

Fix: after 0.18.4
Fix from $2,300 2026-05-14
Gst Plugins Good CRITICAL 9.1
CVE-2026-46470

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function d…

Fix: 1.28.2+
Fix from $2,300 2026-05-14
Filebrowser Quantum CRITICAL 9.1
CVE-2026-44542

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined wi…

Fix: 1.3.1 / 1.3.9+
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.1
CVE-2026-42555

Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case …

Mitigation only
Fix from $2,300 2026-05-14
Catalyst Sd Wan Manager CRITICAL 10.0
CVE-2026-20182 KEVEPSS 92%

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed …

Fix: 20.9.9.1 / 20.12.5.4+
Fix from $2,300 2026-05-14
Gotenberg CRITICAL 9.4
CVE-2026-42596

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webho…

Fix: 8.31.0+
Fix from $2,300 2026-05-14
Gotenberg CRITICAL 9.8
CVE-2026-42589

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON…

Fix: 8.31.0+
Fix from $2,300 2026-05-14
Pytorch Lightning CRITICAL 9.8
CVE-2026-44484

PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent …

No fix yet
Fix from $2,300 2026-05-14