Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.6
CVE-2026-44482

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.0
CVE-2026-42457

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.8
CVE-2026-2347

Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hi…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.8
CVE-2025-11024

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. …

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.1
CVE-2026-6512

The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin …

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.8
CVE-2026-6510

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. …

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.8
CVE-2026-6271

The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. T…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.8
CVE-2026-8181EPSS 15%

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypas…

Mitigation only
Fix from $2,300 2026-05-14
Unclassified CRITICAL 9.8
CVE-2026-8500

Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpass…

Mitigation only
Fix from $2,300 2026-05-13
Opnsense CRITICAL 9.1
CVE-2026-45158

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configu…

Fix: 26.1.8+
Fix from $2,300 2026-05-13
Erpnext CRITICAL 9.9
CVE-2026-44442

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks…

Fix: 16.9.1+
Fix from $2,300 2026-05-13
Opnsense CRITICAL 9.1
CVE-2026-44194EPSS 6%

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsens…

Fix: 26.1.8+
Fix from $2,300 2026-05-13
Opnsense CRITICAL 9.1
CVE-2026-44193

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user …

Fix: 26.1.7+
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.1
CVE-2026-45714

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple m…

Mitigation only
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.1
CVE-2026-45053

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager …

Mitigation only
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.1
CVE-2026-44377

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple m…

Patch available
Fix from $2,300 2026-05-13
Empirbus Wireless Display Unit Firmware CRITICAL 9.3
CVE-2025-27851

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU …

Mitigation only
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.3
CVE-2026-44364

MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerabilit…

Mitigation only
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.1
CVE-2026-44351

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-re…

Mitigation only
Fix from $2,300 2026-05-13
Netty CRITICAL 9.1
CVE-2026-42584

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound res…

Fix: 4.1.133 / 4.2.13+
Fix from $2,300 2026-05-13
Netty CRITICAL 9.8
CVE-2026-42581

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting…

Fix: 4.1.133 / 4.2.13+
Fix from $2,300 2026-05-13
Netty CRITICAL 9.1
CVE-2026-42579

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC…

Fix: 4.1.133 / 4.2.13+
Fix from $2,300 2026-05-13
Ckan CRITICAL 9.1
CVE-2026-42032

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastor…

Fix: 2.10.10 / 2.11.5+
Fix from $2,300 2026-05-13
Ckan CRITICAL 9.8
CVE-2026-42031

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastor…

Fix: 2.10.10 / 2.11.5+
Fix from $2,300 2026-05-13
Pan Os CRITICAL 9.1
CVE-2026-0258

A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attac…

Fix: 10.2.7 / 10.2.10+
Fix from $2,300 2026-05-13
Pan Os CRITICAL 9.1
CVE-2026-0257 KEVEPSS 94%

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass se…

Fix: 10.2.7+
Fix from $2,300 2026-05-13
Vm2 CRITICAL 9.8
CVE-2026-45411

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async g…

Fix: 3.11.3+
Fix from $2,300 2026-05-13
Vm2 CRITICAL 9.8
CVE-2026-44009

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

Fix: 3.11.2+
Fix from $2,300 2026-05-13
Vm2 CRITICAL 9.8
CVE-2026-44008

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but …

Fix: 3.11.2+
Fix from $2,300 2026-05-13
Vm2 CRITICAL 9.1
CVE-2026-44007

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require(…

Fix: 3.11.1+
Fix from $2,300 2026-05-13