Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vm2 CRITICAL 10.0
CVE-2026-44006

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary…

Fix: 3.11.0+
Fix from $2,300 2026-05-13
Vm2 CRITICAL 10.0
CVE-2026-44005

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and…

Fix: 3.11.0+
Fix from $2,300 2026-05-13
Vm2 CRITICAL 9.9
CVE-2026-43999

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (includi…

Fix: 3.11.0+
Fix from $2,300 2026-05-13
Vm2 CRITICAL 10.0
CVE-2026-43997

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Objec…

Fix: 3.11.0+
Fix from $2,300 2026-05-13
Pan Os CRITICAL 9.8
CVE-2026-0264

A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker wi…

Fix: 10.2.7 / 10.2.10+
Fix from $2,300 2026-05-13
Pan Os CRITICAL 9.8
CVE-2026-0263

A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to ex…

Fix: 11.1.4 / 11.1.6+
Fix from $2,300 2026-05-13
Jupyterlab CRITICAL 9.6
CVE-2026-42557

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, Jupyt…

Fix: 4.5.7 / 7.5.6+
Fix from $2,300 2026-05-13
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2026-41225

A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration obj…

Fix: after 17.5.1
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.8
CVE-2020-37168

Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production s…

Mitigation only
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.8
CVE-2026-42062

ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arb…

Mitigation only
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.8
CVE-2026-40621

ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without aut…

Mitigation only
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.9
CVE-2026-41050

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored…

Mitigation only
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.8
CVE-2026-32661

Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker …

Mitigation only
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.6
CVE-2026-44547

ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged a…

Patch available
Fix from $2,300 2026-05-12
Unclassified CRITICAL 10.0
CVE-2026-42288

ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code ex…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.0
CVE-2026-41901

Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists i…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.4
CVE-2026-44262EPSS 6%

Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and val…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.3
CVE-2026-44258

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targets for path traversal and hom…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.3
CVE-2026-44257

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.…

Mitigation only
Fix from $2,300 2026-05-12
Nginx Ui CRITICAL 9.9
CVE-2026-44015

Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF)…

Fix: after 2.3.4
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.9
CVE-2026-43948

wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a …

Mitigation only
Fix from $2,300 2026-05-12
Arduino Esp32 CRITICAL 9.8
CVE-2026-42854

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer m…

Fix: 3.3.8+
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.9
CVE-2026-42196

django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal …

Mitigation only
Fix from $2,300 2026-05-12
Exim CRITICAL 9.8
CVE-2026-45185

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a c…

Fix: 4.99.3+
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.3
CVE-2026-44225

Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every …

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.0
CVE-2026-44221

ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific data…

Patch available
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-42889

Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebS…

Mitigation only
Fix from $2,300 2026-05-12
Connect Desktop Application CRITICAL 9.3
CVE-2026-34660

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code…

Fix: after 2025.9.15
Fix from $2,300 2026-05-12
Connect Desktop Application CRITICAL 9.6
CVE-2026-34659

Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit…

Fix: after 2025.8.157
Fix from $2,300 2026-05-12
Wgdashboard CRITICAL 9.8
CVE-2026-44343

WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allo…

Fix: 4.3.2+
Fix from $2,300 2026-05-12