Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortiauthenticator CRITICAL 9.8
CVE-2026-44277

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, Forti…

Fix: 6.5.7 / 6.6.9+
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-44196

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows …

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-44183

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Pri…

Mitigation only
Fix from $2,300 2026-05-12
Dynamics 365 CRITICAL 9.9
CVE-2026-42898

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …

Fix: 9.1.45.11+
Fix from $2,300 2026-05-12
Dynamics 365 CRITICAL 9.1
CVE-2026-42833

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …

Fix: 9.1.45.11+
Fix from $2,300 2026-05-12
Azure Logic Apps CRITICAL 9.9
CVE-2026-42823

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.3
CVE-2026-42300

DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware accepts a client-supplied X-Admi…

Patch available
Fix from $2,300 2026-05-12
Langflow CRITICAL 9.6
CVE-2026-42048

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowle…

Fix: 1.9.0+
Fix from $2,300 2026-05-12
Confluence Saml Sso CRITICAL 9.1
CVE-2026-41103EPSS 5%

Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate pri…

Fix: 1.3.3 / 7.4.0+
Fix from $2,300 2026-05-12
Windows 11 23h2 CRITICAL 9.8
CVE-2026-41096

Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.

Fix: 10.0.22631.7079 / 10.0.25398.2330+
Fix from $2,300 2026-05-12
Windows Server 2012 CRITICAL 9.8
CVE-2026-41089EPSS 80%

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $2,300 2026-05-12
Windows 11 23h2 CRITICAL 9.3
CVE-2026-40402

Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.20348.5074 / 10.0.22631.7079+
Fix from $2,300 2026-05-12
Dynamics 365 Customer Insights CRITICAL 9.9
CVE-2026-33821

Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
Azure Sdk For Java CRITICAL 9.1
CVE-2026-33117

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com…

Fix: 4.10.6+
Fix from $2,300 2026-05-12
Mem0 CRITICAL 9.1
CVE-2026-31242

The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoin…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31239

The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hu…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31238

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server wit…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31237

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset fil…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31236

The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. This argument is intended to…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31235

The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31234

Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for d…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31233

Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packag…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31231

Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to e…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31230

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_e…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31229

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model l…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-29204

Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without a…

Mitigation only
Fix from $2,300 2026-05-12
Fortisandbox CRITICAL 9.8
CVE-2026-26083

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 throug…

Fix: 4.4.9 / 5.0.2+
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-43992

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate…

Patch available
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.3
CVE-2026-20794

Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2025-65719

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted H…

Mitigation only
Fix from $2,300 2026-05-12