Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tomcat CRITICAL 9.1
CVE-2026-43515

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affe…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Tomcat CRITICAL 9.8
CVE-2026-43512

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 t…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Tomcat CRITICAL 9.8
CVE-2026-41293

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 1…

Fix: 9.0.118 / 10.1.55+
Fix from $2,300 2026-05-12
Pandora Fms CRITICAL 9.8
CVE-2026-34187

Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via graph container parameter. This issue affec…

Fix: 777.17 / 802+
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31228

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluat…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31226

The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) i…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31220

PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of use…

Mitigation only
Fix from $2,300 2026-05-12
Optimate CRITICAL 9.8
CVE-2026-31217

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07…

Mitigation only
Fix from $2,300 2026-05-12
Nexent CRITICAL 9.1
CVE-2026-31216

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /st…

Mitigation only
Fix from $2,300 2026-05-12
Nexent CRITICAL 9.1
CVE-2026-31215

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. The DELETE…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2026-31214

The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insec…

Mitigation only
Fix from $2,300 2026-05-12
Pandora Fms CRITICAL 9.1
CVE-2026-30805

Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 throu…

Fix: 777.17 / 802+
Fix from $2,300 2026-05-12
Firefox CRITICAL 9.8
CVE-2026-8401

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderb…

Fix: 150.0.3+
Fix from $2,300 2026-05-12
Xtraction CRITICAL 9.6
CVE-2026-8043

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write ar…

Fix: 2026.2+
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-45091

sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alp…

Mitigation only
Fix from $2,300 2026-05-12
Dovecot CRITICAL 9.1
CVE-2026-27851

When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe…

Fix: 2.4.4 / 3.1.5+
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.2
CVE-2026-8072

Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board. The vulnerability arose be…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.2
CVE-2026-7428

Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecur…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-41551

A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerability because user input is n…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-25787

Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web inter…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.1
CVE-2026-25786

Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This c…

Mitigation only
Fix from $2,300 2026-05-12
Simatic Cn 4100 Firmware CRITICAL 9.1
CVE-2026-22924

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated con…

Fix: 5.0+
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.8
CVE-2025-6577

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. …

Mitigation only
Fix from $2,300 2026-05-12
Ruggedcom Rox Mx5000 Firmware CRITICAL 9.1
CVE-2025-40949

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX …

Fix: 2.17.1+
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.6
CVE-2026-34263

Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in a…

Mitigation only
Fix from $2,300 2026-05-12
Unclassified CRITICAL 9.6
CVE-2026-34260

SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacker to inject malicious SQL sta…

Mitigation only
Fix from $2,300 2026-05-12
Mistralai CRITICAL 9.6
CVE-2026-45321 KEV

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. Th…

Mitigation only
Fix from $2,300 2026-05-12
Vaultwarden CRITICAL 9.8
CVE-2026-43914

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing…

Fix: 1.35.4+
Fix from $2,300 2026-05-11
Unclassified CRITICAL 9.3
CVE-2026-43900

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Script…

Mitigation only
Fix from $2,300 2026-05-11
Unclassified CRITICAL 9.6
CVE-2026-43899

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitig…

Mitigation only
Fix from $2,300 2026-05-11