Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.4
CVE-2026-42882

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path inte…

Patch available
Fix from $2,300 2026-05-11
Unclassified CRITICAL 10.0
CVE-2026-42869

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a …

Patch available
Fix from $2,300 2026-05-11
Unclassified CRITICAL 9.9
CVE-2026-42864

FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reacha…

Mitigation only
Fix from $2,300 2026-05-11
Openclaw CRITICAL 9.8
CVE-2026-8305

A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions…

Fix: 2026.2.12+
Fix from $2,300 2026-05-11
Flowise CRITICAL 9.8
CVE-2026-43995

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly impor…

Fix: 3.1.0+
Fix from $2,300 2026-05-11
Server CRITICAL 9.1
CVE-2026-43639

Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organizati…

Fix: 2026.4.0+
Fix from $2,300 2026-05-11
Openedx CRITICAL 9.9
CVE-2026-42858

Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allo…

Fix: 2026-04-24+
Fix from $2,300 2026-05-11
Unclassified CRITICAL 9.8
CVE-2026-38567

HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries witho…

Mitigation only
Fix from $2,300 2026-05-11
Pgadmin 4 CRITICAL 9.9
CVE-2026-7813

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. M…

Fix: 9.15+
Fix from $2,300 2026-05-11
Angular Expressions CRITICAL 10.0
CVE-2026-44643

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious e…

Fix: 1.5.2+
Fix from $2,300 2026-05-11
Unclassified CRITICAL 9.4
CVE-2026-42613

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and acc…

Patch available
Fix from $2,300 2026-05-11
Grav CRITICAL 9.1
CVE-2026-42608

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulatin…

Fix: 2.0.0+
Fix from $2,300 2026-05-11
Unclassified CRITICAL 9.1
CVE-2026-42607

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE…

Patch available
Fix from $2,300 2026-05-11
Elastic Cloud Storage CRITICAL 9.8
CVE-2026-35157

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in …

Fix: 4.3.0.0+
Fix from $2,300 2026-05-11
Ac10u Firmware CRITICAL 9.8
CVE-2026-8263

A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtr…

Mitigation only
Fix from $2,300 2026-05-11
Unclassified CRITICAL 9.8
CVE-2021-47940

WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers t…

Mitigation only
Fix from $2,300 2026-05-10
Unclassified CRITICAL 9.8
CVE-2021-47936

OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malici…

Mitigation only
Fix from $2,300 2026-05-10
Unclassified CRITICAL 9.8
CVE-2021-47933

WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending…

Mitigation only
Fix from $2,300 2026-05-10
Unclassified CRITICAL 9.8
CVE-2021-47932

WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts …

Mitigation only
Fix from $2,300 2026-05-10
Unclassified CRITICAL 9.8
CVE-2021-47923

OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSES…

Mitigation only
Fix from $2,300 2026-05-10
PHP CRITICAL 9.1
CVE-2026-6104

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() …

Fix: 8.4.21 / 8.5.6+
Fix from $2,300 2026-05-10
PHP CRITICAL 9.8
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSIS…

Fix: 8.2.31 / 8.3.31+
Fix from $2,300 2026-05-10
PHP CRITICAL 9.8
CVE-2026-6722

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mech…

Fix: 8.2.31 / 8.3.31+
Fix from $2,300 2026-05-10
PHP CRITICAL 9.8
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL…

Fix: 8.2.31 / 8.3.31+
Fix from $2,300 2026-05-10
Archivebox CRITICAL 9.8
CVE-2026-42601

ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts …

Fix: 0.8.6+
Fix from $2,300 2026-05-09
Unclassified CRITICAL 9.0
CVE-2026-42571

Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.2…

Patch available
Fix from $2,300 2026-05-09
Unclassified CRITICAL 9.4
CVE-2026-42569

phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access…

Patch available
Fix from $2,300 2026-05-09
Net\ CRITICAL 9.8
CVE-2026-42257

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::…

Fix: 0.4.24 / 0.5.14+
Fix from $2,300 2026-05-09
Unclassified CRITICAL 9.1
CVE-2026-42560

auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provide…

Patch available
Fix from $2,300 2026-05-09
Pgbouncer CRITICAL 9.8
CVE-2026-6665

The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-…

Fix: 1.25.2+
Fix from $2,300 2026-05-09