Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-44313

Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-…

Mitigation only
Fix from $2,300 2026-05-09
Postiz CRITICAL 9.0
CVE-2026-42556

Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store ar…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.9
CVE-2026-42454

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker cont…

Mitigation only
Fix from $2,300 2026-05-08
Sentry CRITICAL 9.8
CVE-2026-42354

Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered i…

Fix: 26.4.1+
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.8
CVE-2026-42302

FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to una…

Patch available
Fix from $2,300 2026-05-08
Postiz CRITICAL 9.8
CVE-2026-42298

Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflo…

Fix: 2.21.7+
Fix from $2,300 2026-05-08
Unclassified CRITICAL 10.0
CVE-2026-42287

Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attack…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.1
CVE-2026-42193

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification pa…

Mitigation only
Fix from $2,300 2026-05-08
Mailenable CRITICAL 9.8
CVE-2026-44400

MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers …

Fix: 10.56+
Fix from $2,300 2026-05-08
N8n Mcp CRITICAL 9.1
CVE-2026-44694

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before vers…

Fix: 2.50.2+
Fix from $2,300 2026-05-08
Unclassified CRITICAL 10.0
CVE-2026-42160

Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before v…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.8
CVE-2026-42072

Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-…

Patch available
Fix from $2,300 2026-05-08
Pgx CRITICAL 9.8
CVE-2026-41889

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar…

Fix: 5.9.2+
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.8
CVE-2026-38360EPSS 6%

Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash…

Patch available
Fix from $2,300 2026-05-08
Unclassified CRITICAL 10.0
CVE-2026-41070

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version …

Patch available
Fix from $2,300 2026-05-08
Zebra Script CRITICAL 9.1
CVE-2026-44497

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 int…

Fix: 4.4.0 / 6.0.0+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.8
CVE-2026-43465

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ XDP multi-buf pr…

Fix: 6.7 / 6.13+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.8
CVE-2026-43414

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp-…

Fix: 5.16 / 6.2+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.1
CVE-2026-43407

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() This pa…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.1
CVE-2026-43406

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in process_message_header() If t…

Fix: 5.15.203 / 6.1.167+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.8
CVE-2026-43402

In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit paths to prevent use-after-free Guillaume rep…

Fix: 6.18.19 / 6.19.9+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.8
CVE-2026-43384

In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, M…

Fix: 6.12.78 / 6.18.19+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.4
CVE-2026-43383

In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, …

Fix: 5.10.253 / 6.1.167+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.8
CVE-2026-43379

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() opinfo pointer…

Fix: 6.6.130 / 6.12.78+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.8
CVE-2026-43376

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by using call_rcu() for oplock_info ksmbd currently f…

Fix: 6.6.130 / 6.12.78+
Fix from $2,300 2026-05-08
Zebra Script CRITICAL 9.1
CVE-2026-41583

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra fai…

Fix: 4.3.1 / 5.0.2+
Fix from $2,300 2026-05-08
Nhost\/auth CRITICAL 9.8
CVE-2026-41574

Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existi…

Fix: 0.49.1+
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.8
CVE-2026-37431

Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.…

Mitigation only
Fix from $2,300 2026-05-08
Praisonai CRITICAL 9.6
CVE-2026-44336

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou…

Fix: 4.6.34+
Fix from $2,300 2026-05-08
Praisonaiagents CRITICAL 9.8
CVE-2026-44335

PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by at…

Fix: 1.6.32+
Fix from $2,300 2026-05-08