Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-44128

SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes atta…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.2
CVE-2026-44126

SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow u…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.3
CVE-2026-44125

SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthe…

Mitigation only
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.8
CVE-2026-43341

In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema length wraparound in trace fill ioam6_fill_trac…

Fix: 6.1.168 / 6.6.134+
Fix from $2,300 2026-05-08
Linux Kernel CRITICAL 9.8
CVE-2026-43304

In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When decoding the key, verify that…

Fix: 5.15.202 / 6.1.165+
Fix from $2,300 2026-05-08
0din Scanner CRITICAL 9.9
CVE-2026-41512

ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerab…

Fix: 1.4.1+
Fix from $2,300 2026-05-08
Cross Implementation CRITICAL 9.8
CVE-2026-41509

CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there i…

Fix: 2026-03-23+
Fix from $2,300 2026-05-08
Math Codegen CRITICAL 9.8
CVE-2026-41507

math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim i…

Fix: 0.4.3+
Fix from $2,300 2026-05-08
Praisonai CRITICAL 9.8
CVE-2026-41497

PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or arg…

Fix: 4.6.9+
Fix from $2,300 2026-05-08
Cloudstack CRITICAL 9.1
CVE-2026-25199

Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudSt…

Fix: 4.22.0.1+
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.8
CVE-2026-8153

OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft co…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.3
CVE-2026-8076

Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentic…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified CRITICAL 10.0
CVE-2026-6213

A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code exec…

Mitigation only
Fix from $2,300 2026-05-08
Apache\ CRITICAL 9.1
CVE-2013-10075

Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Sto…

Fix: after 1.94
Fix from $2,300 2026-05-08
Pfsense CRITICAL 9.9
CVE-2025-69691

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only …

Mitigation only
Fix from $2,300 2026-05-08
Pfsense CRITICAL 9.1
CVE-2025-69690

Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_rebo…

No fix yet
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.8
CVE-2025-69599

RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: th…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.8
CVE-2025-67887

1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and exec…

Mitigation only
Fix from $2,300 2026-05-08
Unclassified CRITICAL 9.8
CVE-2023-46453

Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both…

Mitigation only
Fix from $2,300 2026-05-08
Librenms CRITICAL 9.1
CVE-2024-51092EPSS 7%

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), Settings…

Fix: 24.10.0+
Fix from $2,300 2026-05-08
Electerm CRITICAL 9.6
CVE-2026-43944

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerabl…

Fix: 3.8.15+
Fix from $2,300 2026-05-08
Electerm CRITICAL 9.6
CVE-2026-43941

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink…

Fix: after 3.8.15
Fix from $2,300 2026-05-08
Axios CRITICAL 9.1
CVE-2026-42264

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL…

Fix: 1.15.2+
Fix from $2,300 2026-05-08
Litellm CRITICAL 9.8
CVE-2026-42208 KEVEPSS 89%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query…

Fix: 1.83.7+
Fix from $2,300 2026-05-08
Openlearnx CRITICAL 10.0
CVE-2026-41900

OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was…

Patch available
Fix from $2,300 2026-05-08
Electerm CRITICAL 9.8
CVE-2026-41501

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability e…

Fix: 3.3.8+
Fix from $2,300 2026-05-08
Electerm CRITICAL 9.8
CVE-2026-41500

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability e…

Fix: 3.3.8+
Fix from $2,300 2026-05-08
Argo Cd CRITICAL 9.6
CVE-2026-42880

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a …

Fix: 3.2.11 / 3.3.9+
Fix from $2,300 2026-05-07
Enterprise Server CRITICAL 9.8
CVE-2026-8034

A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access …

Fix: 3.16.18 / 3.17.15+
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.1
CVE-2026-7891

A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special …

Mitigation only
Fix from $2,300 2026-05-07