Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Azure Ai Foundry CRITICAL 10.0
CVE-2026-35435

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Cloud Shell CRITICAL 9.6
CVE-2026-35428

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s…

Mitigation only
Fix from $2,300 2026-05-07
Azure Managed Instance For Apache Cassandra CRITICAL 9.0
CVE-2026-33844

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-07
Azure Managed Instance For Apache Cassandra CRITICAL 9.9
CVE-2026-33109

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-05-07
I18next Http Backend CRITICAL 9.1
CVE-2026-41691

Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag…

Fix: 3.0.5+
Fix from $2,300 2026-05-07
Gitpython CRITICAL 9.8
CVE-2026-42284

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list,…

Fix: 3.1.47+
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.1
CVE-2026-41902

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts …

Mitigation only
Fix from $2,300 2026-05-07
Snipe It CRITICAL 9.8
CVE-2026-37709

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to …

Fix: 8.4.1+
Fix from $2,300 2026-05-07
Lawn Mower Firmware CRITICAL 9.8
CVE-2026-7415

The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on th…

Mitigation only
Fix from $2,300 2026-05-07
Lawn Mower Firmware CRITICAL 9.8
CVE-2026-7414

Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all device…

Mitigation only
Fix from $2,300 2026-05-07
Lawn Mower Firmware CRITICAL 9.8
CVE-2026-7413

A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged…

Mitigation only
Fix from $2,300 2026-05-07
Endpoint Manager Mobile CRITICAL 9.1
CVE-2026-7821

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a …

Fix: 12.6.1.1+
Fix from $2,300 2026-05-07
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-5788

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitra…

Fix: 12.6.1.1+
Fix from $2,300 2026-05-07
Endpoint Manager Mobile CRITICAL 9.1
CVE-2026-5787

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impers…

Fix: 12.6.1.1+
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.8
CVE-2025-63704

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and…

Mitigation only
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.8
CVE-2025-63703

npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().

Mitigation only
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.8
CVE-2026-36458

ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injec…

Mitigation only
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.8
CVE-2025-63706

NPM package next-npm-version1.0.1 is vulnerable to Command injection.

Mitigation only
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.6
CVE-2026-6795

URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. …

Mitigation only
Fix from $2,300 2026-05-07
Wish CRITICAL 9.6
CVE-2026-41589

Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wis…

No fix yet
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.8
CVE-2026-30496

The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated …

Mitigation only
Fix from $2,300 2026-05-07
Firefox CRITICAL 9.8
CVE-2026-8094

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

Fix: 140.10.2+
Fix from $2,300 2026-05-07
Firefox CRITICAL 9.8
CVE-2026-8091

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.1…

Fix: 115.35.2 / 140.10.1+
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.8
CVE-2026-6508

Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Proper…

Mitigation only
Fix from $2,300 2026-05-07
Hardened Images CRITICAL 9.8
CVE-2026-42010

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch…

Mitigation only
Fix from $2,300 2026-05-07
Open Notebook CRITICAL 10.0
CVE-2026-33587

Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the dock…

Fix: 1.8.4+
Fix from $2,300 2026-05-07
Virtual Storage One Block CRITICAL 9.8
CVE-2025-1978

Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G3…

Mitigation only
Fix from $2,300 2026-05-07
Virtual Storage One Block CRITICAL 9.8
CVE-2025-9661

OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This…

Mitigation only
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.3
CVE-2026-41586

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to…

Mitigation only
Fix from $2,300 2026-05-07
Tor CRITICAL 9.1
CVE-2026-44603

Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.

Fix: 0.4.9.7+
Fix from $2,300 2026-05-07