Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openexr CRITICAL 9.8
CVE-2026-42217

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From…

Fix: 3.2.9 / 3.3.11+
Fix from $2,300 2026-05-07
Openexr CRITICAL 9.1
CVE-2026-42216

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From…

Fix: 3.2.9 / 3.3.11+
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.4
CVE-2026-41203

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Mitigation only
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.4
CVE-2026-41202

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Mitigation only
Fix from $2,300 2026-05-07
Unclassified CRITICAL 9.1
CVE-2026-41201

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In vers…

Mitigation only
Fix from $2,300 2026-05-07
Spring Cloud Config CRITICAL 9.1
CVE-2026-40982

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or …

Fix: 3.1.14 / 4.1.10+
Fix from $2,300 2026-05-07
Tor CRITICAL 9.1
CVE-2026-44597

Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.

Fix: 0.4.9.7+
Fix from $2,300 2026-05-07
Gotenberg CRITICAL 9.1
CVE-2026-40281

Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for co…

Fix: 8.31.0+
Fix from $2,300 2026-05-06
Openclaw CRITICAL 9.6
CVE-2026-44112

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirec…

Fix: 2026.4.22+
Fix from $2,300 2026-05-06
Openclaw CRITICAL 9.8
CVE-2026-44109

OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated re…

Fix: 2026.4.15+
Fix from $2,300 2026-05-06
Openclaw CRITICAL 9.8
CVE-2026-43585

OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. G…

Fix: 2026.4.15+
Fix from $2,300 2026-05-06
Openclaw CRITICAL 9.6
CVE-2026-43581

OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol o…

Fix: 2026.4.10+
Fix from $2,300 2026-05-06
Openclaw CRITICAL 9.1
CVE-2026-43578

OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local back…

Fix: 2026.4.10+
Fix from $2,300 2026-05-06
Openclaw CRITICAL 9.8
CVE-2026-43575

OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactiv…

Fix: 2026.4.10+
Fix from $2,300 2026-05-06
Chrome CRITICAL 9.6
CVE-2026-7910

Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site iso…

Fix: 148.0.7778.96+
Fix from $2,300 2026-05-06
Chrome CRITICAL 9.6
CVE-2026-7908

Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Fix: 148.0.7778.96+
Fix from $2,300 2026-05-06
Unclassified CRITICAL 9.8
CVE-2026-41930

Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthentica…

Patch available
Fix from $2,300 2026-05-06
Pan Os CRITICAL 9.8
CVE-2026-0300 KEVEPSS 32%

A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an un…

Mitigation only
Fix from $2,300 2026-05-06
Apache\ CRITICAL 9.1
CVE-2026-5081

Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (ad…

Fix: after 1.94
Fix from $2,300 2026-05-06
Linux Kernel CRITICAL 9.8
CVE-2026-43208

In the Linux kernel, the following vulnerability has been resolved: net: do not pass flow_id to set_rps_cpu() Blamed commit made the assumption tha…

Fix: 6.18.16 / 6.19.6+
Fix from $2,300 2026-05-06
Linux Kernel CRITICAL 9.1
CVE-2026-43197

In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole…

Fix: 6.18.16 / 6.19.6+
Fix from $2,300 2026-05-06
Linux Kernel CRITICAL 9.8
CVE-2026-43198

In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock(…

Fix: 6.18.16 / 6.19.6+
Fix from $2,300 2026-05-06
Linux Kernel CRITICAL 9.8
CVE-2026-43186

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receiv…

Fix: 5.15.202 / 6.1.165+
Fix from $2,300 2026-05-06
Linux Kernel CRITICAL 9.8
CVE-2026-43185

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() smb_direct_prep…

Fix: 6.18.16 / 6.19.6+
Fix from $2,300 2026-05-06
Linux Kernel CRITICAL 9.8
CVE-2026-43125

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_n…

Fix: 6.12.75 / 6.18.16+
Fix from $2,300 2026-05-06
Dfxanalytics CRITICAL 9.1
CVE-2025-59852

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encrypt…

Fix: 4.1+
Fix from $2,300 2026-05-06
Dfxanalytics CRITICAL 9.8
CVE-2025-59851

HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-componen…

Fix: 4.1+
Fix from $2,300 2026-05-06
Linux Kernel CRITICAL 9.1
CVE-2026-43117

In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file(…

Fix: 6.6.136 / 6.12.83+
Fix from $2,300 2026-05-06
Linux Kernel CRITICAL 9.4
CVE-2026-43114

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New t…

Fix: 6.6.136 / 6.12.83+
Fix from $2,300 2026-05-06
Linux Kernel CRITICAL 9.1
CVE-2026-43083

In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (tra…

Fix: 6.18.24 / 6.19.14+
Fix from $2,300 2026-05-06