Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wicket CRITICAL 9.1
CVE-2026-40010

Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache …

Fix: 10.9.0+
Fix from $2,300 2026-05-06
HTTP Server CRITICAL 9.8
CVE-2026-28780

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server …

Fix: 2.4.67+
Fix from $2,300 2026-05-05
Coredns CRITICAL 9.8
CVE-2026-35579

CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG a…

Fix: 1.14.3+
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.3
CVE-2026-40331

Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.3
CVE-2026-40330

Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.3
CVE-2026-40329

Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc compone…

Mitigation only
Fix from $2,300 2026-05-05
Phpspreadsheet CRITICAL 9.8
CVE-2026-34084

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3…

Fix: 1.30.3 / 2.1.15+
Fix from $2,300 2026-05-05
Di 8100 Firmware CRITICAL 9.8
CVE-2026-7854EPSS 6%

A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url…

Mitigation only
Fix from $2,300 2026-05-05
Kestra CRITICAL 9.8
CVE-2026-38428

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly conc…

Fix: 1.0.35 / 1.3.7+
Fix from $2,300 2026-05-05
Opencti CRITICAL 9.8
CVE-2026-27960

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a pri…

Fix: 6.9.13+
Fix from $2,300 2026-05-05
Di 8100 Firmware CRITICAL 9.8
CVE-2026-7853

A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Hand…

Mitigation only
Fix from $2,300 2026-05-05
Erpnext CRITICAL 9.8
CVE-2026-38431

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates ca…

Fix: after 15.103.1
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.8
CVE-2026-38429

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip fi…

Patch available
Fix from $2,300 2026-05-05
Unclassified CRITICAL 10.0
CVE-2026-7411

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticat…

Mitigation only
Fix from $2,300 2026-05-05
Linux Kernel CRITICAL 9.1
CVE-2026-43071

In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two There is an OOB read problem …

Fix: 3.11 / 3.13+
Fix from $2,300 2026-05-05
Linux Kernel CRITICAL 9.8
CVE-2026-43067

In the Linux kernel, the following vulnerability has been resolved: ext4: handle wraparound when searching for blocks for indirect mapped blocks Co…

Fix: 5.16 / 6.6.134+
Fix from $2,300 2026-05-05
Enterprise Linux CRITICAL 9.1
CVE-2026-34002

A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An a…

Mitigation only
Fix from $2,300 2026-05-05
Enterprise Linux CRITICAL 9.1
CVE-2026-34000

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.8
CVE-2026-7834

A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/m…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.1
CVE-2026-36356EPSS 14%

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via …

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.1
CVE-2026-34408

An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to se…

Mitigation only
Fix from $2,300 2026-05-05
Openclaw CRITICAL 9.8
CVE-2026-43566

OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake eve…

Fix: 2026.4.14+
Fix from $2,300 2026-05-05
Openclaw CRITICAL 9.8
CVE-2026-43534

OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Atta…

Fix: 2026.4.10+
Fix from $2,300 2026-05-05
Openclaw CRITICAL 9.3
CVE-2026-43526

OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that allows attackers to fetch arbit…

Fix: 2026.4.12+
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.8
CVE-2023-54344

Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary comm…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.8
CVE-2023-54342

Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated att…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.3
CVE-2026-40797

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQ…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.8
CVE-2026-7823

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cg…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.8
CVE-2026-5294

The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route…

Mitigation only
Fix from $2,300 2026-05-05
Unclassified CRITICAL 9.8
CVE-2025-13618

The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not p…

Mitigation only
Fix from $2,300 2026-05-05