Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-5722

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the gues…

Mitigation only
Fix from $2,300 2026-05-05
Nginx Ui CRITICAL 9.8
CVE-2026-42238

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) tha…

Fix: 2.3.8+
Fix from $2,300 2026-05-04
Nginx Ui CRITICAL 9.8
CVE-2026-42222

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the init…

Mitigation only
Fix from $2,300 2026-05-04
Nginx Ui CRITICAL 9.8
CVE-2026-42221

Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim …

Fix: 2.3.8+
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2026-41926

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cgi binary across five request …

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2026-41925

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function th…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2026-41924

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unaut…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2026-41923

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthen…

Mitigation only
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2026-41922

WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that allows unauthen…

Mitigation only
Fix from $2,300 2026-05-04
N8n CRITICAL 9.6
CVE-2026-42235

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a mali…

Fix: 1.123.32 / 2.17.4+
Fix from $2,300 2026-05-04
N8n CRITICAL 9.8
CVE-2026-42233

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select opera…

Fix: 1.123.32 / 2.17.4+
Fix from $2,300 2026-05-04
Arelle CRITICAL 9.8
CVE-2026-42796

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins que…

Fix: 2.39.10+
Fix from $2,300 2026-05-04
Cosmos CRITICAL 9.6
CVE-2026-42087

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before …

Fix: 7.0.0+
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.4
CVE-2026-41571

Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("nu…

Mitigation only
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42812

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42811

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or tabl…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42810

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table acc…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Polaris CRITICAL 9.9
CVE-2026-42809

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val…

Fix: 1.4.1+
Fix from $2,300 2026-05-04
Dir 456u Firmware CRITICAL 9.8
CVE-2026-42376

D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init…

Mitigation only
Fix from $2,300 2026-05-04
Notesnook Desktop CRITICAL 9.6
CVE-2026-42090

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Androi…

Fix: 3.3.15 / 3.3.20+
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.8
CVE-2026-42076

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function…

Mitigation only
Fix from $2,300 2026-05-04
Opennlp CRITICAL 9.8
CVE-2026-42027

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M…

Fix: 2.5.9+
Fix from $2,300 2026-05-04
Opennlp CRITICAL 9.1
CVE-2026-40682

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0…

Fix: 2.5.9+
Fix from $2,300 2026-05-04
Vm2 CRITICAL 9.8
CVE-2026-26956

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker cod…

Fix: 3.10.5+
Fix from $2,300 2026-05-04
Vm2 CRITICAL 10.0
CVE-2026-26332

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code.…

Fix: 3.11.0+
Fix from $2,300 2026-05-04
Qca7005 Firmware CRITICAL 9.8
CVE-2026-25293

Buffer overflow due to incorrect authorization in PLC FW

No fix yet
Fix from $2,300 2026-05-04
Vm2 CRITICAL 9.8
CVE-2026-24120

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing at…

Fix: 3.10.5+
Fix from $2,300 2026-05-04
Vm2 CRITICAL 9.8
CVE-2026-24118

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to wr…

Fix: 3.11.0+
Fix from $2,300 2026-05-04
Vm2 CRITICAL 9.8
CVE-2026-24781

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function…

Fix: 3.11.0+
Fix from $2,300 2026-05-04
Unclassified CRITICAL 9.3
CVE-2025-13605

3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands …

Mitigation only
Fix from $2,300 2026-05-04