Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mina CRITICAL 9.8
CVE-2026-42779

The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's Abstrac…

Fix: 2.1.12 / 2.2.7+
Fix from $2,300 2026-05-01
Mina CRITICAL 9.8
CVE-2026-42778

The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 i…

Fix: 2.1.12 / 2.2.7+
Fix from $2,300 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-7567EPSS 9%

The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input …

Mitigation only
Fix from $2,300 2026-05-01
Unclassified CRITICAL 10.0
CVE-2026-42996

JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long …

Patch available
Fix from $2,300 2026-05-01
Cli CRITICAL 9.8
CVE-2026-42994

Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkma…

Mitigation only
Fix from $2,300 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-7546

A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the compon…

Mitigation only
Fix from $2,300 2026-05-01
Unclassified CRITICAL 9.8
CVE-2026-7538

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of the file /cgi-bin/cstecgi.cg…

Mitigation only
Fix from $2,300 2026-05-01
Exim CRITICAL 9.1
CVE-2026-40687

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes …

Fix: 4.99.2+
Fix from $2,300 2026-04-30
Exim CRITICAL 9.8
CVE-2026-40685

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrus…

Fix: 4.99.2+
Fix from $2,300 2026-04-30
I CRITICAL 9.8
CVE-2026-2311

IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI authorization check.  A mali…

Mitigation only
Fix from $2,300 2026-04-30
Traefik CRITICAL 10.0
CVE-2026-39858

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass…

Fix: 2.11.43 / 3.6.14+
Fix from $2,300 2026-04-30
Traefik CRITICAL 10.0
CVE-2026-35051

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerabilit…

Fix: 2.11.43 / 3.6.14+
Fix from $2,300 2026-04-30
Secure Access CRITICAL 9.8
CVE-2026-33447

CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified …

Fix: 14.50+
Fix from $2,300 2026-04-30
Secure Access CRITICAL 9.8
CVE-2026-33446

CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attackers with control of a modifi…

Fix: 14.50+
Fix from $2,300 2026-04-30
Openshift Container Platform CRITICAL 9.1
CVE-2026-33845

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reass…

Mitigation only
Fix from $2,300 2026-04-30
Unclassified CRITICAL 10.0
CVE-2026-36767

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path vi…

Mitigation only
Fix from $2,300 2026-04-30
Unclassified CRITICAL 9.6
CVE-2026-36760

An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to ex…

Mitigation only
Fix from $2,300 2026-04-30
Smg Gateway Management Software CRITICAL 9.8
CVE-2025-71284EPSS 6%

Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where…

Mitigation only
Fix from $2,300 2026-04-30
Unclassified CRITICAL 9.8
CVE-2022-50993

Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpo…

Mitigation only
Fix from $2,300 2026-04-30
Moveit Automation CRITICAL 9.8
CVE-2026-4670EPSS 6%

Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVE…

Fix: 2024.1.8 / 2025.1.5+
Fix from $2,300 2026-04-30
Connext Professional CRITICAL 9.1
CVE-2025-14543

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Link…

Fix: 7.3.1.1 / 7.7.0+
Fix from $2,300 2026-04-30
Asr1803 Firmware CRITICAL 9.8
CVE-2026-42799

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/N…

Fix: 1.216.002+
Fix from $2,300 2026-04-30
Coloros Assistant CRITICAL 9.8
CVE-2026-22070

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

Mitigation only
Fix from $2,300 2026-04-30
Django Mdeditor CRITICAL 9.8
CVE-2025-13030

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker …

Patch available
Fix from $2,300 2026-04-30
Plack\ CRITICAL 9.1
CVE-2026-7381

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the va…

Fix: after 1.0053
Fix from $2,300 2026-04-29
Fh303 Firmware CRITICAL 9.8
CVE-2018-25318

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by explo…

Mitigation only
Fix from $2,300 2026-04-29
W309r Firmware CRITICAL 9.8
CVE-2018-25317

Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to…

Mitigation only
Fix from $2,300 2026-04-29
W308r Firmware CRITICAL 9.8
CVE-2018-25316

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting i…

Mitigation only
Fix from $2,300 2026-04-29
Wazuh CRITICAL 9.9
CVE-2026-30893

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path tra…

Fix: 4.14.4+
Fix from $2,300 2026-04-29
Docsgpt CRITICAL 9.8
CVE-2026-26015

DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT websit…

Mitigation only
Fix from $2,300 2026-04-29