Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.6
CVE-2026-5166

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institu…

Mitigation only
Fix from $2,300 2026-04-29
Wp Squared CRITICAL 9.8
CVE-2026-41940 KEVEPSS 99%

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to …

Fix: 86.0.41 / 110.0.97+
Fix from $2,300 2026-04-29
Unclassified CRITICAL 9.8
CVE-2026-38992

Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows a…

Mitigation only
Fix from $2,300 2026-04-29
Unclassified CRITICAL 9.8
CVE-2026-36841

TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function.

Mitigation only
Fix from $2,300 2026-04-29
GitHub CRITICAL 9.0
CVE-2026-42523

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHu…

Fix: 1.46.0.1+
Fix from $2,300 2026-04-29
Ollama CRITICAL 9.8
CVE-2026-42249

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP respon…

Fix: after 0.17.5
Fix from $2,300 2026-04-29
Ollama CRITICAL 9.8
CVE-2026-42248

Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows impl…

Fix: after 0.17.5
Fix from $2,300 2026-04-29
Unclassified CRITICAL 10.0
CVE-2026-3325

SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The v…

Mitigation only
Fix from $2,300 2026-04-29
Chrome CRITICAL 9.6
CVE-2026-7333

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML p…

Fix: 147.0.7727.138+
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.8
CVE-2026-41446

Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MA…

Mitigation only
Fix from $2,300 2026-04-28
Openclaw CRITICAL 9.6
CVE-2026-41397

OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation du…

Fix: 2026.3.31+
Fix from $2,300 2026-04-28
Openclaw CRITICAL 9.8
CVE-2026-41386

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes…

Fix: 2026.3.22+
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.4
CVE-2026-3893

The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its con…

Mitigation only
Fix from $2,300 2026-04-28
Nvflare CRITICAL 9.8
CVE-2026-24178

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause author…

Fix: 2.7.2+
Fix from $2,300 2026-04-28
Pony Mail CRITICAL 9.8
CVE-2026-41873

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading t…

Mitigation only
Fix from $2,300 2026-04-28
Hpx CRITICAL 9.8
CVE-2025-60889

Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or othe…

Fix: after 1.11.0
Fix from $2,300 2026-04-28
Firefox CRITICAL 9.6
CVE-2026-7321

Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150…

Fix: 140.10.1 / 150.0+
Fix from $2,300 2026-04-28
Di 8100 Firmware CRITICAL 9.4
CVE-2026-7248

A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. Th…

No fix yet
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.8
CVE-2026-7244

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cg…

Mitigation only
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.8
CVE-2026-7243

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.8
CVE-2026-7242

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi…

Mitigation only
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.8
CVE-2026-7241

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi o…

Mitigation only
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.8
CVE-2026-7240

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAccountCfg of the file /cgi-bin…

Mitigation only
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.8
CVE-2026-7204

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi…

Mitigation only
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.8
CVE-2026-7203

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cst…

Mitigation only
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.8
CVE-2026-7202

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of…

Mitigation only
Fix from $2,300 2026-04-28
Unclassified CRITICAL 9.8
CVE-2026-32644

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

Mitigation only
Fix from $2,300 2026-04-28
Spring Boot CRITICAL 9.1
CVE-2026-40976

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be v…

Fix: 4.0.6+
Fix from $2,300 2026-04-28
Spring Boot CRITICAL 9.8
CVE-2026-40974

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring…

Fix: 2.7.33 / 3.3.19+
Fix from $2,300 2026-04-28
Spring Boot CRITICAL 9.1
CVE-2026-40971

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitM…

Fix: 3.5.14 / 4.0.6+
Fix from $2,300 2026-04-27