Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-7037

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstec…

Mitigation only
Fix from $2,300 2026-04-26
I9 Firmware CRITICAL 9.8
CVE-2026-7036

A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP…

Mitigation only
Fix from $2,300 2026-04-26
Picoclaw CRITICAL 9.8
CVE-2026-6987

A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher …

Fix: after 0.2.4
Fix from $2,300 2026-04-25
Linux Kernel CRITICAL 9.4
CVE-2026-31685

In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` …

Fix: 6.6.136 / 6.12.83+
Fix from $2,300 2026-04-25
Linux Kernel CRITICAL 9.1
CVE-2026-31682

In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-04-25
Simple Git CRITICAL 9.8
CVE-2026-6951

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://…

Fix: 3.36.0+
Fix from $2,300 2026-04-25
Saltcorn CRITICAL 9.9
CVE-2026-41478

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability …

Fix: 1.4.6 / 1.5.6+
Fix from $2,300 2026-04-24
Cyberpanel CRITICAL 9.1
CVE-2026-41473

CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated …

Fix: 2.4.4+
Fix from $2,300 2026-04-24
Unclassified CRITICAL 9.1
CVE-2026-41248

Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro c…

Mitigation only
Fix from $2,300 2026-04-24
Bacnet Stack CRITICAL 9.1
CVE-2026-41475

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-sta…

Fix: 1.4.3+
Fix from $2,300 2026-04-24
Budibase CRITICAL 9.1
CVE-2026-41428

Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-a…

Fix: 3.35.4+
Fix from $2,300 2026-04-24
Dgraph CRITICAL 9.8
CVE-2026-41492

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/v…

Fix: 25.3.3+
Fix from $2,300 2026-04-24
Pjsip CRITICAL 9.1
CVE-2026-41415

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a mal…

Fix: 2.17+
Fix from $2,300 2026-04-24
Dgraph CRITICAL 9.1
CVE-2026-41328

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attack…

Fix: 25.3.3+
Fix from $2,300 2026-04-24
Dgraph CRITICAL 9.1
CVE-2026-41327

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attack…

Fix: 25.3.3+
Fix from $2,300 2026-04-24
Axios CRITICAL 10.0
CVE-2026-42043

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axio…

Fix: 0.31.1 / 1.15.1+
Fix from $2,300 2026-04-24
Axios CRITICAL 9.1
CVE-2026-42044

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollutio…

Fix: 1.15.1+
Fix from $2,300 2026-04-24
Rust Openssl CRITICAL 9.1
CVE-2026-41677

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validat…

Fix: 0.10.78+
Fix from $2,300 2026-04-24
Unclassified CRITICAL 9.8
CVE-2026-6911

Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to…

Patch available
Fix from $2,300 2026-04-24
Unclassified CRITICAL 9.8
CVE-2026-39920

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints wit…

Mitigation only
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31669

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table loo…

Fix: 5.15.203 / 6.1.169+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31668

In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths in seg6 lwtunnel The seg6 l…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31659

In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buffers batadv_tt_prepare_tvlv_…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31657

In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() ca…

Fix: 6.1.169 / 6.6.135+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31649

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode imp…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31637

In the Linux kernel, the following vulnerability has been resolved: rxrpc: reject undecryptable rxkad response tickets rxkad_decrypt_ticket() decry…

Fix: 6.6.135 / 6.12.82+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.1
CVE-2026-31636

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read rxgk_verify_authenticator() c…

Fix: 6.18.23 / 6.19.13+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31633

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In rxgk_verify_response()…

Fix: 6.18.23 / 6.19.13+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31609

In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flus…

Fix: 6.18.24 / 6.19.14+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31608

In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush…

Fix: 6.18.24 / 6.19.14+
Fix from $2,300 2026-04-24