Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rust Openssl CRITICAL 9.1
CVE-2026-41677

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validat…

Fix: 0.10.78+
Fix from $2,300 2026-04-24
Unclassified CRITICAL 9.8
CVE-2026-6911

Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to…

Patch available
Fix from $2,300 2026-04-24
Unclassified CRITICAL 9.8
CVE-2026-39920

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints wit…

Mitigation only
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31669

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table loo…

Fix: 5.15.203 / 6.1.169+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31668

In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths in seg6 lwtunnel The seg6 l…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31659

In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buffers batadv_tt_prepare_tvlv_…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31657

In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() ca…

Fix: 6.1.169 / 6.6.135+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31649

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode imp…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31637

In the Linux kernel, the following vulnerability has been resolved: rxrpc: reject undecryptable rxkad response tickets rxkad_decrypt_ticket() decry…

Fix: 6.6.135 / 6.12.82+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.1
CVE-2026-31636

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read rxgk_verify_authenticator() c…

Fix: 6.18.23 / 6.19.13+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31633

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In rxgk_verify_response()…

Fix: 6.18.23 / 6.19.13+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31609

In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flus…

Fix: 6.18.24 / 6.19.14+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31608

In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush…

Fix: 6.18.24 / 6.19.14+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31607

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP clie…

Fix: 6.6.136 / 6.12.83+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31589

In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directly in folio_unmap_invalidate() We can only call f…

Fix: 6.19.14 / 7.0.1+
Fix from $2,300 2026-04-24
Linux Kernel CRITICAL 9.8
CVE-2026-31536

In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion without IB_SEND_SIGNALED With sm…

Fix: 6.18.11 / 6.19.1+
Fix from $2,300 2026-04-24
Codechecker CRITICAL 9.8
CVE-2026-25660

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs …

Fix: 6.27.4+
Fix from $2,300 2026-04-24
Azure Iot Central CRITICAL 9.9
CVE-2026-21515

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-24
As320t Firmware CRITICAL 9.8
CVE-2026-1951

Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.

Fix: 1.12+
Fix from $2,300 2026-04-24
As320t Firmware CRITICAL 9.8
CVE-2026-1950

Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.

Fix: 1.16+
Fix from $2,300 2026-04-24
As320t Firmware CRITICAL 9.8
CVE-2026-1949

Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.

Fix: 1.16+
Fix from $2,300 2026-04-24
Kyverno CRITICAL 9.1
CVE-2026-41323

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiC…

Fix: 1.16.4 / 1.17.2+
Fix from $2,300 2026-04-24
Roxy Wi CRITICAL 9.8
CVE-2026-33078

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability i…

Fix: 8.2.6.4+
Fix from $2,300 2026-04-24
Roxy Wi CRITICAL 9.8
CVE-2026-33076

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p…

Fix: 8.2.6.4+
Fix from $2,300 2026-04-24
X3500 Firmware CRITICAL 9.8
CVE-2026-40630

A vulnerability in  SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access…

Mitigation only
Fix from $2,300 2026-04-24
X3500 Firmware CRITICAL 9.8
CVE-2026-40620

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authenticat…

Mitigation only
Fix from $2,300 2026-04-24
X3500 Firmware CRITICAL 9.8
CVE-2026-35503

A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on har…

Mitigation only
Fix from $2,300 2026-04-24
X3500 Firmware CRITICAL 9.1
CVE-2026-27843

A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient …

Mitigation only
Fix from $2,300 2026-04-24
Unclassified CRITICAL 9.8
CVE-2026-25775

A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication…

Mitigation only
Fix from $2,300 2026-04-24
Flowise CRITICAL 9.8
CVE-2026-41274

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-pr…

Fix: 3.1.0+
Fix from $2,300 2026-04-23