Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Entra Id CRITICAL 10.0
CVE-2026-35431

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

Mitigation only
Fix from $2,300 2026-04-23
Bing CRITICAL 9.8
CVE-2026-33819

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

Mitigation only
Fix from $2,300 2026-04-23
365 Copilot CRITICAL 9.3
CVE-2026-33102

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Ktransformers CRITICAL 9.8
CVE-2026-26210

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a…

Fix: after 0.5.3
Fix from $2,300 2026-04-23
Purview Ediscovery CRITICAL 10.0
CVE-2026-26150

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-23
Partner Center CRITICAL 9.6
CVE-2026-24303

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41276EPSS 7%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers t…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41268EPSS 14%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41267

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41265

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41264

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Lerobot CRITICAL 9.8
CVE-2026-25874EPSS 16%

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize da…

Fix: after 0.5.1
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.8
CVE-2026-6074

Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debu…

Mitigation only
Fix from $2,300 2026-04-23
Elfinder CRITICAL 9.8
CVE-2026-41247

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulner…

Fix: 2.1.67+
Fix from $2,300 2026-04-23
Chrome CRITICAL 9.6
CVE-2026-6920

Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to p…

Fix: 147.0.7727.116+
Fix from $2,300 2026-04-23
Chrome CRITICAL 9.6
CVE-2026-6919

Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially…

Fix: 147.0.7727.116+
Fix from $2,300 2026-04-23
Linux Kernel CRITICAL 9.8
CVE-2026-31533

In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUS…

Fix: 5.15.203 / 6.1.169+
Fix from $2,300 2026-04-23
A3300r Firmware CRITICAL 9.8
CVE-2026-31181

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr p…

Mitigation only
Fix from $2,300 2026-04-23
A3300r Firmware CRITICAL 9.8
CVE-2026-31178

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive par…

Mitigation only
Fix from $2,300 2026-04-23
A3300r Firmware CRITICAL 9.8
CVE-2026-31177

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive par…

Mitigation only
Fix from $2,300 2026-04-23
A3300r Firmware CRITICAL 9.8
CVE-2026-31175

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable param…

Mitigation only
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.9
CVE-2026-40472

In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cro…

Mitigation only
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.6
CVE-2026-40471

hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage s…

Mitigation only
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.9
CVE-2026-40470

A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the docum…

Mitigation only
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.8
CVE-2026-23751

Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel …

Mitigation only
Fix from $2,300 2026-04-23
Pipecat CRITICAL 9.8
CVE-2025-62373

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a v…

Fix: 0.0.94+
Fix from $2,300 2026-04-23
Jizhicms CRITICAL 9.8
CVE-2025-50229

Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.

Mitigation only
Fix from $2,300 2026-04-23
Socialengine CRITICAL 9.8
CVE-2026-41460

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input p…

Fix: after 7.8.0
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.9
CVE-2026-39440

Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue aff…

Mitigation only
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.8
CVE-2026-6887

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attac…

Mitigation only
Fix from $2,300 2026-04-23