Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-6886

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remo…

Mitigation only
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.8
CVE-2026-6885

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated rem…

Mitigation only
Fix from $2,300 2026-04-23
H2o CRITICAL 9.8
CVE-2026-3960

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior…

Fix: 3.46.0.10+
Fix from $2,300 2026-04-23
Froxlor CRITICAL 9.1
CVE-2026-41229

Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quo…

Fix: 2.3.6+
Fix from $2,300 2026-04-23
Froxlor CRITICAL 9.9
CVE-2026-41228

Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does…

Fix: 2.3.6+
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.8
CVE-2026-3844EPSS 28%

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote'…

Mitigation only
Fix from $2,300 2026-04-23
Paperclipai CRITICAL 10.0
CVE-2026-41679

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated a…

Fix: 2026.416.0+
Fix from $2,300 2026-04-23
Vite\+ CRITICAL 10.0
CVE-2026-41211

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` …

Fix: 0.1.17+
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.3
CVE-2026-41197

Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode …

Mitigation only
Fix from $2,300 2026-04-23
Minetest CRITICAL 10.0
CVE-2026-41196

Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can…

Fix: 5.15.2+
Fix from $2,300 2026-04-23
Total Storage Service Console CRITICAL 9.8
CVE-2026-5935

IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma…

Mitigation only
Fix from $2,300 2026-04-23
Rclone CRITICAL 9.8
CVE-2026-41179EPSS 9%

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to…

Fix: 1.73.5+
Fix from $2,300 2026-04-23
Rclone CRITICAL 9.8
CVE-2026-41176EPSS 33%

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is expose…

Fix: 1.73.5+
Fix from $2,300 2026-04-23
Rocket.chat CRITICAL 9.8
CVE-2026-29198

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover o…

Fix: 7.10.9 / 7.11.6+
Fix from $2,300 2026-04-23
Unclassified CRITICAL 9.1
CVE-2026-41167

Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by in…

Patch available
Fix from $2,300 2026-04-22
Espocrm CRITICAL 9.1
CVE-2026-33656

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing …

Fix: 9.3.4+
Fix from $2,300 2026-04-22
Nimiq Proof Of Stake CRITICAL 9.6
CVE-2026-33471

nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len…

Fix: 1.3.0+
Fix from $2,300 2026-04-22
Unclassified CRITICAL 9.8
CVE-2026-34415

Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to…

Patch available
Fix from $2,300 2026-04-22
Powerprotect Dp Series Appliance CRITICAL 9.8
CVE-2026-26354

Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 t…

Fix: 2.7.9 / 7.13.1.60+
Fix from $2,300 2026-04-22
Ddev CRITICAL 9.1
CVE-2026-32885

DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction …

Fix: 1.25.2+
Fix from $2,300 2026-04-22
Unclassified CRITICAL 9.8
CVE-2018-25272

ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with S…

Mitigation only
Fix from $2,300 2026-04-22
Thinkphp CRITICAL 9.8
CVE-2018-25270

ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functi…

Fix: 5.0.23+
Fix from $2,300 2026-04-22
Augmentt CRITICAL 9.6
CVE-2026-6356

A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipul…

Fix: 2025-10-02+
Fix from $2,300 2026-04-22
Authoritative CRITICAL 9.8
CVE-2026-33608

An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its confi…

Fix: 4.9.14 / 5.0.4+
Fix from $2,300 2026-04-22
Dnsdist CRITICAL 9.1
CVE-2026-33598

A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet c…

Fix: 1.9.13 / 2.0.4+
Fix from $2,300 2026-04-22
Linux Kernel CRITICAL 9.8
CVE-2026-31501

In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path cppi5_h…

Fix: 6.19.11+
Fix from $2,300 2026-04-22
Linux Kernel CRITICAL 9.8
CVE-2026-31478

In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len()…

Fix: 5.15.203 / 6.1.168+
Fix from $2,300 2026-04-22
Linux Kernel CRITICAL 9.8
CVE-2026-31463

In the Linux kernel, the following vulnerability has been resolved: iomap: fix invalid folio access when i_blkbits differs from I/O granularity Com…

Fix: 6.19.11+
Fix from $2,300 2026-04-22
Linux Kernel CRITICAL 9.4
CVE-2026-31448

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, whe…

Fix: 6.1.168 / 6.6.131+
Fix from $2,300 2026-04-22
Linux Kernel CRITICAL 9.8
CVE-2026-31444

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() smb_grant_oplock…

Fix: 6.12.80 / 6.18.21+
Fix from $2,300 2026-04-22