Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Linux Kernel CRITICAL 9.8
CVE-2026-31436

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() …

Fix: 6.12.80 / 6.18.21+
Fix from $2,300 2026-04-22
Unclassified CRITICAL 9.8
CVE-2026-6235

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up …

Mitigation only
Fix from $2,300 2026-04-22
Unclassified CRITICAL 9.1
CVE-2026-4119

The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin…

Mitigation only
Fix from $2,300 2026-04-22
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2026-6023

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when resto…

Fix: 2026.1.421+
Fix from $2,300 2026-04-22
Avideo CRITICAL 9.8
CVE-2026-41304

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shel…

Fix: after 29.0
Fix from $2,300 2026-04-22
Fprime CRITICAL 9.8
CVE-2026-41144

F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, …

Patch available
Fix from $2,300 2026-04-22
Avideo CRITICAL 9.3
CVE-2026-41064

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` f…

Fix: after 29.0
Fix from $2,300 2026-04-22
Oauth2 Proxy CRITICAL 9.1
CVE-2026-40575

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-For…

Fix: 7.15.2+
Fix from $2,300 2026-04-22
Enterprise Server CRITICAL 9.6
CVE-2026-5845

An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attac…

Fix: 3.14.26 / 3.15.21+
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.2
CVE-2026-40946

Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in t…

Mitigation only
Fix from $2,300 2026-04-21
Flowise CRITICAL 9.9
CVE-2026-40933EPSS 13%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio command…

Fix: 3.1.0+
Fix from $2,300 2026-04-21
Avideo CRITICAL 10.0
CVE-2026-40911

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON messa…

Fix: after 29.0
Fix from $2,300 2026-04-21
Frp CRITICAL 9.1
CVE-2026-40910

frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used…

Fix: 0.68.1+
Fix from $2,300 2026-04-21
Pjsip CRITICAL 9.8
CVE-2026-40892

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_crea…

Fix: 2.17+
Fix from $2,300 2026-04-21
Identity Manager Connector CRITICAL 9.1
CVE-2026-34287

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…

Mitigation only
Fix from $2,300 2026-04-21
Identity Manager Connector CRITICAL 9.1
CVE-2026-34286

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…

Mitigation only
Fix from $2,300 2026-04-21
Identity Manager Connector CRITICAL 9.1
CVE-2026-34285

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…

Mitigation only
Fix from $2,300 2026-04-21
Enterprise Manager Base Platform CRITICAL 9.1
CVE-2026-34279

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions …

Mitigation only
Fix from $2,300 2026-04-21
Advanced Inbound Telephony CRITICAL 9.8
CVE-2026-34275

Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions …

Fix: after 12.2.15
Fix from $2,300 2026-04-21
Portal For Arcgis CRITICAL 9.8
CVE-2026-33519

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly…

Mitigation only
Fix from $2,300 2026-04-21
Goshs CRITICAL 9.1
CVE-2026-40903

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB…

Fix: 2.0.0+
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.1
CVE-2026-40887

Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL…

Mitigation only
Fix from $2,300 2026-04-21
Goshs CRITICAL 9.8
CVE-2026-40884

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username bas…

Fix: 2.0.0+
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.3
CVE-2026-40872

mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover logs r…

Mitigation only
Fix from $2,300 2026-04-21
Asp.net Core CRITICAL 9.1
CVE-2026-40372EPSS 11%

Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

Fix: 10.0.7+
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.1
CVE-2026-41193

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives…

Patch available
Fix from $2,300 2026-04-21
Crafty Controller CRITICAL 9.0
CVE-2026-5652

An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform …

Fix: 4.10.4+
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.4
CVE-2026-40576

excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions u…

Mitigation only
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.0
CVE-2026-40569

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connectio…

Patch available
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.8
CVE-2026-40050

CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulne…

Mitigation only
Fix from $2,300 2026-04-21