Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-75843

ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated …

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-75837

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admi…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-75627

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication fil…

Patch available
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-75626

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject …

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-34884

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking M…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-15748

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-75094

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-67919

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginAppli…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-42164

Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to rec…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-42162

Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-38165

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers t…

Patch available
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67960

An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, C…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.6
CVE-2026-71424

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} end…

Patch available
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67868

A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67854

SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

No fix yet
Fix from $5,750 2026-08-17
Mlflow CRITICAL 9.3
CVE-2026-64849 KEVEPSS 8%

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated…

Fix: 3.15.0+
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-51977

An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-42163

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain c…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-75110

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, d…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-75106

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attack…

Patch available
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67967

Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-448…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67966

Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell acces…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67965

An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67926

An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67917

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` comma…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-66795

A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSR…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.9
CVE-2026-65974

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permissio…

Patch available
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-47698

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Funct…

Patch available
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.9
CVE-2026-47686

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedE…

Patch available
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-39255

Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_…

No fix yet
Fix from $5,750 2026-08-17