Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

W30e Firmware CRITICAL 9.8
CVE-2026-38835

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName…

Mitigation only
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.3
CVE-2019-25714

Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to…

Mitigation only
Fix from $2,300 2026-04-21
Freescout CRITICAL 9.8
CVE-2026-40498

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system …

Fix: 1.8.213+
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.3
CVE-2025-41029

SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, create, update, and delete da…

Mitigation only
Fix from $2,300 2026-04-21
Net\ CRITICAL 10.0
CVE-2025-15638

Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dr…

Fix: 0.14+
Fix from $2,300 2026-04-21
Storable CRITICAL 10.0
CVE-2017-20230

Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer bu…

Fix: 3.05+
Fix from $2,300 2026-04-21
Firefox CRITICAL 9.8
CVE-2026-6771

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 1…

Fix: 140.10.0 / 150.0+
Fix from $2,300 2026-04-21
Firefox CRITICAL 9.8
CVE-2026-6768

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $2,300 2026-04-21
Firefox CRITICAL 9.8
CVE-2026-6760

Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $2,300 2026-04-21
Firefox CRITICAL 9.8
CVE-2026-6748

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and …

Fix: 140.10.0 / 150.0+
Fix from $2,300 2026-04-21
Unclassified CRITICAL 9.8
CVE-2026-5965

NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands an…

Mitigation only
Fix from $2,300 2026-04-21
Freescout CRITICAL 9.1
CVE-2026-40496

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and pre…

Fix: 1.8.213+
Fix from $2,300 2026-04-21
Claude Code CRITICAL 10.0
CVE-2026-39861

Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks poin…

Fix: 2.1.64+
Fix from $2,300 2026-04-21
Openclaw CRITICAL 9.9
CVE-2026-41329

OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and sen…

Fix: 2026.3.31+
Fix from $2,300 2026-04-21
Glibc CRITICAL 9.8
CVE-2026-5450

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width spec…

Fix: after 2.43
Fix from $2,300 2026-04-20
Roxy Wi CRITICAL 9.1
CVE-2026-33432

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authenticat…

Fix: after 8.2.8.2
Fix from $2,300 2026-04-20
Spinnaker CRITICAL 9.9
CVE-2026-32613

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to proce…

Fix: 2025.3.2 / 2025.4.2+
Fix from $2,300 2026-04-20
Spinnaker CRITICAL 9.9
CVE-2026-32604

Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor c…

Fix: 2025.3.2 / 2025.4.2+
Fix from $2,300 2026-04-20
Unclassified CRITICAL 9.8
CVE-2026-29646

In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enabl…

Patch available
Fix from $2,300 2026-04-20
Unclassified CRITICAL 9.1
CVE-2026-6257

Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file …

Patch available
Fix from $2,300 2026-04-20
Flowsint CRITICAL 9.8
CVE-2026-32311

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a u…

Patch available
Fix from $2,300 2026-04-20
Nemu CRITICAL 9.8
CVE-2026-29649

NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectly masked/…

Patch available
Fix from $2,300 2026-04-20
Unclassified CRITICAL 9.4
CVE-2026-39109

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the lo…

Mitigation only
Fix from $2,300 2026-04-20
Doorman CRITICAL 9.9
CVE-2026-30269

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role vi…

Mitigation only
Fix from $2,300 2026-04-20
Unclassified CRITICAL 9.8
CVE-2026-39918

Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized in…

Patch available
Fix from $2,300 2026-04-20
Openaev CRITICAL 9.8
CVE-2026-24467

OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in ve…

Fix: 2.0.13+
Fix from $2,300 2026-04-20
Sglang CRITICAL 9.8
CVE-2026-5760

SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is load…

Fix: 0.5.11+
Fix from $2,300 2026-04-20
Kafka CRITICAL 9.1
CVE-2026-33557

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set…

Fix: 4.1.2+
Fix from $2,300 2026-04-20
Easyflow .net CRITICAL 9.8
CVE-2026-5964

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to r…

Fix: after 6.6.17
Fix from $2,300 2026-04-20
Easyflow .net CRITICAL 9.8
CVE-2026-5963

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to r…

Fix: after 6.6.17
Fix from $2,300 2026-04-20