Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Master CRITICAL 9.1
CVE-2026-6644

A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrative user to break out of the r…

Fix: 4.3.3.RR42 / 5.1.2.reo1+
Fix from $2,300 2026-04-20
Data Master CRITICAL 9.9
CVE-2026-6643

A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unbounded sscanf() and passing u…

Fix: 4.3.3.RR42 / 5.1.2.reo1+
Fix from $2,300 2026-04-20
Sd 330ac Firmware CRITICAL 9.8
CVE-2026-32956

SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbit…

Fix: 1.50 / 5.1.0+
Fix from $2,300 2026-04-20
Protobufjs CRITICAL 9.8
CVE-2026-41242

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in…

Fix: 7.5.5+
Fix from $2,300 2026-04-18
Unclassified CRITICAL 9.8
CVE-2026-40494

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 45d48d1f2e8e0d…

Patch available
Fix from $2,300 2026-04-18
Unclassified CRITICAL 9.8
CVE-2026-40493

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3f…

Patch available
Fix from $2,300 2026-04-18
Unclassified CRITICAL 9.8
CVE-2026-40492

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb…

Patch available
Fix from $2,300 2026-04-18
Postiz CRITICAL 9.0
CVE-2026-40487

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitr…

Fix: 2.21.6+
Fix from $2,300 2026-04-18
Novumos CRITICAL 9.0
CVE-2026-40572

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 use…

Fix: 0.24+
Fix from $2,300 2026-04-18
Novumos CRITICAL 9.3
CVE-2026-40317

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary …

Fix: 0.24+
Fix from $2,300 2026-04-18
Unclassified CRITICAL 9.1
CVE-2026-40582

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and…

Patch available
Fix from $2,300 2026-04-18
Unclassified CRITICAL 9.1
CVE-2026-40484

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive…

Patch available
Fix from $2,300 2026-04-18
Unclassified CRITICAL 9.1
CVE-2026-40324

Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Ut…

Patch available
Fix from $2,300 2026-04-18
Miniupnpd CRITICAL 9.1
CVE-2026-5720

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or infor…

Fix: 2.3.10+
Fix from $2,300 2026-04-17
Thymeleaf CRITICAL 9.0
CVE-2026-40478

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulne…

Fix: 3.1.4+
Fix from $2,300 2026-04-17
Thymeleaf CRITICAL 9.0
CVE-2026-40477

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulne…

Fix: 3.1.4+
Fix from $2,300 2026-04-17
Fastgpt CRITICAL 9.8
CVE-2026-40351

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without run…

Fix: 4.14.9.5+
Fix from $2,300 2026-04-17
Unclassified CRITICAL 9.1
CVE-2026-40258

The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerabil…

Patch available
Fix from $2,300 2026-04-17
Libcoap CRITICAL 9.8
CVE-2026-29013

libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c reli…

Fix: 4.3.5b+
Fix from $2,300 2026-04-17
Xrdp CRITICAL 9.1
CVE-2026-33689

xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing log…

Fix: 0.10.6+
Fix from $2,300 2026-04-17
Dolibarr Erp\/crm CRITICAL 9.1
CVE-2026-23500

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT …

Fix: 23.0.0+
Fix from $2,300 2026-04-17
Firebird CRITICAL 9.9
CVE-2026-40342

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader con…

Fix: 3.0.14 / 4.0.7+
Fix from $2,300 2026-04-17
Cx7 Firmware CRITICAL 9.8
CVE-2026-35546

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant …

Mitigation only
Fix from $2,300 2026-04-17
Xrdp CRITICAL 9.1
CVE-2026-33516

xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capability exchange phase. The …

Fix: 0.10.6+
Fix from $2,300 2026-04-17
Openviking CRITICAL 9.1
CVE-2026-40525

OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authenticatio…

Fix: 0.3.9+
Fix from $2,300 2026-04-17
Deerflow CRITICAL 9.1
CVE-2026-40518

ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation whe…

Patch available
Fix from $2,300 2026-04-17
Unclassified CRITICAL 9.1
CVE-2026-6284

An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited…

Mitigation only
Fix from $2,300 2026-04-17
Junie CRITICAL 9.8
CVE-2026-41153

In JetBrains Junie before 252.549.29 command execution was possible via malicious project file

Fix: 252.549.29+
Fix from $2,300 2026-04-17
Unclassified CRITICAL 9.8
CVE-2026-37749

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication …

Mitigation only
Fix from $2,300 2026-04-17
Pro Cloud Server CRITICAL 9.8
CVE-2025-15625

Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

Mitigation only
Fix from $2,300 2026-04-17