Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-6443

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a ma…

Mitigation only
Fix from $2,300 2026-04-17
Cubecart CRITICAL 9.8
CVE-2026-34018

An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.

Fix: 6.6.0+
Fix from $2,300 2026-04-17
Siyuan CRITICAL 9.0
CVE-2026-40322

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "…

Fix: 3.6.4+
Fix from $2,300 2026-04-16
Dataease CRITICAL 9.8
CVE-2026-33122

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API dat…

Fix: 2.10.21+
Fix from $2,300 2026-04-16
Dataease CRITICAL 9.8
CVE-2026-33082

DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export f…

Fix: 2.10.21+
Fix from $2,300 2026-04-16
Zlib CRITICAL 9.8
CVE-2026-27820

zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer ove…

Fix: 3.0.1 / 3.1.2+
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.1
CVE-2026-5426

Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent…

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.1
CVE-2026-37347

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php.

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-37345

SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-37340

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-37339

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.4
CVE-2026-37338

SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php.

Mitigation only
Fix from $2,300 2026-04-16
Fastify\/middie CRITICAL 9.1
CVE-2026-33804

@fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. …

Fix: 9.3.2+
Fix from $2,300 2026-04-16
Fastify\/middie CRITICAL 9.1
CVE-2026-6270

@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instances. When a Fastify application…

Fix: 9.3.2+
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-31843

The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthent…

Mitigation only
Fix from $2,300 2026-04-16
Api Manager CRITICAL 9.1
CVE-2024-2374

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entiti…

Fix: 2.0.0.328 / 2.0.0.348+
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-3596

The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin regis…

Mitigation only
Fix from $2,300 2026-04-16
Intelligent Power Protector CRITICAL 9.9
CVE-2026-22619

Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an…

Fix: 2.00+
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-6350

MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the p…

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-6349

The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS command…

Mitigation only
Fix from $2,300 2026-04-16
Ffmpeg CRITICAL 9.8
CVE-2026-40962

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

Fix: 8.1+
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-40504

Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bou…

Patch available
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.3
CVE-2026-40959

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

Patch available
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-4880

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege …

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.1
CVE-2026-6388

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a m…

Mitigation only
Fix from $2,300 2026-04-15
Dgraph CRITICAL 9.4
CVE-2026-40173

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where…

Fix: 25.3.2+
Fix from $2,300 2026-04-15
Chrome CRITICAL 9.6
CVE-2026-6296

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafte…

Fix: 147.0.7727.101+
Fix from $2,300 2026-04-15
Pyroscope CRITICAL 9.1
CVE-2025-41118

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (CO…

Fix: 1.15.2+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.2
CVE-2026-5189

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with net…

Mitigation only
Fix from $2,300 2026-04-15
Velociraptor CRITICAL 9.1
CVE-2026-6290

Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token…

Fix: 0.76.3+
Fix from $2,300 2026-04-15