Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-30993

Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnera…

Mitigation only
Fix from $2,300 2026-04-15
Identity Services Engine CRITICAL 9.9
CVE-2026-20186EPSS 6%

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…

Fix: 3.2.0+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-20184

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote att…

Mitigation only
Fix from $2,300 2026-04-15
Identity Services Engine CRITICAL 9.9
CVE-2026-20180EPSS 6%

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…

Fix: 3.2.0+
Fix from $2,300 2026-04-15
Identity Services Engine Passive Identity Connector CRITICAL 9.9
CVE-2026-20147EPSS 12%

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operatin…

Fix: 3.1.0+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.3
CVE-2025-15610

The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed…

Mitigation only
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.3
CVE-2026-5387

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator D…

Mitigation only
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-30625

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define M…

Patch available
Fix from $2,300 2026-04-15
Fastify\/express CRITICAL 9.1
CVE-2026-33808

Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options…

Fix: 4.0.5+
Fix from $2,300 2026-04-15
Fastify\/express CRITICAL 9.1
CVE-2026-33807

@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited…

Fix: 4.0.5+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-3461

The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to…

Mitigation only
Fix from $2,300 2026-04-15
Openremote CRITICAL 9.9
CVE-2026-39842

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engin…

Fix: 1.22.0+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-1555

The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all v…

Mitigation only
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.6
CVE-2026-39399

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec fi…

Patch available
Fix from $2,300 2026-04-14
Nanobot CRITICAL 9.3
CVE-2026-35589

nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's Web…

Fix: 0.1.5+
Fix from $2,300 2026-04-14
Jellyfin CRITICAL 9.1
CVE-2026-35033

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpe…

Fix: 10.11.7+
Fix from $2,300 2026-04-14
Oauth2 Proxy CRITICAL 9.1
CVE-2026-34457

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authe…

Fix: 7.15.2+
Fix from $2,300 2026-04-14
Webperfect Image Suite CRITICAL 10.0
CVE-2026-39907

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts un…

Mitigation only
Fix from $2,300 2026-04-14
Webperfect Image Suite CRITICAL 10.0
CVE-2026-39906

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthentic…

Mitigation only
Fix from $2,300 2026-04-14
Coldfusion CRITICAL 9.3
CVE-2026-27304

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.3
CVE-2026-5752

Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain trave…

Mitigation only
Fix from $2,300 2026-04-14
Connect CRITICAL 9.3
CVE-2026-34615

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-33824 KEVEPSS 73%

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $2,300 2026-04-14
Connect CRITICAL 9.6
CVE-2026-27303

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Connect CRITICAL 9.3
CVE-2026-27246

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Connect CRITICAL 9.3
CVE-2026-27245

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Connect CRITICAL 9.3
CVE-2026-27243

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Power Apps CRITICAL 9.0
CVE-2026-26149

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ…

Fix: 3.26032.10.0+
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-70023

An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

Mitigation only
Fix from $2,300 2026-04-14
Fortisandbox CRITICAL 9.8
CVE-2026-39813EPSS 23%

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to esc…

Fix: 4.4.9 / 5.0.6+
Fix from $2,300 2026-04-14