Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortisandbox CRITICAL 9.8
CVE-2026-39808 KEVEPSS 93%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

Fix: after 4.4.9
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.9
CVE-2026-38526

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute ar…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-65135

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.p…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-65133

A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attac…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-63939

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the si…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-61260EPSS 7%

A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) conf…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2026-31049

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration …

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.1
CVE-2025-8095

The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuita…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.0
CVE-2026-2449

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions upKeeper Instant Privilege Acc…

Mitigation only
Fix from $2,300 2026-04-14
Jetty CRITICAL 9.1
CVE-2026-2332

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques out…

Fix: 9.4.60 / 10.0.28+
Fix from $2,300 2026-04-14
Apisix CRITICAL 9.1
CVE-2026-31908

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious…

Fix: 3.16.0+
Fix from $2,300 2026-04-14
Praisonai CRITICAL 9.8
CVE-2026-40315

PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteConversationStore where the ta…

Fix: 4.5.133+
Fix from $2,300 2026-04-14
Praisonai CRITICAL 9.1
CVE-2026-40313

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known cre…

Fix: 4.5.140+
Fix from $2,300 2026-04-14
Praisonaiagents CRITICAL 9.1
CVE-2026-40289

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser…

Fix: 1.5.140 / 4.5.139+
Fix from $2,300 2026-04-14
Praisonaiagents CRITICAL 9.8
CVE-2026-40288

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to …

Fix: 1.5.140 / 4.5.139+
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2026-6264

A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The att…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.1
CVE-2026-4365

The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` f…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.9
CVE-2026-27681

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute cra…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2026-22564

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized chang…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-22563

A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. A…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-22562

A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on t…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-31048

An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message.

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-40044

Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serializ…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-40042

Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsa…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-6195EPSS 14%

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the fil…

Mitigation only
Fix from $2,300 2026-04-13
Devops Velocity CRITICAL 9.8
CVE-2025-31991

Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsu…

Fix: 5.1.7+
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-31283

In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Ema…

Mitigation only
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.8
CVE-2026-31282

Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form. An attacker…

Mitigation only
Fix from $2,300 2026-04-13
Linux Kernel CRITICAL 9.8
CVE-2026-31414

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper Use expect->helper in ctnetl…

Fix: 6.1.168 / 6.6.134+
Fix from $2,300 2026-04-13
Unclassified CRITICAL 9.3
CVE-2026-4810

A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.…

Mitigation only
Fix from $2,300 2026-04-13