Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-6349

The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS command…

Mitigation only
Fix from $2,300 2026-04-16
Ffmpeg CRITICAL 9.8
CVE-2026-40962

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

Fix: 8.1+
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-40504

Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bou…

Patch available
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.3
CVE-2026-40959

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

Patch available
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-4880

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege …

Mitigation only
Fix from $2,300 2026-04-16
Unclassified CRITICAL 9.1
CVE-2026-6388

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a m…

Mitigation only
Fix from $2,300 2026-04-15
Dgraph CRITICAL 9.4
CVE-2026-40173

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where…

Fix: 25.3.2+
Fix from $2,300 2026-04-15
Chrome CRITICAL 9.6
CVE-2026-6296

Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafte…

Fix: 147.0.7727.101+
Fix from $2,300 2026-04-15
Pyroscope CRITICAL 9.1
CVE-2025-41118

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (CO…

Fix: 1.15.2+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.2
CVE-2026-5189

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with net…

Mitigation only
Fix from $2,300 2026-04-15
Velociraptor CRITICAL 9.1
CVE-2026-6290

Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token…

Fix: 0.76.3+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-30993

Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnera…

Mitigation only
Fix from $2,300 2026-04-15
Identity Services Engine CRITICAL 9.9
CVE-2026-20186EPSS 6%

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…

Fix: 3.2.0+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-20184

A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote att…

Mitigation only
Fix from $2,300 2026-04-15
Identity Services Engine CRITICAL 9.9
CVE-2026-20180EPSS 6%

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…

Fix: 3.2.0+
Fix from $2,300 2026-04-15
Identity Services Engine Passive Identity Connector CRITICAL 9.9
CVE-2026-20147EPSS 12%

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operatin…

Fix: 3.1.0+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.3
CVE-2025-15610

The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed…

Mitigation only
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.3
CVE-2026-5387

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator D…

Mitigation only
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-30625

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define M…

Patch available
Fix from $2,300 2026-04-15
Fastify\/express CRITICAL 9.1
CVE-2026-33808

Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options…

Fix: 4.0.5+
Fix from $2,300 2026-04-15
Fastify\/express CRITICAL 9.1
CVE-2026-33807

@fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited…

Fix: 4.0.5+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-3461

The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to…

Mitigation only
Fix from $2,300 2026-04-15
Openremote CRITICAL 9.9
CVE-2026-39842

OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engin…

Fix: 1.22.0+
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-1555

The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all v…

Mitigation only
Fix from $2,300 2026-04-15
Unclassified CRITICAL 9.6
CVE-2026-39399

NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec fi…

Patch available
Fix from $2,300 2026-04-14
Nanobot CRITICAL 9.3
CVE-2026-35589

nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's Web…

Fix: 0.1.5+
Fix from $2,300 2026-04-14
Jellyfin CRITICAL 9.1
CVE-2026-35033

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpe…

Fix: 10.11.7+
Fix from $2,300 2026-04-14
Oauth2 Proxy CRITICAL 9.1
CVE-2026-34457

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authe…

Fix: 7.15.2+
Fix from $2,300 2026-04-14
Webperfect Image Suite CRITICAL 10.0
CVE-2026-39907

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts un…

Mitigation only
Fix from $2,300 2026-04-14
Webperfect Image Suite CRITICAL 10.0
CVE-2026-39906

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthentic…

Mitigation only
Fix from $2,300 2026-04-14