Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Coldfusion CRITICAL 9.3
CVE-2026-27304

ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.3
CVE-2026-5752

Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain trave…

Mitigation only
Fix from $2,300 2026-04-14
Connect CRITICAL 9.3
CVE-2026-34615

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-33824 KEVEPSS 73%

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $2,300 2026-04-14
Connect CRITICAL 9.6
CVE-2026-27303

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Connect CRITICAL 9.3
CVE-2026-27246

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Connect CRITICAL 9.3
CVE-2026-27245

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Connect CRITICAL 9.3
CVE-2026-27243

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this…

Fix: 12.11 / 2025.9.15+
Fix from $2,300 2026-04-14
Power Apps CRITICAL 9.0
CVE-2026-26149

Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ…

Fix: 3.26032.10.0+
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-70023

An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.

Mitigation only
Fix from $2,300 2026-04-14
Fortisandbox CRITICAL 9.8
CVE-2026-39813EPSS 23%

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to esc…

Fix: 4.4.9 / 5.0.6+
Fix from $2,300 2026-04-14
Fortisandbox CRITICAL 9.8
CVE-2026-39808 KEVEPSS 93%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

Fix: after 4.4.9
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.9
CVE-2026-38526

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute ar…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-65135

In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin/between-date-reprtsdetails.p…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-65133

A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attac…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-63939

Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the si…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2025-61260EPSS 7%

A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) conf…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2026-31049

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration …

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.1
CVE-2025-8095

The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuita…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.0
CVE-2026-2449

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions upKeeper Instant Privilege Acc…

Mitigation only
Fix from $2,300 2026-04-14
Jetty CRITICAL 9.1
CVE-2026-2332

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques out…

Fix: 9.4.60 / 10.0.28+
Fix from $2,300 2026-04-14
Apisix CRITICAL 9.1
CVE-2026-31908

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious…

Fix: 3.16.0+
Fix from $2,300 2026-04-14
Praisonai CRITICAL 9.8
CVE-2026-40315

PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteConversationStore where the ta…

Fix: 4.5.133+
Fix from $2,300 2026-04-14
Praisonai CRITICAL 9.1
CVE-2026-40313

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known cre…

Fix: 4.5.140+
Fix from $2,300 2026-04-14
Praisonaiagents CRITICAL 9.1
CVE-2026-40289

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser…

Fix: 1.5.140 / 4.5.139+
Fix from $2,300 2026-04-14
Praisonaiagents CRITICAL 9.8
CVE-2026-40288

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to …

Fix: 1.5.140 / 4.5.139+
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2026-6264

A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The att…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.1
CVE-2026-4365

The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the `delete_question_answer()` f…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.9
CVE-2026-27681

Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authenticated user can execute cra…

Mitigation only
Fix from $2,300 2026-04-14
Unclassified CRITICAL 9.8
CVE-2026-22564

An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable SSH to make unauthorized chang…

Mitigation only
Fix from $2,300 2026-04-13