Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Praisonai CRITICAL 9.6
CVE-2026-40088

PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled i…

Fix: 4.5.121+
Fix from $2,300 2026-04-09
Tomcat CRITICAL 9.1
CVE-2026-29145

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati…

Fix: 1.3.7 / 2.0.14+
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.8
CVE-2025-13926

An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls B…

Mitigation only
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.1
CVE-2026-39912

V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the …

Patch available
Fix from $2,300 2026-04-09
Wasmtime CRITICAL 9.9
CVE-2026-34987

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler back…

Fix: 36.0.7 / 42.0.2+
Fix from $2,300 2026-04-09
A3300r Firmware CRITICAL 9.8
CVE-2026-31170

An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parame…

Mitigation only
Fix from $2,300 2026-04-09
Openplc V3 Firmware CRITICAL 9.8
CVE-2026-28205

OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to th…

Mitigation only
Fix from $2,300 2026-04-09
Metagpt CRITICAL 9.8
CVE-2026-5971

A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/action…

Fix: after 0.8.1
Fix from $2,300 2026-04-09
Metagpt CRITICAL 9.8
CVE-2026-5970

A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MB…

Fix: after 0.8.1
Fix from $2,300 2026-04-09
Marimo CRITICAL 9.8
CVE-2026-39987 KEVEPSS 97%

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks au…

Fix: 0.23.0+
Fix from $2,300 2026-04-09
Ch22 Firmware CRITICAL 9.8
CVE-2026-5962

A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The ma…

Mitigation only
Fix from $2,300 2026-04-09
Misp CRITICAL 9.6
CVE-2026-39962

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in Apa…

Fix: 2.5.36+
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.1
CVE-2026-39958

oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repositories (topics) named "Topic…

Patch available
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.1
CVE-2026-30479

A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted execut…

Mitigation only
Fix from $2,300 2026-04-09
Ubuntu Desktop Provision CRITICAL 9.1
CVE-2025-15480

In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a use…

Patch available
Fix from $2,300 2026-04-09
Orthanc CRITICAL 9.1
CVE-2026-5445

An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The lookup-table decoding logic used f…

Fix: 1.12.11+
Fix from $2,300 2026-04-09
Orthanc CRITICAL 9.8
CVE-2026-5443

A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication f…

Fix: 1.12.11+
Fix from $2,300 2026-04-09
Orthanc CRITICAL 9.8
CVE-2026-5442

A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (U…

Fix: 1.12.11+
Fix from $2,300 2026-04-09
Axios CRITICAL 9.9
CVE-2025-62718

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization …

Fix: 0.31.0 / 1.15.0+
Fix from $2,300 2026-04-09
Jizhicms CRITICAL 9.1
CVE-2025-50228

Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.

Mitigation only
Fix from $2,300 2026-04-09
Airflow CRITICAL 9.1
CVE-2025-57735

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was inte…

Fix: 3.2.0+
Fix from $2,300 2026-04-09
Control System CRITICAL 9.1
CVE-2026-34184

AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and ev…

Fix: 9.8.5+
Fix from $2,300 2026-04-09
Lxd CRITICAL 9.1
CVE-2026-34179

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PU…

Fix: after 6.7
Fix from $2,300 2026-04-09
Lxd CRITICAL 9.1
CVE-2026-34178

In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates …

Fix: after 6.7
Fix from $2,300 2026-04-09
Lxd CRITICAL 9.1
CVE-2026-34177

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omit…

Fix: after 6.7
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.8
CVE-2026-5854EPSS 18%

A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cst…

Mitigation only
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.8
CVE-2026-5853EPSS 14%

A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of …

Mitigation only
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.8
CVE-2026-5852EPSS 14%

A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the …

Mitigation only
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.8
CVE-2026-5851EPSS 14%

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi o…

Mitigation only
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.8
CVE-2026-5850EPSS 16%

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of …

Mitigation only
Fix from $2,300 2026-04-09