Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

I12 Firmware CRITICAL 9.8
CVE-2026-5849

A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a ma…

Mitigation only
Fix from $2,300 2026-04-09
I3 Firmware CRITICAL 9.8
CVE-2026-5841

A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. E…

Mitigation only
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.8
CVE-2026-1830EPSS 8%

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insuffic…

Mitigation only
Fix from $2,300 2026-04-09
Unclassified CRITICAL 9.4
CVE-2026-3199

A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with ta…

Mitigation only
Fix from $2,300 2026-04-08
Chrome CRITICAL 9.8
CVE-2026-5902

Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media …

Fix: 147.0.7727.55+
Fix from $2,300 2026-04-08
Chrome CRITICAL 9.6
CVE-2026-5874

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Fix: 147.0.7727.55+
Fix from $2,300 2026-04-08
Unfurl CRITICAL 9.1
CVE-2026-40035

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug conf…

Fix: after 2025.08
Fix from $2,300 2026-04-08
Praisonai CRITICAL 9.8
CVE-2026-39890

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files wit…

Fix: after 4.5.114
Fix from $2,300 2026-04-08
Cryptography CRITICAL 9.8
CVE-2026-39892

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contig…

Fix: 46.0.7+
Fix from $2,300 2026-04-08
Praisonai CRITICAL 9.9
CVE-2026-39888

PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", w…

Fix: 1.5.115+
Fix from $2,300 2026-04-08
Kcp CRITICAL 9.1
CVE-2026-39429

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cach…

Fix: 0.29.3 / 0.30.3+
Fix from $2,300 2026-04-08
Inventree CRITICAL 9.9
CVE-2026-35477

InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to u…

Fix: after 1.2.6
Fix from $2,300 2026-04-08
Unclassified CRITICAL 9.8
CVE-2026-2942

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadP…

Mitigation only
Fix from $2,300 2026-04-08
Logstash CRITICAL 9.8
CVE-2026-33466

Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code executi…

Fix: 8.19.14 / 9.2.8+
Fix from $2,300 2026-04-08
Ac6 Firmware CRITICAL 9.8
CVE-2025-52221

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters.

Mitigation only
Fix from $2,300 2026-04-08
Erpnext CRITICAL 9.1
CVE-2026-31017

A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us…

Mitigation only
Fix from $2,300 2026-04-08
Qd CRITICAL 9.1
CVE-2023-46945

QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request

Fix: after 20230821
Fix from $2,300 2026-04-08
Xwiki CRITICAL 9.8
CVE-2026-33229

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly p…

Fix: 17.4.8 / 17.10.1+
Fix from $2,300 2026-04-08
Stata Mcp CRITICAL 9.8
CVE-2026-31040

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command…

Fix: 1.13.0+
Fix from $2,300 2026-04-08
Ci4ms CRITICAL 9.8
CVE-2026-39394

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.4.0+
Fix from $2,300 2026-04-08
Unclassified CRITICAL 9.3
CVE-2025-14816

Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICON…

Mitigation only
Fix from $2,300 2026-04-08
Unclassified CRITICAL 9.3
CVE-2025-14815

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Sui…

Mitigation only
Fix from $2,300 2026-04-08
Coolercontrold CRITICAL 9.1
CVE-2026-5300

Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data …

Fix: 4.0.0+
Fix from $2,300 2026-04-08
Unclassified CRITICAL 9.6
CVE-2026-39640

Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from…

Mitigation only
Fix from $2,300 2026-04-08
Unclassified CRITICAL 9.6
CVE-2026-39620

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affec…

Mitigation only
Fix from $2,300 2026-04-08
Unclassified CRITICAL 9.6
CVE-2026-39619

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Bus…

Mitigation only
Fix from $2,300 2026-04-08
Unclassified CRITICAL 9.6
CVE-2026-39617

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestr…

Mitigation only
Fix from $2,300 2026-04-08
Movable Type CRITICAL 9.8
CVE-2026-33088

Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement.

Fix: 8.0.10 / 8.8.3+
Fix from $2,300 2026-04-08
Movable Type CRITICAL 9.8
CVE-2026-25776

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

Fix: 8.0.10 / 8.8.3+
Fix from $2,300 2026-04-08
Unclassified CRITICAL 9.8
CVE-2026-3535

The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownl…

Mitigation only
Fix from $2,300 2026-04-08