Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-4003

The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including …

Mitigation only
Fix from $2,300 2026-04-08
Unclassified CRITICAL 9.8
CVE-2026-3296

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untru…

Mitigation only
Fix from $2,300 2026-04-08
Go CRITICAL 9.8
CVE-2026-27143

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid …

Fix: 1.25.9 / 1.26.2+
Fix from $2,300 2026-04-08
Siyuan CRITICAL 9.0
CVE-2026-39846

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the Si…

Fix: 3.6.4+
Fix from $2,300 2026-04-07
Botan CRITICAL 9.1
CVE-2026-34582

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the…

Fix: after 3.11.0
Fix from $2,300 2026-04-07
OpenSSL CRITICAL 9.8
CVE-2026-31789

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impac…

Fix: 3.0.20 / 3.3.7+
Fix from $2,300 2026-04-07
Flatpak CRITICAL 10.0
CVE-2026-34078

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options…

Fix: after 1.16.3
Fix from $2,300 2026-04-07
Payload Puck CRITICAL 9.8
CVE-2026-39397

@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers…

Fix: 0.6.23+
Fix from $2,300 2026-04-07
Podman Desktop CRITICAL 9.1
CVE-2026-34045

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Des…

Fix: 1.26.2+
Fix from $2,300 2026-04-07
Openam CRITICAL 9.8
CVE-2026-33439EPSS 10%

Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulnerable to pre-authentication Re…

Fix: 16.0.6+
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.3
CVE-2026-39382

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Inside th…

Patch available
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.1
CVE-2025-69515

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS sig…

Mitigation only
Fix from $2,300 2026-04-07
Frappe CRITICAL 9.1
CVE-2026-39351

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe allows unrestricted Doctype access via API exploit.

Fix: 15.104.0 / 16.14.0+
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.1
CVE-2025-71058

Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configure…

No fix yet
Fix from $2,300 2026-04-07
Churchcrm CRITICAL 9.1
CVE-2026-39339

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (…

Fix: 7.1.0+
Fix from $2,300 2026-04-07
Churchcrm CRITICAL 10.0
CVE-2026-39337

ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's …

Fix: 7.1.0+
Fix from $2,300 2026-04-07
Rack Session CRITICAL 9.8
CVE-2026-39324

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failu…

Fix: 2.1.2+
Fix from $2,300 2026-04-07
Churchcrm CRITICAL 9.1
CVE-2026-35573

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allo…

Fix: 6.5.3+
Fix from $2,300 2026-04-07
Mrcms CRITICAL 9.8
CVE-2026-31272

MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks pro…

Mitigation only
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.8
CVE-2026-31271

megagao production_ssm v1.0 contains an authorization bypass vulnerability in the user addition functionality. The insert() method in UserController.…

Mitigation only
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.8
CVE-2026-4631EPSS 15%

Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitizati…

Mitigation only
Fix from $2,300 2026-04-07
Praisonai CRITICAL 10.0
CVE-2026-39305

PraisonAI is a multi-agent teams system. Prior to 1.5.113, the Action Orchestrator feature contains a Path Traversal vulnerability that allows an att…

Fix: after 4.5.112
Fix from $2,300 2026-04-07
Frappe CRITICAL 9.8
CVE-2026-35614

Frappe is a full-stack web application framework. Prior to 16.14.0 and 15.104.0, Frappe has a SQL injection in bulk_update. This vulnerability is fix…

Fix: 15.104.0 / 16.14.0+
Fix from $2,300 2026-04-07
Emissary CRITICAL 9.1
CVE-2026-35580

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-contr…

Fix: after 8.38.0
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.9
CVE-2026-23696EPSS 16%

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allo…

Patch available
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.8
CVE-2024-36058

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parame…

Mitigation only
Fix from $2,300 2026-04-07
Changedetection CRITICAL 9.8
CVE-2026-35490

changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (…

Fix: 0.54.8+
Fix from $2,300 2026-04-07
Pgx CRITICAL 9.8
CVE-2026-33816

Memory-safety vulnerability in github.com/jackc/pgx/v5.

Fix: 5.9.0+
Fix from $2,300 2026-04-07
Pgx CRITICAL 9.8
CVE-2026-33815

Memory-safety vulnerability in github.com/jackc/pgx/v5.

Mitigation only
Fix from $2,300 2026-04-07
Exynos W1000 Firmware CRITICAL 9.8
CVE-2025-52908

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W…

Mitigation only
Fix from $2,300 2026-04-07