Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2024-36057

Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $…

Mitigation only
Fix from $2,300 2026-04-07
Django CRITICAL 9.8
CVE-2026-4277

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated o…

Fix: 4.2.30 / 5.2.13+
Fix from $2,300 2026-04-07
Gotenberg CRITICAL 9.8
CVE-2026-35458

Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns wi…

Fix: 8.29.1+
Fix from $2,300 2026-04-07
Oai Cn5g Amf CRITICAL 9.8
CVE-2026-30079

In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authenticati…

No fix yet
Fix from $2,300 2026-04-07
Libraw CRITICAL 9.8
CVE-2026-24450

An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious fi…

Mitigation only
Fix from $2,300 2026-04-07
Libraw CRITICAL 9.8
CVE-2026-21413

A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A speciall…

Mitigation only
Fix from $2,300 2026-04-07
Libraw CRITICAL 9.8
CVE-2026-20911

A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially cr…

Mitigation only
Fix from $2,300 2026-04-07
Libraw CRITICAL 9.8
CVE-2026-20889

A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file …

Mitigation only
Fix from $2,300 2026-04-07
Libraw CRITICAL 9.8
CVE-2026-20884

An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can l…

Mitigation only
Fix from $2,300 2026-04-07
Exynos 990 Firmware CRITICAL 9.8
CVE-2025-62818

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24…

Mitigation only
Fix from $2,300 2026-04-07
Exynos W1000 Firmware CRITICAL 9.8
CVE-2025-52909

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W…

Mitigation only
Fix from $2,300 2026-04-07
Firefox CRITICAL 9.8
CVE-2026-5735

Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that wi…

Fix: 149.0.2+
Fix from $2,300 2026-04-07
Firefox CRITICAL 9.8
CVE-2026-5734

Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed eviden…

Fix: 140.9.1 / 149.0.2+
Fix from $2,300 2026-04-07
Firefox CRITICAL 9.8
CVE-2026-5731

Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of th…

Mitigation only
Fix from $2,300 2026-04-07
Erlang\/inets CRITICAL 9.8
CVE-2026-28808

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when se…

Fix: 9.1.0.6 / 9.3.2.4+
Fix from $2,300 2026-04-07
Aruba Networking Private 5g Core CRITICAL 9.6
CVE-2026-23818

A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacke…

Fix: 1.25.3.1+
Fix from $2,300 2026-04-07
E Cology CRITICAL 9.8
CVE-2026-22679EPSS 21%

Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/dev…

Fix: 20260312+
Fix from $2,300 2026-04-07
Tianxin Internet Behavior Management System CRITICAL 9.8
CVE-2021-4473EPSS 6%

Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated…

Fix: 4.0.0.7_20210716.180815+
Fix from $2,300 2026-04-07
Lollms CRITICAL 9.8
CVE-2026-1114

In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key f…

Patch available
Fix from $2,300 2026-04-07
Job Management Partner 1\/it Desktop Management Manager CRITICAL 9.8
CVE-2025-65115

Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows…

Fix: after 13-01-06
Fix from $2,300 2026-04-07
Unclassified CRITICAL 9.8
CVE-2026-0740EPSS 63%

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Co…

Mitigation only
Fix from $2,300 2026-04-07
Goshs CRITICAL 9.8
CVE-2026-35471

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixe…

Fix: 2.0.0+
Fix from $2,300 2026-04-06
Directus CRITICAL 9.3
CVE-2026-35408

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked…

Fix: 11.17.0+
Fix from $2,300 2026-04-06
Goshs CRITICAL 9.8
CVE-2026-35393

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2…

Fix: 2.0.0+
Fix from $2,300 2026-04-06
Goshs CRITICAL 9.8
CVE-2026-35392

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is …

Fix: 2.0.0+
Fix from $2,300 2026-04-06
Pyload Ng CRITICAL 9.1
CVE-2026-35459

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vu…

Fix: 0.5.0b3.dev97+
Fix from $2,300 2026-04-06
Dye CRITICAL 9.8
CVE-2026-35197

dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbit…

Mitigation only
Fix from $2,300 2026-04-06
Ecclesiacrm CRITICAL 9.8
CVE-2026-35184

EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/templates/query/queryview.php via the…

Fix: 8.0.0+
Fix from $2,300 2026-04-06
Forceworkbench CRITICAL 9.8
CVE-2026-35178

Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Force.com APIs. Prior to 65.0.0…

Fix: 65.0.0+
Fix from $2,300 2026-04-06
Exynos 980 Firmware CRITICAL 10.0
CVE-2025-54328

An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1…

Mitigation only
Fix from $2,300 2026-04-06