Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Exynos 990 Firmware CRITICAL 9.1
CVE-2025-58349

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 14…

Mitigation only
Fix from $2,300 2026-04-06
Kedro CRITICAL 9.8
CVE-2026-35171

Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGIN…

Fix: 1.3.0+
Fix from $2,300 2026-04-06
D Tale CRITICAL 9.8
CVE-2026-35052

D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale p…

Fix: 3.22.0+
Fix from $2,300 2026-04-06
Bravecms CRITICAL 9.8
CVE-2026-35047

Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitr…

Fix: 2.0.6+
Fix from $2,300 2026-04-06
Bentoml CRITICAL 9.6
CVE-2026-35044

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation…

Fix: 1.4.38+
Fix from $2,300 2026-04-06
Fast Jwt CRITICAL 9.1
CVE-2026-35039

fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not pro…

Fix: 6.1.0+
Fix from $2,300 2026-04-06
Ci4ms CRITICAL 9.0
CVE-2026-35035

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.2.0+
Fix from $2,300 2026-04-06
Litellm CRITICAL 9.1
CVE-2026-35030

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt…

Fix: 1.83.0+
Fix from $2,300 2026-04-06
Ci4ms CRITICAL 9.0
CVE-2026-34989

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-06
Aperisolve CRITICAL 9.8
CVE-2026-34977

Aperi'Solve is an open-source steganalysis web platform. In versions 3.1.3 through 3.2.0, when uploading a JPEG, a user can specify an optional passw…

Fix: after 3.2.0
Fix from $2,300 2026-04-06
Dgraph CRITICAL 10.0
CVE-2026-34976

Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware…

Fix: after 25.3.0
Fix from $2,300 2026-04-06
Bruno CRITICAL 9.8
CVE-2026-34841

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised version…

Fix: 3.2.1+
Fix from $2,300 2026-04-06
Fast Jwt CRITICAL 9.1
CVE-2026-34950

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ an…

Fix: 6.2.0+
Fix from $2,300 2026-04-06
Lupa CRITICAL 10.0
CVE-2026-34444

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are acc…

Fix: after 2.6
Fix from $2,300 2026-04-06
Sandboxjs CRITICAL 10.0
CVE-2026-34208

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), …

Fix: 0.8.36+
Fix from $2,300 2026-04-06
Dcmtk CRITICAL 9.8
CVE-2026-5663

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/a…

Fix: after 3.7.0
Fix from $2,300 2026-04-06
Yard Management Solutions CRITICAL 9.8
CVE-2026-31151

An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the application 's resources.

Mitigation only
Fix from $2,300 2026-04-06
520w Firmware CRITICAL 9.8
CVE-2026-31059

A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to exec…

Mitigation only
Fix from $2,300 2026-04-06
Glpi CRITICAL 9.8
CVE-2026-26263EPSS 9%

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL…

Fix: 11.0.6+
Fix from $2,300 2026-04-06
Linux Kernel CRITICAL 9.8
CVE-2026-31405

In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-04-06
Kados CRITICAL 9.1
CVE-2019-25704

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the fil…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25702

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25700

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sor…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25698

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25696

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the lan…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25694

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25692

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id…

No fix yet
Fix from $2,300 2026-04-05
Kados CRITICAL 9.1
CVE-2019-25688

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code…

No fix yet
Fix from $2,300 2026-04-05
Pegasus Cms CRITICAL 9.8
CVE-2019-25687

Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitr…

Mitigation only
Fix from $2,300 2026-04-05
Advance Gift Shop Pro Script CRITICAL 9.8
CVE-2019-25680

Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by …

Fix: after 2.0.3
Fix from $2,300 2026-04-05