Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zimaos CRITICAL 10.0
CVE-2026-28798

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/prox…

Fix: 1.5.3+
Fix from $2,300 2026-04-03
Cloudreve CRITICAL 9.8
CVE-2026-25726

Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator …

Fix: 4.13.0+
Fix from $2,300 2026-04-03
Bing CRITICAL 9.8
CVE-2026-32186

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-04-03
Mlflow CRITICAL 9.8
CVE-2026-0545

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a…

Mitigation only
Fix from $2,300 2026-04-03
Stackfield CRITICAL 9.6
CVE-2026-28373

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when proce…

Fix: 1.10.2+
Fix from $2,300 2026-04-03
Budibase CRITICAL 9.0
CVE-2026-35216EPSS 12%

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Bud…

Fix: 3.33.4+
Fix from $2,300 2026-04-03
Budibase CRITICAL 9.9
CVE-2026-31818

Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST d…

Fix: 3.33.4+
Fix from $2,300 2026-04-03
Linux Kernel CRITICAL 9.8
CVE-2026-31402

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache u…

Fix: 5.10.253 / 6.1.167+
Fix from $2,300 2026-04-03
Linux Kernel CRITICAL 9.1
CVE-2026-23455

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ9…

Fix: 5.10.253 / 5.15.203+
Fix from $2,300 2026-04-03
Linux Kernel CRITICAL 9.8
CVE-2026-23450

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller repo…

Fix: 5.15.203 / 6.1.167+
Fix from $2,300 2026-04-03
Pymetasploit3 CRITICAL 9.8
CVE-2026-5463

Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline charact…

Fix: after 1.0.6
Fix from $2,300 2026-04-03
Azure Databricks CRITICAL 9.8
CVE-2026-33107

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Kubernetes Service CRITICAL 9.8
CVE-2026-33105

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Azure Ai Foundry CRITICAL 9.8
CVE-2026-32213

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-04-03
Oneuptime CRITICAL 9.8
CVE-2026-35053

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow executio…

Fix: 10.0.42+
Fix from $2,300 2026-04-02
Hoppscotch CRITICAL 9.3
CVE-2026-34932

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This is…

Fix: 2026.3.0+
Fix from $2,300 2026-04-02
Hoppscotch CRITICAL 9.6
CVE-2026-34931

hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfilt…

Fix: 2026.3.0+
Fix from $2,300 2026-04-02
Group Office CRITICAL 9.9
CVE-2026-34838

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability i…

Fix: 6.8.156 / 25.0.90+
Fix from $2,300 2026-04-02
Unclassified CRITICAL 9.8
CVE-2024-14034

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauth…

Mitigation only
Fix from $2,300 2026-04-02
Oneuptime CRITICAL 9.1
CVE-2026-34758

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Nu…

Fix: 10.0.40+
Fix from $2,300 2026-04-02
Fireshare CRITICAL 9.1
CVE-2026-34745

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/up…

Fix: 1.5.3+
Fix from $2,300 2026-04-02
Car Rental Project CRITICAL 9.8
CVE-2026-5368

A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the com…

Mitigation only
Fix from $2,300 2026-04-02
Mbed Tls CRITICAL 9.8
CVE-2026-34877

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session st…

Fix: 3.6.6+
Fix from $2,300 2026-04-02
Signal K Server CRITICAL 9.4
CVE-2026-33950

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnera…

Fix: 2.24.0+
Fix from $2,300 2026-04-02
Monitoring And Management CRITICAL 9.9
CVE-2026-25212

An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admi…

Fix: 3.7.0+
Fix from $2,300 2026-04-02
Convoy CRITICAL 9.8
CVE-2026-33746

Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did …

Fix: 4.5.1+
Fix from $2,300 2026-04-02
Agno CRITICAL 9.8
CVE-2026-35002

Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arb…

Fix: 2.3.24+
Fix from $2,300 2026-04-02
Fastmcp CRITICAL 10.0
CVE-2026-32871

FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clien…

Fix: 3.2.0+
Fix from $2,300 2026-04-02
Online Enrollment System CRITICAL 9.8
CVE-2026-5334

A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=e…

Mitigation only
Fix from $2,300 2026-04-02
Content Management System CRITICAL 9.8
CVE-2026-5333

A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/to…

Mitigation only
Fix from $2,300 2026-04-02