Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sharefile Storage Zones Controller CRITICAL 9.8
CVE-2026-2699EPSS 60%

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to …

Fix: 5.12.4+
Fix from $2,300 2026-04-02
Mbconnect24 CRITICAL 9.1
CVE-2026-33615

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization …

Fix: after 2.19.4
Fix from $2,300 2026-04-02
Secure Email Gateway CRITICAL 9.1
CVE-2026-29143

SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an a…

Fix: 15.0.3+
Fix from $2,300 2026-04-02
Secure Email Gateway CRITICAL 9.8
CVE-2026-29139

SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.

Fix: 15.0.3+
Fix from $2,300 2026-04-02
Secure Email Gateway CRITICAL 9.1
CVE-2026-29133

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.

Fix: 15.0.3+
Fix from $2,300 2026-04-02
Mongoose CRITICAL 9.8
CVE-2026-5244

A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS…

Fix: 7.21+
Fix from $2,300 2026-04-02
Ci4ms CRITICAL 9.0
CVE-2026-34571

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34569

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34568

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34567

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34566

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34565

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34564

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34563

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34562

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34560

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Ci4ms CRITICAL 9.0
CVE-2026-34559

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-04-01
Security Verify Access CRITICAL 9.8
CVE-2026-4101

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces…

Fix: after 11.0.2.0
Fix from $2,300 2026-04-01
Mbed Tls CRITICAL 9.1
CVE-2026-34873

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

Fix: 3.6.6 / 4.1.0+
Fix from $2,300 2026-04-01
Filebrowser CRITICAL 9.0
CVE-2026-34529

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver…

Fix: 2.62.2+
Fix from $2,300 2026-04-01
Filebrowser CRITICAL 9.8
CVE-2026-34528

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver…

Fix: 2.62.2+
Fix from $2,300 2026-04-01
Aiohttp CRITICAL 9.1
CVE-2026-34520

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs)…

Fix: 3.13.4+
Fix from $2,300 2026-04-01
Mbed Tls CRITICAL 9.1
CVE-2026-34872

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to impr…

Fix: 3.6.6+
Fix from $2,300 2026-04-01
Reviactyl CRITICAL 9.8
CVE-2026-34456

Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before …

Patch available
Fix from $2,300 2026-04-01
Mbed Tls CRITICAL 9.8
CVE-2026-34875

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

Fix: 1.1.0 / 3.6.6+
Fix from $2,300 2026-04-01
Payload CRITICAL 9.1
CVE-2026-34751

Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in …

Fix: 3.79.1+
Fix from $2,300 2026-04-01
Auth0 Php CRITICAL 9.8
CVE-2026-34236

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth…

Fix: 8.19.0+
Fix from $2,300 2026-04-01
Llama.cpp CRITICAL 9.8
CVE-2026-34159

llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation …

Patch available
Fix from $2,300 2026-04-01
Cronmaster CRITICAL 9.8
CVE-2026-34072

Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an …

Fix: 2.2.0+
Fix from $2,300 2026-04-01
Model Runner CRITICAL 9.1
CVE-2026-33990

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains a…

Fix: 1.1.25+
Fix from $2,300 2026-04-01