Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hl7 Fhir Core CRITICAL 9.1
CVE-2026-34359

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtil…

Fix: 6.9.4+
Fix from $2,300 2026-03-31
Bionemo Framework CRITICAL 9.8
CVE-2026-24164

NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability migh…

Fix: 2026-01-21+
Fix from $2,300 2026-03-31
Jetson Linux CRITICAL 9.4
CVE-2026-24148

NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization …

Fix: 35.6.4 / 36.5+
Fix from $2,300 2026-03-31
Wenxian CRITICAL 9.8
CVE-2026-34243

wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Action…

Fix: after 0.3.1
Fix from $2,300 2026-03-31
Pjsip CRITICAL 9.1
CVE-2026-34235

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists …

Fix: 2.17+
Fix from $2,300 2026-03-31
Mikroorm CRITICAL 9.1
CVE-2026-34221

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototyp…

Fix: 6.6.10 / 7.0.6+
Fix from $2,300 2026-03-31
Mikroorm CRITICAL 9.8
CVE-2026-34220

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a…

Fix: 6.6.10 / 7.0.6+
Fix from $2,300 2026-03-31
Neo.maru CRITICAL 9.8
CVE-2026-30281

An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, …

Mitigation only
Fix from $2,300 2026-03-31
Document Translator CRITICAL 9.8
CVE-2026-30276

An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file imp…

Mitigation only
Fix from $2,300 2026-03-31
Parse Server CRITICAL 9.1
CVE-2026-34532

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, …

Fix: 8.6.67 / 9.7.0+
Fix from $2,300 2026-03-31
Fastgpt CRITICAL 10.0
CVE-2026-34162

FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exp…

Fix: 4.14.9.5+
Fix from $2,300 2026-03-31
Openclaw CRITICAL 9.9
CVE-2026-33579

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into th…

Fix: 2026.3.28+
Fix from $2,300 2026-03-31
Auto Approval Module CRITICAL 9.8
CVE-2026-30314

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl…

Fix: after 0.1.1
Fix from $2,300 2026-03-31
Unclassified CRITICAL 9.8
CVE-2026-30312

DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism comple…

Mitigation only
Fix from $2,300 2026-03-31
Auto Approval Module CRITICAL 9.8
CVE-2026-30311

Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl…

Fix: after 0.1.1
Fix from $2,300 2026-03-31
Nocobase CRITICAL 9.9
CVE-2026-34156EPSS 35%

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's …

Fix: 2.0.28+
Fix from $2,300 2026-03-31
Unclassified CRITICAL 9.8
CVE-2026-30310

In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands. The description for…

Mitigation only
Fix from $2,300 2026-03-31
Openclaw CRITICAL 9.8
CVE-2026-32917

OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute …

Fix: 2026.3.13+
Fix from $2,300 2026-03-31
Openclaw CRITICAL 9.8
CVE-2026-32916

OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods throug…

Fix: 2026.3.11+
Fix from $2,300 2026-03-31
Business\ CRITICAL 9.1
CVE-2025-15618

Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::OnlinePayment::StoredTransaction ge…

Patch available
Fix from $2,300 2026-03-31
Unclassified CRITICAL 9.3
CVE-2026-4317

SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated at…

Mitigation only
Fix from $2,300 2026-03-31
3dexperience CRITICAL 9.1
CVE-2025-10559

A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Rele…

Mitigation only
Fix from $2,300 2026-03-31
Tew 713re Firmware CRITICAL 9.8
CVE-2026-5183EPSS 7%

A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the file /goform/addRouting. Exec…

Mitigation only
Fix from $2,300 2026-03-31
Ruby Lsp CRITICAL 9.8
CVE-2026-34060

Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rub…

Fix: 0.10.2 / 0.26.9+
Fix from $2,300 2026-03-31
Act CRITICAL 9.8
CVE-2026-34041

act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env:: …

Fix: 0.2.86+
Fix from $2,300 2026-03-31
Scitokens Library CRITICAL 9.8
CVE-2026-32714

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL In…

Fix: 1.9.6+
Fix from $2,300 2026-03-31
A3300r Firmware CRITICAL 9.8
CVE-2026-5176

A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi…

Mitigation only
Fix from $2,300 2026-03-31
Unclassified CRITICAL 9.8
CVE-2026-3300EPSS 41%

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12…

Mitigation only
Fix from $2,300 2026-03-31
Basercms CRITICAL 9.8
CVE-2026-30880

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue …

Fix: 5.2.3+
Fix from $2,300 2026-03-31
Basercms CRITICAL 9.8
CVE-2026-27697

baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been pa…

Fix: 5.2.3+
Fix from $2,300 2026-03-31