Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-4257EPSS 41%

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in a…

Mitigation only
Fix from $2,300 2026-03-30
Kyverno CRITICAL 9.8
CVE-2026-4789

Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.

Fix: after 1.17.1
Fix from $2,300 2026-03-30
Ci4ms CRITICAL 9.0
CVE-2026-34558

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-03-30
Ci4ms CRITICAL 9.0
CVE-2026-34557

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t…

Fix: 0.31.0.0+
Fix from $2,300 2026-03-30
Openolat CRITICAL 9.8
CVE-2026-31946

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From version 10.5.4 to before version …

Fix: 20.2.5+
Fix from $2,300 2026-03-30
Cline CRITICAL 9.8
CVE-2026-30313

DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism comple…

Fix: after 1.1.2
Fix from $2,300 2026-03-30
Hai Build CRITICAL 9.8
CVE-2026-30308

In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe commands and Execute all commands. …

Fix: after 3.13.3
Fix from $2,300 2026-03-30
Sakadev CRITICAL 9.8
CVE-2026-30306

In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute all commands. The description f…

Fix: 4.0.6+
Fix from $2,300 2026-03-30
Nginx Ui CRITICAL 9.1
CVE-2026-33026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper w…

Fix: 2.3.4+
Fix from $2,300 2026-03-30
Tautulli CRITICAL 9.1
CVE-2026-32275

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP cal…

Fix: 2.17.0+
Fix from $2,300 2026-03-30
Roo Code CRITICAL 9.8
CVE-2026-30307

Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism complete…

Fix: after 3.46.1
Fix from $2,300 2026-03-30
Syntx CRITICAL 9.8
CVE-2026-30305

Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely …

Fix: after 2.5.0
Fix from $2,300 2026-03-30
Tautulli CRITICAL 10.0
CVE-2026-28505

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handl…

Fix: 2.17.0+
Fix from $2,300 2026-03-30
Nginx Ui CRITICAL 9.8
CVE-2026-33032EPSS 36%

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes…

Fix: after 2.3.5
Fix from $2,300 2026-03-30
Nginx Ui CRITICAL 9.9
CVE-2026-33030

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) …

Fix: after 2.3.3
Fix from $2,300 2026-03-30
Sales And Inventory System CRITICAL 9.3
CVE-2026-30562

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add…

No fix yet
Fix from $2,300 2026-03-30
Crewai CRITICAL 9.8
CVE-2026-2287

CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.

Mitigation only
Fix from $2,300 2026-03-30
Crewai CRITICAL 9.8
CVE-2026-2286

CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG…

Mitigation only
Fix from $2,300 2026-03-30
Unclassified CRITICAL 9.6
CVE-2026-2275

The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling.

Mitigation only
Fix from $2,300 2026-03-30
Control Center CRITICAL 9.8
CVE-2026-4415

Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote …

Fix: 25.12.10.01+
Fix from $2,300 2026-03-30
Mlflow CRITICAL 9.8
CVE-2025-15379

A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to…

Fix: after 3.8.1
Fix from $2,300 2026-03-30
Mlflow CRITICAL 10.0
CVE-2025-15036

A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlf…

Fix: 3.9.0+
Fix from $2,300 2026-03-30
Perl CRITICAL 9.8
CVE-2026-4176

Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Z…

Fix: 5.40.4 / 5.42.2+
Fix from $2,300 2026-03-29
Lollms CRITICAL 9.8
CVE-2026-0558

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/fil…

Fix: after 2.1.0
Fix from $2,300 2026-03-29
Openclaw CRITICAL 9.8
CVE-2026-32987

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers …

Fix: 2026.3.13+
Fix from $2,300 2026-03-29
Openclaw CRITICAL 9.8
CVE-2026-32975

OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of …

Fix: 2026.3.12+
Fix from $2,300 2026-03-29
Openclaw CRITICAL 9.8
CVE-2026-32974

OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationToken is configured without en…

Fix: 2026.3.12+
Fix from $2,300 2026-03-29
Openclaw CRITICAL 9.8
CVE-2026-32973

OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly normalizes patterns with lower…

Fix: 2026.3.11+
Fix from $2,300 2026-03-29
Openclaw CRITICAL 9.8
CVE-2026-32924

OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type are misclassified as p2p…

Fix: 2026.3.12+
Fix from $2,300 2026-03-29
Openclaw CRITICAL 9.9
CVE-2026-32922

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to min…

Fix: 2026.3.11+
Fix from $2,300 2026-03-29