Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Web Interface CRITICAL 9.8
CVE-2026-33765

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 …

Fix: 6.0+
Fix from $2,300 2026-03-27
Nanobot CRITICAL 9.8
CVE-2026-33654

nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module …

Fix: 0.1.4+
Fix from $2,300 2026-03-27
Fleet CRITICAL 9.8
CVE-2026-34387

Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an …

Fix: 4.81.1+
Fix from $2,300 2026-03-27
Avideo CRITICAL 9.1
CVE-2026-34374

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by…

Fix: after 26.0
Fix from $2,300 2026-03-27
Letta CRITICAL 9.8
CVE-2026-4965

A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the…

Mitigation only
Fix from $2,300 2026-03-27
Smolagents CRITICAL 10.0
CVE-2026-4963

A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the…

Mitigation only
Fix from $2,300 2026-03-27
Avideo CRITICAL 9.8
CVE-2026-33770

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` con…

Fix: after 26.0
Fix from $2,300 2026-03-27
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28369

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce…

Mitigation only
Fix from $2,300 2026-03-27
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28368

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed diffe…

Mitigation only
Fix from $2,300 2026-03-27
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28367

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for…

Mitigation only
Fix from $2,300 2026-03-27
Online Food Ordering System CRITICAL 9.8
CVE-2026-30533

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.

Mitigation only
Fix from $2,300 2026-03-27
Online Food Ordering System CRITICAL 9.8
CVE-2026-30532

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.

Mitigation only
Fix from $2,300 2026-03-27
Online Food Ordering System CRITICAL 9.8
CVE-2026-30530

A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer actio…

Mitigation only
Fix from $2,300 2026-03-27
Coderider CRITICAL 10.0
CVE-2026-30302

The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffec…

Fix: after 2.3.6
Fix from $2,300 2026-03-27
Ai Code CRITICAL 9.6
CVE-2026-30304

In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute all commands. The description f…

Fix: after 3.12.4
Fix from $2,300 2026-03-27
Axon Code CRITICAL 9.8
CVE-2026-30303

The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective.…

Fix: after 4.123.1
Fix from $2,300 2026-03-27
Grafana CRITICAL 9.1
CVE-2026-27876

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a…

Fix: 11.6.0 / 12.0.0+
Fix from $2,300 2026-03-27
Unclassified CRITICAL 9.3
CVE-2026-1496

Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an aut…

Mitigation only
Fix from $2,300 2026-03-27
Aterm Wg2600hs Firmware CRITICAL 9.8
CVE-2026-4622

OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.

Fix: 1.3.2 / 1.4.2+
Fix from $2,300 2026-03-27
Aterm Wx3600hp Firmware CRITICAL 9.8
CVE-2026-4620

OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.

Fix: 1.4.2 / 1.5.3+
Fix from $2,300 2026-03-27
Aterm Wx3600hp Firmware CRITICAL 9.8
CVE-2026-4619

Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.

Fix: 1.5.3+
Fix from $2,300 2026-03-27
Bludit CRITICAL 9.8
CVE-2026-25101

Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behav…

Fix: 3.17.2+
Fix from $2,300 2026-03-27
Wcr 1166dhpl Firmware CRITICAL 9.8
CVE-2026-33280

Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionali…

Fix: 1.01 / 2.53+
Fix from $2,300 2026-03-27
Wcr 1166dhpl Firmware CRITICAL 9.8
CVE-2026-32669

Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the pr…

Fix: 1.01 / 2.53+
Fix from $2,300 2026-03-27
Wcr 1166dhpl Firmware CRITICAL 9.8
CVE-2026-27650

OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be execut…

Fix: 1.01 / 2.53+
Fix from $2,300 2026-03-27
Spring Ai CRITICAL 9.8
CVE-2026-22738

In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious a…

Fix: 1.0.5 / 1.1.4+
Fix from $2,300 2026-03-27
Simple Laundry System CRITICAL 9.8
CVE-2026-4908

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /modstaffinfo.php of the…

Mitigation only
Fix from $2,300 2026-03-27
Mytube CRITICAL 9.8
CVE-2026-33890

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitra…

Fix: 1.8.71+
Fix from $2,300 2026-03-27
Buildkit CRITICAL 9.8
CVE-2026-33747

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when …

Fix: 0.28.1+
Fix from $2,300 2026-03-27
Openfga CRITICAL 9.8
CVE-2026-33729

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to…

Fix: 1.13.1+
Fix from $2,300 2026-03-27