Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dd Trace Java CRITICAL 9.8
CVE-2026-33728

dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a cus…

Fix: 1.60.3+
Fix from $2,300 2026-03-27
Openhands CRITICAL 9.9
CVE-2026-33718

OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in the `get_git_diff()` method a…

Fix: 1.5.0+
Fix from $2,300 2026-03-27
Opentelemetry Instrumentation For Java CRITICAL 9.8
CVE-2026-33701

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, t…

Fix: 2.26.1+
Fix from $2,300 2026-03-27
Incus CRITICAL 9.6
CVE-2026-33945

Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For container…

Fix: 6.23.0+
Fix from $2,300 2026-03-27
Tigervnc CRITICAL 9.8
CVE-2026-34352

In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, b…

Fix: 1.16.2+
Fix from $2,300 2026-03-26
Incus CRITICAL 9.9
CVE-2026-33897

Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writ…

Fix: 6.23.0+
Fix from $2,300 2026-03-26
Outline CRITICAL 9.8
CVE-2026-33640

Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identit…

Fix: 1.6.0+
Fix from $2,300 2026-03-26
Fuel Cms CRITICAL 9.1
CVE-2026-30458

An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

No fix yet
Fix from $2,300 2026-03-26
Dwoo CRITICAL 9.8
CVE-2026-30457

An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.

Mitigation only
Fix from $2,300 2026-03-26
Thingino Firmware CRITICAL 9.8
CVE-2026-26213EPSS 6%

thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulnerability in the WiFi captive p…

Fix: after 2026-03-15
Fix from $2,300 2026-03-26
Oathkeeper CRITICAL 10.0
CVE-2026-33494

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versi…

Fix: 26.2.0+
Fix from $2,300 2026-03-26
Everest CRITICAL 9.1
CVE-2026-27816

EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_transfer_modes copies a variable…

Fix: 2026.02.0+
Fix from $2,300 2026-03-26
Everest CRITICAL 9.1
CVE-2026-27815

EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup copies a variable-length payment…

Fix: 2026.02.0+
Fix from $2,300 2026-03-26
Oneuptime CRITICAL 9.9
CVE-2026-33396

OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can …

Fix: 10.0.35+
Fix from $2,300 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55261

HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise th…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55270

HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55269

HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force…

Mitigation only
Fix from $2,300 2026-03-26
Aftermarket Cloud CRITICAL 9.8
CVE-2025-55267

HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full cont…

Mitigation only
Fix from $2,300 2026-03-26
Library Cms CRITICAL 9.8
CVE-2018-25204

Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through …

Mitigation only
Fix from $2,300 2026-03-26
School Management System Cms CRITICAL 9.8
CVE-2018-25201

School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authenticat…

Mitigation only
Fix from $2,300 2026-03-26
Hotel Cms CRITICAL 9.8
CVE-2018-25195

Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authen…

Mitigation only
Fix from $2,300 2026-03-26
Restaurant Cms CRITICAL 9.8
CVE-2018-25185

Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting …

Mitigation only
Fix from $2,300 2026-03-26
Shipping System Cms CRITICAL 9.8
CVE-2018-25183

Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code …

Mitigation only
Fix from $2,300 2026-03-26
Unclassified CRITICAL 9.8
CVE-2026-4809

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a cli…

Mitigation only
Fix from $2,300 2026-03-26
Simple Laundry System CRITICAL 9.8
CVE-2026-4850

A security flaw has been discovered in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checkregisitem.php of th…

Mitigation only
Fix from $2,300 2026-03-26
Plack\ CRITICAL 9.8
CVE-2014-125112

Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through …

Fix: 0.23+
Fix from $2,300 2026-03-26
Saloon CRITICAL 9.8
CVE-2026-33942

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAut…

Fix: 4.0.0+
Fix from $2,300 2026-03-26
Saloon CRITICAL 9.1
CVE-2026-33183

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file path…

Fix: 4.0.0+
Fix from $2,300 2026-03-26
Sonarr CRITICAL 9.8
CVE-2026-30975

Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled au…

Fix: 4.0.16.2942+
Fix from $2,300 2026-03-25
Websphere Application Server CRITICAL 9.8
CVE-2025-14917

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected secu…

Fix: 26.0.0.4+
Fix from $2,300 2026-03-25