Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Minio CRITICAL 9.8
CVE-2026-33322

MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusio…

Fix: 2026-03-17t21-25-16z+
Fix from $2,300 2026-03-24
\@astrojs\/vercel CRITICAL 9.1
CVE-2026-33768

Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query par…

Fix: 10.0.2+
Fix from $2,300 2026-03-24
Parse Server CRITICAL 9.1
CVE-2026-33409

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, …

Fix: 8.6.52 / 9.6.0+
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.3
CVE-2026-2417

A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthe…

Mitigation only
Fix from $2,300 2026-03-24
Wallos CRITICAL 9.1
CVE-2026-33407

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY a…

Fix: 4.7.0+
Fix from $2,300 2026-03-24
Lollms Web Ui CRITICAL 9.1
CVE-2026-33340EPSS 22%

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulner…

No fix yet
Fix from $2,300 2026-03-24
Vikunja CRITICAL 9.6
CVE-2026-33334

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w…

Fix: 2.2.2+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4729

Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 10.0
CVE-2026-4725

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.1
CVE-2026-4724

Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4723

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4721

Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showe…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4720

Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4717

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 14…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.1
CVE-2026-4716

Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.1
CVE-2026-4715

Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunde…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4711

Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4710

Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thun…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4705

Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4702

JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4701

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 1…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4700

Mitigation bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4698

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thund…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4696

Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbi…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 10.0
CVE-2026-4692

Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbi…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4691

Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thun…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 10.0
CVE-2026-4689

Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability was fixed in Firefox 149, Firefox ES…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 10.0
CVE-2026-4688

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunder…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Langflow CRITICAL 9.1
CVE-2026-33475

Langflow is a tool for building and deploying AI-powered agents and workflows. An unauthenticated remote shell injection vulnerability exists in mult…

Fix: 1.9.0+
Fix from $2,300 2026-03-24
Langflow CRITICAL 9.9
CVE-2026-33309EPSS 11%

Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-6…

Fix: 1.9.0+
Fix from $2,300 2026-03-24