Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mailcarrier CRITICAL 9.8
CVE-2019-25646

Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.8
CVE-2019-25628

Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute …

Mitigation only
Fix from $2,300 2026-03-24
Android Imagemagick7 CRITICAL 9.8
CVE-2026-4755

CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11.

Fix: 7.1.2-11+
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.1
CVE-2026-4753

Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72.

Patch available
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.1
CVE-2026-4750

Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0.

Patch available
Fix from $2,300 2026-03-24
Android Imagemagick7 CRITICAL 9.8
CVE-2026-33854

Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10.

Fix: 7.1.2-10+
Fix from $2,300 2026-03-24
Unclassified CRITICAL 10.0
CVE-2026-4746

Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src‎ modules). This vulnerability is associated with program files infl…

Patch available
Fix from $2,300 2026-03-24
Unclassified CRITICAL 10.0
CVE-2026-4745

Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules). This vulnerability is as…

Patch available
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.1
CVE-2026-4283

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This i…

Mitigation only
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.3
CVE-2026-4744

Out-of-bounds Read vulnerability in rizonesoft Notepad3 (‎scintilla/oniguruma/src modules). This vulnerability is associated with program files regco…

Patch available
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.4
CVE-2026-4739

Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (‎Modules/ThirdParty/Expat/src/expat modules).This issue affects ITK: b…

Patch available
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.4
CVE-2026-4738

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulne…

Patch available
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.4
CVE-2026-4734

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt/openmpt-trunk/include/premak…

Patch available
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.8
CVE-2026-4001

The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via…

Mitigation only
Fix from $2,300 2026-03-24
Graphiti CRITICAL 9.1
CVE-2026-33286

Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary me…

Fix: 1.10.2+
Fix from $2,300 2026-03-24
Rails CRITICAL 9.1
CVE-2026-33202

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's …

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $2,300 2026-03-24
Tekton Pipelines CRITICAL 9.6
CVE-2026-33211

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3…

Fix: 1.3.3 / 1.6.1+
Fix from $2,300 2026-03-24
Rails CRITICAL 9.8
CVE-2026-33195

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's …

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $2,300 2026-03-24
Unclassified CRITICAL 9.3
CVE-2026-4681

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through t…

Mitigation only
Fix from $2,300 2026-03-23
Openclaw CRITICAL 9.1
CVE-2026-32913

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across…

Fix: 2026.3.7+
Fix from $2,300 2026-03-23
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2026-3055 KEVEPSS 87%

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

Fix: 13.1-37.262 / 13.1-62.23+
Fix from $2,300 2026-03-23
Mantisbt CRITICAL 9.8
CVE-2026-30849

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authenti…

Fix: 2.28.1+
Fix from $2,300 2026-03-23
Unclassified CRITICAL 9.4
CVE-2026-2298

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web …

Mitigation only
Fix from $2,300 2026-03-23
Avideo CRITICAL 9.4
CVE-2026-33716

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/stand…

Fix: after 26.0
Fix from $2,300 2026-03-23
Unclassified CRITICAL 9.0
CVE-2026-0898

An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Micro…

Mitigation only
Fix from $2,300 2026-03-23
Harbor CRITICAL 9.4
CVE-2026-4404

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

Fix: after 2.15.0
Fix from $2,300 2026-03-23
Avideo CRITICAL 10.0
CVE-2026-33478EPSS 13%

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain toget…

Fix: after 26.0
Fix from $2,300 2026-03-23
Avideo CRITICAL 9.8
CVE-2026-33352

WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` …

Fix: 26.0+
Fix from $2,300 2026-03-23
Avideo CRITICAL 9.1
CVE-2026-33351

WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standA…

Fix: 26.0+
Fix from $2,300 2026-03-23
Avideo CRITICAL 9.1
CVE-2026-33297

WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administr…

Fix: 26.0+
Fix from $2,300 2026-03-23