Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chall Manager CRITICAL 9.9
CVE-2026-32768

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, due to a miswritten NetworkPo…

Fix: 0.6.5+
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4472

A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the fi…

Mitigation only
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4471

A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_em…

Mitigation only
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4470

A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of …

Mitigation only
Fix from $2,300 2026-03-20
Online Frozen Foods Ordering System CRITICAL 9.8
CVE-2026-4469

A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of…

Mitigation only
Fix from $2,300 2026-03-20
Avideo Encoder CRITICAL 9.1
CVE-2026-33024

AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpo…

Fix: 8.0+
Fix from $2,300 2026-03-20
Langflow CRITICAL 9.8
CVE-2026-33017 KEVEPSS 96%

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id…

Fix: 1.8.2+
Fix from $2,300 2026-03-20
Unclassified CRITICAL 9.8
CVE-2026-4038

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check…

Mitigation only
Fix from $2,300 2026-03-20
Pjsip CRITICAL 9.8
CVE-2026-32945

PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based Buffer Overflowvulnerability…

Fix: 2.17+
Fix from $2,300 2026-03-20
Anchorr CRITICAL 9.0
CVE-2026-32891

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and be…

Fix: after 1.4.1
Fix from $2,300 2026-03-20
Anchorr CRITICAL 9.6
CVE-2026-32890

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and…

Fix: after 1.4.1
Fix from $2,300 2026-03-20
Identity Manager CRITICAL 9.8
CVE-2026-21992

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracle Web Services Manager produc…

Mitigation only
Fix from $2,300 2026-03-20
Admidio CRITICAL 9.1
CVE-2026-32817

Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the curre…

Fix: 5.0.7+
Fix from $2,300 2026-03-20
Monitoring CRITICAL 9.8
CVE-2026-32771

The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces).…

Fix: 0.2.2+
Fix from $2,300 2026-03-20
Fullchain CRITICAL 9.8
CVE-2026-32769

Fullchain is an umbrella project for deploying a ready-to-use CTF platform. In versions prior to 0.1.1, due to a mis-written NetworkPolicy, a malici…

Fix: 0.1.1+
Fix from $2,300 2026-03-20
Siyuan CRITICAL 9.8
CVE-2026-32767

SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextS…

Fix: 3.6.1+
Fix from $2,300 2026-03-20
Suitecrm CRITICAL 9.8
CVE-2026-33289

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP…

Fix: 7.15.1 / 8.9.3+
Fix from $2,300 2026-03-20
Xerte Online Toolkits CRITICAL 9.8
CVE-2026-32985

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality t…

Fix: after 3.14.0
Fix from $2,300 2026-03-20
Filebrowser CRITICAL 9.8
CVE-2026-32760

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions …

Fix: 2.62.0+
Fix from $2,300 2026-03-20
Spring Security CRITICAL 9.1
CVE-2026-22732

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will n…

Fix: 5.7.22 / 5.8.24+
Fix from $2,300 2026-03-19
Freescout CRITICAL 9.3
CVE-2026-32754

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scr…

Fix: 1.8.209+
Fix from $2,300 2026-03-19
Siyuan CRITICAL 9.0
CVE-2026-32751

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) renders notebook names via inner…

Fix: 3.6.1+
Fix from $2,300 2026-03-19
Bing Images CRITICAL 9.8
CVE-2026-32194

Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu…

No fix yet
Fix from $2,300 2026-03-19
Openclaw CRITICAL 9.0
CVE-2026-32038

OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network…

Fix: 2026.2.24+
Fix from $2,300 2026-03-19
Openwrt CRITICAL 9.8
CVE-2026-30872

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based B…

Fix: 24.10.6 / 25.12.1+
Fix from $2,300 2026-03-19
Openwrt CRITICAL 9.8
CVE-2026-30871

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based B…

Fix: 24.10.6 / 25.12.1+
Fix from $2,300 2026-03-19
Wolfssl CRITICAL 9.8
CVE-2026-4395

Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote attacker to write attacker-cont…

Fix: 5.9.0+
Fix from $2,300 2026-03-19
Wolfssl CRITICAL 9.8
CVE-2026-3849

Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) suppor…

Fix: 5.9.0+
Fix from $2,300 2026-03-19
Wolfssl CRITICAL 9.8
CVE-2026-3549

Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in…

Fix: 5.9.0+
Fix from $2,300 2026-03-19
Siyuan CRITICAL 9.1
CVE-2026-32749

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploa…

Fix: 3.6.1+
Fix from $2,300 2026-03-19