Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mlflow CRITICAL 9.1
CVE-2025-15031

A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically,…

Fix: after 3.10.1
Fix from $2,300 2026-03-18
Samtools CRITICAL 9.8
CVE-2026-31972

SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been a…

Fix: 1.21.1+
Fix from $2,300 2026-03-18
Unclassified CRITICAL 9.8
CVE-2026-25873

OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute ar…

Patch available
Fix from $2,300 2026-03-18
Htslib CRITICAL 9.1
CVE-2026-31967

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the…

Fix: 1.21.1 / 1.22.2+
Fix from $2,300 2026-03-18
Htslib CRITICAL 9.1
CVE-2026-31966

HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one…

Fix: 1.21.1 / 1.22.2+
Fix from $2,300 2026-03-18
Glances CRITICAL 9.1
CVE-2026-32633

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r…

Fix: 4.5.2+
Fix from $2,300 2026-03-18
Glances CRITICAL 9.1
CVE-2026-32611

Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export…

Fix: 4.5.2+
Fix from $2,300 2026-03-18
Unclassified CRITICAL 9.1
CVE-2026-30704

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB

Mitigation only
Fix from $2,300 2026-03-18
Unclassified CRITICAL 9.8
CVE-2026-30703

A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi e…

Mitigation only
Fix from $2,300 2026-03-18
Unclassified CRITICAL 9.8
CVE-2026-30702

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login pa…

Mitigation only
Fix from $2,300 2026-03-18
Unclassified CRITICAL 9.1
CVE-2026-30701

The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of S…

Mitigation only
Fix from $2,300 2026-03-18
Aapanel CRITICAL 9.8
CVE-2026-29859

An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.

Mitigation only
Fix from $2,300 2026-03-18
Mura Cms CRITICAL 9.8
CVE-2025-67830

Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.

Fix: 10.1.4+
Fix from $2,300 2026-03-18
Mura Cms CRITICAL 9.8
CVE-2025-67829

Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.

Fix: 10.1.4+
Fix from $2,300 2026-03-18
Unclassified CRITICAL 9.8
CVE-2026-25449

Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through…

Mitigation only
Fix from $2,300 2026-03-18
Librechat CRITICAL 9.0
CVE-2026-33265

In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.

No fix yet
Fix from $2,300 2026-03-18
Unclassified CRITICAL 9.6
CVE-2026-30884

mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. P…

Patch available
Fix from $2,300 2026-03-18
Onnx CRITICAL 9.1
CVE-2026-28500

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security con…

Fix: after 1.20.1
Fix from $2,300 2026-03-18
Openclaw CRITICAL 9.1
CVE-2026-22171

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpol…

Fix: 2026.2.19+
Fix from $2,300 2026-03-18
Pyopenssl CRITICAL 9.8
CVE-2026-27459

pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set…

Fix: 26.0.0+
Fix from $2,300 2026-03-18
Db2 Recovery Expert CRITICAL 9.1
CVE-2026-3856

IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for …

Patch available
Fix from $2,300 2026-03-17
Okit CRITICAL 9.8
CVE-2026-21994

Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop).…

Mitigation only
Fix from $2,300 2026-03-17
Bpm Enterprise CRITICAL 9.8
CVE-2026-3207

Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.

Fix: 4.3.5+
Fix from $2,300 2026-03-17
Simple Food Order System CRITICAL 9.8
CVE-2026-4319

A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Mitigation only
Fix from $2,300 2026-03-17
Es3 Kvm Firmware CRITICAL 9.1
CVE-2026-32298

The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute O…

Mitigation only
Fix from $2,300 2026-03-17
Wazuh CRITICAL 9.1
CVE-2026-25769EPSS 9%

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execut…

Fix: 4.14.3+
Fix from $2,300 2026-03-17
Unclassified CRITICAL 9.1
CVE-2026-25534

### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed th…

Patch available
Fix from $2,300 2026-03-17
Unclassified CRITICAL 9.0
CVE-2026-3564

A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to ob…

Mitigation only
Fix from $2,300 2026-03-17
Gcb\/fcb Government Financial Cybersecurity Configuration Audit Software CRITICAL 9.8
CVE-2026-4312

GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly acces…

Mitigation only
Fix from $2,300 2026-03-17
Yaml\ CRITICAL 9.1
CVE-2026-4177

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML e…

Fix: 1.37+
Fix from $2,300 2026-03-16