Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Chrome CRITICAL 9.6
CVE-2026-3916

Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a craf…

Fix: 146.0.7680.71+
Fix from $2,300 2026-03-11
Adguardhome CRITICAL 9.8
CVE-2026-32136

AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentic…

Fix: 0.107.73+
Fix from $2,300 2026-03-11
2fauth CRITICAL 9.1
CVE-2026-32133

2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0, a blind SSRF vulnerability …

Fix: 6.1.0+
Fix from $2,300 2026-03-11
Winter CRITICAL 9.9
CVE-2026-27591

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS al…

Fix: 1.0.477 / 1.1.12+
Fix from $2,300 2026-03-11
Openemr CRITICAL 9.0
CVE-2026-32118

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scriptin…

Fix: 8.0.0.1+
Fix from $2,300 2026-03-11
Unclassified CRITICAL 9.8
CVE-2025-70041

An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.

Mitigation only
Fix from $2,300 2026-03-11
Unclassified CRITICAL 9.8
CVE-2025-70024

An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benkeen generatedata 4.0.14.

Mitigation only
Fix from $2,300 2026-03-11
Unclassified CRITICAL 9.9
CVE-2025-66956

Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachme…

Mitigation only
Fix from $2,300 2026-03-11
Xygeni Action CRITICAL 9.8
CVE-2026-31976

xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull …

Fix: after 6.4.0
Fix from $2,300 2026-03-11
Himmelblau CRITICAL 10.0
CVE-2026-31957

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a conf…

Fix: 3.1.0+
Fix from $2,300 2026-03-11
Black CRITICAL 9.8
CVE-2026-31900

Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject:…

Fix: 26.3.0+
Fix from $2,300 2026-03-11
Wegia CRITICAL 9.8
CVE-2026-31896

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. T…

Fix: 3.6.6+
Fix from $2,300 2026-03-11
Riot CRITICAL 9.8
CVE-2026-27703

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded de…

Fix: after 2026.01
Fix from $2,300 2026-03-11
Unitycatalog CRITICAL 9.1
CVE-2026-27478

Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Uni…

Fix: after 0.4.0
Fix from $2,300 2026-03-11
Runtipi CRITICAL 9.8
CVE-2026-31881

Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-re…

Fix: 4.8.0+
Fix from $2,300 2026-03-11
Frappe CRITICAL 9.8
CVE-2026-31877

Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result i…

Fix: 14.99.0 / 15.84.0+
Fix from $2,300 2026-03-11
Taskosaur CRITICAL 9.8
CVE-2026-31874

Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly…

Patch available
Fix from $2,300 2026-03-11
Unclassified CRITICAL 9.8
CVE-2019-25487EPSS 8%

SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands b…

Mitigation only
Fix from $2,300 2026-03-11
File Thingie CRITICAL 9.8
CVE-2019-25471

FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the…

Fix: after 2.5.7
Fix from $2,300 2026-03-11
Unclassified CRITICAL 9.8
CVE-2019-25468

NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by …

Mitigation only
Fix from $2,300 2026-03-11
Unclassified CRITICAL 9.8
CVE-2018-25159

Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated att…

Mitigation only
Fix from $2,300 2026-03-11
Cloud Cli CRITICAL 9.8
CVE-2026-31975

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection v…

Fix: 1.25.0+
Fix from $2,300 2026-03-11
Parse Server CRITICAL 9.8
CVE-2026-31871

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL inje…

Fix: 8.6.31 / 9.6.0+
Fix from $2,300 2026-03-11
Parse Server CRITICAL 9.8
CVE-2026-31856

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the P…

Fix: 8.6.29 / 9.6.0+
Fix from $2,300 2026-03-11
Jellyfin CRITICAL 9.8
CVE-2026-31852

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execut…

Patch available
Fix from $2,300 2026-03-11
Parse Server CRITICAL 9.8
CVE-2026-31840

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacke…

Fix: 8.6.28 / 9.6.0+
Fix from $2,300 2026-03-11
Neo4j CRITICAL 9.8
CVE-2026-1524

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c…

Fix: 5.26.22 / 2026.02+
Fix from $2,300 2026-03-11
Eds3016ps1ns Firmware CRITICAL 9.8
CVE-2025-70082

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

Mitigation only
Fix from $2,300 2026-03-11
Eds3016ps1ns Firmware CRITICAL 9.8
CVE-2025-67041

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly saniti…

Mitigation only
Fix from $2,300 2026-03-11
Eds3016ps1ns Firmware CRITICAL 9.1
CVE-2025-67039

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to th…

Mitigation only
Fix from $2,300 2026-03-11