Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Oneuptime CRITICAL 9.9
CVE-2026-30956

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass authorization and tenant isol…

Fix: 10.0.21+
Fix from $2,300 2026-03-10
Glances CRITICAL 9.8
CVE-2026-30930

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module constructs SQL queries using string co…

Fix: 4.5.1+
Fix from $2,300 2026-03-10
Sharepoint Server CRITICAL 9.3
CVE-2026-26105

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20076+
Fix from $2,300 2026-03-10
Linux Kernel CRITICAL 9.8
CVE-2026-23240

In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered du…

Fix: 6.12.75 / 6.18.16+
Fix from $2,300 2026-03-10
Account Management Portal CRITICAL 9.1
CVE-2025-69615

Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. …

Fix: after 2025-10-24
Fix from $2,300 2026-03-10
Account Management Portal CRITICAL 9.4
CVE-2025-69614

Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. A…

Fix: 2025-10-27+
Fix from $2,300 2026-03-10
Limesurvey CRITICAL 9.8
CVE-2025-56422

A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code on the server.

Fix: after 6.14.3
Fix from $2,300 2026-03-10
Unclassified CRITICAL 9.8
CVE-2025-41709

An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write access on the affected device.

Mitigation only
Fix from $2,300 2026-03-10
Unclassified CRITICAL 9.6
CVE-2025-40943

Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code through social engineering an autho…

Mitigation only
Fix from $2,300 2026-03-10
Oneuptime CRITICAL 9.9
CVE-2026-30921

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allow low-privileged project user…

Fix: 10.0.20+
Fix from $2,300 2026-03-10
Oneuptime CRITICAL 9.9
CVE-2026-30887

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/Java…

Fix: 10.0.18+
Fix from $2,300 2026-03-10
Siyuan CRITICAL 9.8
CVE-2026-30869

SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read …

Fix: 3.5.10+
Fix from $2,300 2026-03-10
Appsmith CRITICAL 9.0
CVE-2026-30862

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table …

Fix: 1.96+
Fix from $2,300 2026-03-10
Unclassified CRITICAL 9.1
CVE-2026-27685

SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, …

Mitigation only
Fix from $2,300 2026-03-10
Unclassified CRITICAL 9.8
CVE-2026-0953

The Tutor LMS Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.9.5 via the Social Login addon.…

Mitigation only
Fix from $2,300 2026-03-10
Vantara Pentaho Data Integration And Analytics CRITICAL 9.1
CVE-2025-11158

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT …

Fix: 10.2.0.6+
Fix from $2,300 2026-03-10
Budibase CRITICAL 9.1
CVE-2026-31816EPSS 15%

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() m…

Fix: after 3.31.4
Fix from $2,300 2026-03-09
Vllm CRITICAL 9.8
CVE-2026-25960

vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in…

Fix: 0.17.0+
Fix from $2,300 2026-03-09
Budibase CRITICAL 9.0
CVE-2026-25737

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerabili…

Fix: after 3.24.0
Fix from $2,300 2026-03-09
Twake CRITICAL 9.8
CVE-2025-70039

An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.

Mitigation only
Fix from $2,300 2026-03-09
Oa Font Service CRITICAL 9.8
CVE-2025-70046

An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master.

No fix yet
Fix from $2,300 2026-03-09
Thermakube CRITICAL 9.8
CVE-2025-70042

An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.

Mitigation only
Fix from $2,300 2026-03-09
Easy7 Cms CRITICAL 9.8
CVE-2026-3818

A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebService/GetDBData.jsp. This mani…

Mitigation only
Fix from $2,300 2026-03-09
Jflow CRITICAL 9.8
CVE-2026-3813

A vulnerability was identified in opencc JFlow up to 5badc00db382d7cb82dad231e6a866b18e0addfe. Affected by this vulnerability is the function Calcula…

Mitigation only
Fix from $2,300 2026-03-09
Eventobot CRITICAL 9.8
CVE-2025-40639

A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases thr…

Mitigation only
Fix from $2,300 2026-03-09
Iotdb CRITICAL 9.8
CVE-2026-24713

Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users a…

Fix: 1.3.7 / 2.0.7+
Fix from $2,300 2026-03-09
Iotdb CRITICAL 9.8
CVE-2026-24015

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrad…

Fix: 1.3.7 / 2.0.7+
Fix from $2,300 2026-03-09
Universal Bacnet Router Firmware CRITICAL 9.1
CVE-2025-41765

Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to upload and apply arbitrary d…

Fix: 6.0.1.0+
Fix from $2,300 2026-03-09
Universal Bacnet Router Firmware CRITICAL 9.1
CVE-2025-41764

Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to upload and apply arbitrary u…

Fix: 6.0.1.0+
Fix from $2,300 2026-03-09
Atop Ehg2408 Firmware CRITICAL 9.8
CVE-2026-3823

EHG2408 series switch developed by Atop Technologies has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to co…

Fix: 3.36+
Fix from $2,300 2026-03-09