Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Soft Serve CRITICAL 9.1
CVE-2026-30832

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the s…

Fix: 0.11.4+
Fix from $2,300 2026-03-07
Zitadel CRITICAL 9.3
CVE-2026-29191

ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered …

Fix: 4.12.0+
Fix from $2,300 2026-03-07
Backstage Plugin Techdocs Node CRITICAL 9.8
CVE-2026-29186

Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arb…

Fix: 1.14.3+
Fix from $2,300 2026-03-07
Zitadel CRITICAL 9.3
CVE-2026-29067

ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password rese…

Fix: 4.7.1+
Fix from $2,300 2026-03-07
Flowise CRITICAL 9.8
CVE-2026-30824EPSS 36%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvid…

Fix: 3.0.13+
Fix from $2,300 2026-03-07
Flowise CRITICAL 9.8
CVE-2026-30821EPSS 15%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId…

Fix: 3.0.13+
Fix from $2,300 2026-03-07
Zikestor Sks8310 8x Firmware CRITICAL 9.8
CVE-2026-25072

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogi…

Fix: after 1.04.b07
Fix from $2,300 2026-03-07
Zikestor Sks8310 8x Firmware CRITICAL 9.8
CVE-2026-25070

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endp…

Fix: after 1.04.b07
Fix from $2,300 2026-03-07
Immutable CRITICAL 9.8
CVE-2026-29063

Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immuta…

Fix: 3.8.3 / 4.3.7+
Fix from $2,300 2026-03-06
Rocket.chat CRITICAL 9.8
CVE-2026-30831

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, an…

Fix: 7.10.8 / 7.11.5+
Fix from $2,300 2026-03-06
Rocket.chat CRITICAL 9.8
CVE-2026-28514

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, an…

Fix: 7.8.6 / 7.9.8+
Fix from $2,300 2026-03-06
Mesa CRITICAL 9.8
CVE-2026-29075

Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and pri…

Fix: after 3.5.0
Fix from $2,300 2026-03-06
Api.everon.io CRITICAL 9.8
CVE-2026-26288

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-06
Mobiliti E Mobi.hu CRITICAL 9.8
CVE-2026-26051

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent …

Mitigation only
Fix from $2,300 2026-03-06
Php Oop Cms Blog CRITICAL 9.8
CVE-2018-25199

OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious …

Mitigation only
Fix from $2,300 2026-03-06
Tina4 Stack CRITICAL 9.8
CVE-2018-25187

Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection a…

Mitigation only
Fix from $2,300 2026-03-06
Unclassified CRITICAL 9.8
CVE-2026-2331

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to imprope…

Mitigation only
Fix from $2,300 2026-03-06
Unclassified CRITICAL 9.4
CVE-2026-2330

An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain direct…

Mitigation only
Fix from $2,300 2026-03-06
Changedetection CRITICAL 9.1
CVE-2026-29065

changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore func…

Fix: 0.54.4+
Fix from $2,300 2026-03-06
Avideo Encoder CRITICAL 9.8
CVE-2026-29058

AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by inj…

Fix: 7.0+
Fix from $2,300 2026-03-06
Nuclio CRITICAL 9.8
CVE-2026-29042

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a …

Fix: 1.15.20+
Fix from $2,300 2026-03-06
Authlib CRITICAL 9.8
CVE-2026-28802

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passi…

Fix: 1.6.7+
Fix from $2,300 2026-03-06
Openchatbi CRITICAL 9.8
CVE-2026-28795

OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze, and visualize data through n…

Fix: 0.2.2+
Fix from $2,300 2026-03-06
Cocoindex CRITICAL 9.8
CVE-2026-28438

CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify the configured table name befo…

Fix: 0.3.34+
Fix from $2,300 2026-03-06
Unclassified CRITICAL 9.8
CVE-2026-2446

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated use…

Mitigation only
Fix from $2,300 2026-03-06
Orpc CRITICAL 9.8
CVE-2026-28794

oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.6, a prototype pollution v…

Fix: 1.13.6+
Fix from $2,300 2026-03-06
Oneuptime CRITICAL 9.0
CVE-2026-28787

OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does no…

Fix: after 10.0.11
Fix from $2,300 2026-03-06
Ghostfolio CRITICAL 9.8
CVE-2026-28785

Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary …

Fix: 2.244.0+
Fix from $2,300 2026-03-06
Ghostfolio CRITICAL 9.3
CVE-2026-28680

Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform…

Fix: 2.245.0+
Fix from $2,300 2026-03-06
Chartbrew CRITICAL 9.8
CVE-2026-27005

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3…

Fix: 4.8.3+
Fix from $2,300 2026-03-06