Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sub2api CRITICAL 9.1
CVE-2026-27812

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vulnerability in versions prior t…

Fix: 0.1.85+
Fix from $2,300 2026-02-26
Psd Tools CRITICAL 9.1
CVE-2026-27809

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed …

Fix: 1.12.2+
Fix from $2,300 2026-02-26
Parse Server CRITICAL 9.1
CVE-2026-27804

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an…

Fix: 8.6.3 / 9.3.1+
Fix from $2,300 2026-02-26
Tinyweb CRITICAL 9.8
CVE-2026-27613

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers …

Fix: 2.01+
Fix from $2,300 2026-02-25
N8n CRITICAL 9.9
CVE-2026-27577EPSS 10%

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation o…

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
N8n CRITICAL 9.9
CVE-2026-27495

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
N8n CRITICAL 9.9
CVE-2026-27494

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
N8n CRITICAL 9.0
CVE-2026-27493

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability …

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
Vikunja CRITICAL 9.1
CVE-2026-27575

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 123…

Fix: 2.0.0+
Fix from $2,300 2026-02-25
Storybook CRITICAL 9.6
CVE-2026-27148

Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10…

Fix: 7.6.23 / 8.6.17+
Fix from $2,300 2026-02-25
Freerdp CRITICAL 9.8
CVE-2026-25997

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_clipboard_format_equal` reads freed `lastSentFormats` m…

Fix: 3.23.0+
Fix from $2,300 2026-02-25
Freerdp CRITICAL 9.8
CVE-2026-25959

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprdr_provide_data_` passes freed `pDstData` to `XCha…

Fix: 3.23.0+
Fix from $2,300 2026-02-25
Freerdp CRITICAL 9.8
CVE-2026-25955

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` wh…

Fix: 3.23.0+
Fix from $2,300 2026-02-25
Freerdp CRITICAL 9.8
CVE-2026-25953

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWi…

Fix: 3.23.0+
Fix from $2,300 2026-02-25
Freerdp CRITICAL 9.8
CVE-2026-25952

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow`…

Fix: 3.23.0+
Fix from $2,300 2026-02-25
Unclassified CRITICAL 9.2
CVE-2026-0542

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an…

Mitigation only
Fix from $2,300 2026-02-25
Aria Operations CRITICAL 9.0
CVE-2026-22720

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be abl…

Fix: 5.2.3 / 8.18.6+
Fix from $2,300 2026-02-25
Unclassified CRITICAL 9.2
CVE-2026-27739

The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-S…

Patch available
Fix from $2,300 2026-02-25
Junos Os Evolved CRITICAL 9.8
CVE-2026-21902EPSS 18%

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved…

Mitigation only
Fix from $2,300 2026-02-25
Unclassified CRITICAL 9.8
CVE-2026-27849

Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normall…

Mitigation only
Fix from $2,300 2026-02-25
Mchange Commons Java CRITICAL 9.8
CVE-2026-27727

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including suppo…

Fix: 0.4.0+
Fix from $2,300 2026-02-25
Catalyst Sd Wan Manager CRITICAL 9.8
CVE-2026-20129

A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an …

Fix: 20.9.8.2 / 20.12.5.3+
Fix from $2,300 2026-02-25
Catalyst Sd Wan Manager CRITICAL 10.0
CVE-2026-20127 KEVEPSS 88%

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD…

Fix: 20.9.8.2 / 20.12.5.3+
Fix from $2,300 2026-02-25
Unclassified CRITICAL 9.8
CVE-2026-27848

Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as…

Mitigation only
Fix from $2,300 2026-02-25
Unclassified CRITICAL 9.8
CVE-2026-27847

Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inj…

Mitigation only
Fix from $2,300 2026-02-25
Budibase CRITICAL 9.0
CVE-2026-27702

Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability i…

Fix: 3.30.4+
Fix from $2,300 2026-02-25
Asbplayer CRITICAL 9.6
CVE-2025-69771

Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execut…

Fix: after 1.13.0
Fix from $2,300 2026-02-25
Unclassified CRITICAL 9.1
CVE-2025-1242

The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware revers…

Mitigation only
Fix from $2,300 2026-02-25
Sz Boot Parent CRITICAL 9.8
CVE-2026-3187

A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api…

Fix: after 0.9.0
Fix from $2,300 2026-02-25
Basic Ftp CRITICAL 9.8
CVE-2026-27699

The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` m…

Fix: 5.2.0+
Fix from $2,300 2026-02-25