Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-49457

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshak…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 10.0
CVE-2026-19188

A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-73849

Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately …

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-48528

Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauth…

No fix yet
Fix from $5,750 2026-08-14
Security Center CRITICAL 9.9
CVE-2026-19682

A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary co…

Fix: 6.9.0+
Fix from $5,750 2026-08-14
Security Center CRITICAL 9.9
CVE-2026-19681

An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by…

Fix: 6.9.0+
Fix from $5,750 2026-08-14
Security Center CRITICAL 9.9
CVE-2026-19626

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user …

Fix: 6.9.0+
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.3
CVE-2026-19871

Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to a…

Patch available
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72830

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write schedu…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72829

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. …

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72826

The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in …

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72824

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-tog…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72822

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlik…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 10.0
CVE-2026-72811

SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates s…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-12949

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and i…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.6
CVE-2026-73843

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-f…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73842

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go ex…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-73665

FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socke…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-73663

FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted …

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-73421

NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for …

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-73420

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by th…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73302

Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved a…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-72851

Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers c…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-72850

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are p…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.9
CVE-2026-72842

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management r…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.9
CVE-2026-72841

luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal a…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-72839

filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthen…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-72776

AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arb…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-8715

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication conf…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-19297

IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of exce…

No fix yet
Fix from $2,300 2026-08-13