Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-65507

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

No fix yet
Fix from $2,300 2026-08-06
Virtual Storage Integrator CRITICAL 9.8
CVE-2026-54489

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. …

Fix: 10.11.1.0+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-53976

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unau…

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-53975

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands b…

Patch available
Fix from $2,300 2026-08-06
Apr Util CRITICAL 9.1
CVE-2026-34191

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…

Fix: after 1.6.3
Fix from $2,300 2026-08-06
Apr Util CRITICAL 9.1
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an…

Fix: 1.6.4+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-28139

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-28005

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

No fix yet
Fix from $2,300 2026-08-06
Rvtools CRITICAL 9.1
CVE-2026-64993

Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker c…

Fix: 4.8.1+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-5134

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. C…

No fix yet
Fix from $2,300 2026-08-06
Glassfish CRITICAL 9.6
CVE-2026-12605

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled …

Fix: 8.0.4+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.8
CVE-2026-68079

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-65583

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-63687

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-61466

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.8
CVE-2026-66909

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-64597

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt …

No fix yet
Fix from $2,300 2026-08-06
Api Control Plane CRITICAL 10.0
CVE-2026-5430

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t…

Fix: 4.1.0.257 / 4.2.0.197+
Fix from $2,300 2026-08-06
Api Control Plane CRITICAL 9.8
CVE-2026-1728

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitati…

Fix: 4.0.0.384 / 4.1.0.248+
Fix from $2,300 2026-08-06
Api Control Plane CRITICAL 9.4
CVE-2025-15039

The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a…

Fix: 1.4.0.137 / 1.4.0.143+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-16054

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid no…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-12713

The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowin…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-67873

A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encod…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-67870

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remo…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-52466

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming requ…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.3
CVE-2026-67531

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host …

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.6
CVE-2026-71319

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channe…

Patch available
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2025-63823

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentic…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-70615

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission …

No fix yet
Fix from $2,300 2026-08-05
Enterprise Server CRITICAL 9.1
CVE-2026-17556

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and dire…

Fix: 3.17.19 / 3.18.13+
Fix from $2,300 2026-08-05