Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Langflow CRITICAL 9.8
CVE-2026-9205

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

Fix: 1.11.0+
Fix from $2,300 2026-08-05
Langflow CRITICAL 9.1
CVE-2026-8470

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random mod…

Fix: 1.11.0+
Fix from $2,300 2026-08-05
Unclassified CRITICAL 10.0
CVE-2026-48168

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection b…

Patch available
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.0
CVE-2026-70426

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-2…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-20310

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-20304

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-20303

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Ios Xe CRITICAL 9.8
CVE-2026-20272

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Ios Xe CRITICAL 9.0
CVE-2026-20267

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Application Gateway Operator CRITICAL 9.8
CVE-2026-17617

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specif…

Fix: after 26.6.0
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.3
CVE-2026-9195

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an…

Mitigation only
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-9193

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticate…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-9192

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote …

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-9190

An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypa…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-8709

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows …

Mitigation only
Fix from $2,300 2026-08-05
Websphere Application Server CRITICAL 9.8
CVE-2026-8400

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in I…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-7557

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-7329

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.…

No fix yet
Fix from $2,300 2026-08-05
Answer CRITICAL 9.1
CVE-2026-60053

Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained u…

Fix: 2.0.2+
Fix from $2,300 2026-08-05
Build Of Keycloak CRITICAL 9.8
CVE-2026-16442

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs beca…

Fix: 26.4.14 / 26.6.5+
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.4
CVE-2026-15587

Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to…

Mitigation only
Fix from $2,300 2026-08-05
Qradar Security Information And Event Manager CRITICAL 9.8
CVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne…

No fix yet
Fix from $2,300 2026-08-05
Build Of Keycloak CRITICAL 9.1
CVE-2026-16443

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red…

Fix: 26.4.14 / 26.6.5+
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71289

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service'…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71278

rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. Th…

Mitigation only
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-71277

rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never …

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-71268

OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes t…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71267

microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-71263

The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71262

IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersC…

Mitigation only
Fix from $2,300 2026-08-05