Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-58062

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Cast…

Patch available
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-8763

In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java…

Patch available
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-59650

In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS b…

Patch available
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-59638

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bounc…

Patch available
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-65321

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper …

Patch available
Fix from $2,300 2026-08-02
Unclassified CRITICAL 9.6
CVE-2026-68579

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows…

Patch available
Fix from $2,300 2026-08-02
Unclassified CRITICAL 9.8
CVE-2026-16256

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated us…

No fix yet
Fix from $2,300 2026-08-02
Unclassified CRITICAL 9.8
CVE-2026-8457

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to …

No fix yet
Fix from $2,300 2026-08-02
Unclassified CRITICAL 9.8
CVE-2026-67342

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoi…

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67341

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with …

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.9
CVE-2026-67330

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authoriza…

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67324

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default …

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.3
CVE-2026-67308

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submi…

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.4
CVE-2026-67305

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONT…

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67289

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetA…

Patch available
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-66402

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls…

Patch available
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-15964

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and …

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.1
CVE-2026-13596

The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL qu…

Mitigation only
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.1
CVE-2026-3141

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/re…

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-68771

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to exec…

Patch available
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-52134

An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured G…

No fix yet
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-68770

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logi…

Patch available
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-51785

An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request

No fix yet
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-38713

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer…

No fix yet
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-38708

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer…

Mitigation only
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2025-69948

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.

No fix yet
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2025-69946

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_…

No fix yet
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-38711

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer…

No fix yet
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.6
CVE-2026-54725

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in …

Patch available
Fix from $2,300 2026-07-31
Fms Employee CRITICAL 9.8
CVE-2026-21662

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affec…

Fix: after 2025.3.1
Fix from $2,300 2026-07-31