Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-69936

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69935

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69934

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69933

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

Mitigation only
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69930

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-65336

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.

Mitigation only
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-67594

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-67208

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by …

No fix yet
Fix from $2,300 2026-07-30
Tika CRITICAL 9.8
CVE-2026-66756

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a…

No fix yet
Fix from $2,300 2026-07-30
Langflow CRITICAL 9.9
CVE-2026-12946

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input…

Fix: 1.10.1+
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.5
CVE-2026-66066

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not di…

Patch available
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-51272

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() character encoding conversion function. …

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.3
CVE-2026-48499

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut…

Patch available
Fix from $2,300 2026-07-30
Sglang CRITICAL 9.8
CVE-2026-15976

SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from…

Fix: after 0.5.15
Fix from $2,300 2026-07-30
Sglang CRITICAL 9.8
CVE-2026-15971

SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, ena…

Fix: after 0.5.15
Fix from $2,300 2026-07-30
Sglang CRITICAL 9.8
CVE-2026-15969

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma…

Fix: after 0.5.15
Fix from $2,300 2026-07-30
Langflow CRITICAL 9.9
CVE-2026-13435

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.

Fix: 1.10.2+
Fix from $2,300 2026-07-30
Hardware Management Console CRITICAL 9.8
CVE-2026-12943

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)…

Fix: 10.3.1064.1 / 11.1.1112.1+
Fix from $2,300 2026-07-30
Webmethods Integration CRITICAL 9.8
CVE-2026-12118

IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-51291

sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.1
CVE-2026-51290

SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module. The program frees a BtLock structure wi…

No fix yet
Fix from $2,300 2026-07-30
Openvpn CRITICAL 9.1
CVE-2026-13379

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service cras…

Fix: 2.7.5+
Fix from $2,300 2026-07-30
Langflow CRITICAL 9.8
CVE-2026-12940

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model C…

Fix: 1.10.2+
Fix from $2,300 2026-07-30
Kyuubi CRITICAL 9.8
CVE-2026-52680

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …

Fix: 1.12.0+
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-4978

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL …

No fix yet
Fix from $2,300 2026-07-30
Jspwiki CRITICAL 9.8
CVE-2026-28812

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende…

Fix: 2.12.4+
Fix from $2,300 2026-07-30
Web Help Desk CRITICAL 9.8
CVE-2026-28323

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to b…

Fix: 2026.2.1+
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.1
CVE-2026-53431

Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion…

Patch available
Fix from $2,300 2026-07-30
App Connect Enterprise CRITICAL 9.8
CVE-2026-15435

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $2,300 2026-07-30
App Connect Enterprise CRITICAL 9.8
CVE-2026-14522

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $2,300 2026-07-30