Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Websphere Application Server CRITICAL 9.3
CVE-2026-11707

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-07-30
Vcenter Server CRITICAL 9.8
CVE-2026-59310 KEV

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i…

Fix: 8.0 / 9.0.2.0100+
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-59309

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may …

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.1
CVE-2026-54363

CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted token…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.3
CVE-2026-47876

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileg…

No fix yet
Fix from $2,300 2026-07-30
PHP CRITICAL 9.8
CVE-2026-17544

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and…

Fix: 8.4.24 / 8.5.9+
Fix from $2,300 2026-07-30
PHP CRITICAL 9.8
CVE-2026-17543

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from…

Fix: 8.2.33 / 8.3.33+
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.1
CVE-2026-18363

A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the pas…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-7849

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration whic…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-44108

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a tempor…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-44104

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verificat…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-44101

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can …

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.4
CVE-2026-44100

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UI…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.1
CVE-2026-44092

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches fro…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.1
CVE-2026-44091

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system conf…

Mitigation only
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-44090

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firew…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-58066

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind t…

Patch available
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.9
CVE-2026-58046

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data f…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.0
CVE-2026-14602

The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attack…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-16610

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via…

No fix yet
Fix from $2,300 2026-07-30
Campaign CRITICAL 9.8
CVE-2026-48449

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …

Fix: after 7.4.2
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-18015

Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-18002

Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the r…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17991

Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer p…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17990

Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rend…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17987

Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17947

Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17940

Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17924

Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perfo…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17865

Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer proc…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30