Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-54680

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer Fluen…

Patch available
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-51992

SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries …

Mitigation only
Fix from $2,300 2026-07-29
Undici CRITICAL 9.1
CVE-2026-13697

undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a…

Fix: 7.29.0 / 8.9.0+
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-67191

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write…

No fix yet
Fix from $2,300 2026-07-29
Ait Dsn CRITICAL 9.8
CVE-2026-60113

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Exte…

Fix: 2.2.2+
Fix from $2,300 2026-07-29
Ait Gui CRITICAL 9.8
CVE-2026-60112

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to o…

Fix: 2.5.1+
Fix from $2,300 2026-07-29
Prebid Server CRITICAL 10.0
CVE-2026-54735

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in …

Fix: 4.4.0+
Fix from $2,300 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65888

Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65887

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any u…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.4
CVE-2026-9177

A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in vers…

No fix yet
Fix from $2,300 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65890

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65884

Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing una…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.3
CVE-2026-0667

CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of …

No fix yet
Fix from $2,300 2026-07-29
Aimy Captcha Less Form Guard CRITICAL 9.8
CVE-2026-65883

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP o…

Fix: after 20.0
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-14900

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to…

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-14488

The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission exten…

No fix yet
Fix from $2,300 2026-07-29
Apache Airflow Providers Fab CRITICAL 9.8
CVE-2026-59243

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or…

Fix: 3.7.3+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.8
CVE-2026-58185

The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 thro…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.8
CVE-2026-58179

The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: fro…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.8
CVE-2026-58177

The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Se…

Fix: 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.1
CVE-2026-58163

Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: …

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 10.0
CVE-2026-58162

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server:…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-10656

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions u…

No fix yet
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.3
CVE-2026-58155

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Tr…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 10.0
CVE-2026-58150

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic …

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 10.0
CVE-2026-57834

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.3
CVE-2026-41920

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 thr…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Traffic Server CRITICAL 9.1
CVE-2026-33267

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 t…

Fix: 9.2.15 / 10.1.4+
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-18191

VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden fu…

Mitigation only
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.9
CVE-2026-63234

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessmen…

No fix yet
Fix from $2,300 2026-07-29