Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2024-51312

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-53595

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{h…

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.8
CVE-2024-51313

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.8
CVE-2024-51311

The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-63767

ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers t…

Patch available
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-63766

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate…

Mitigation only
Fix from $2,300 2026-07-20
Request Tracker CRITICAL 9.1
CVE-2026-44231

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an informa…

Fix: 5.0.10 / 6.0.3+
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-16337

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a …

Patch available
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-64193

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose pars…

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.1
CVE-2026-62414

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply ac…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified CRITICAL 10.0
CVE-2026-61900

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-61425

Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, poten…

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 10.0
CVE-2026-61424

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vuln…

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-60034

Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS …

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-60032

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authentic…

No fix yet
Fix from $2,300 2026-07-20
Identityiq CRITICAL 9.8
CVE-2026-12341

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to im…

Fix: 8.3+
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.3
CVE-2026-39878

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenti…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.9
CVE-2026-54051

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`San…

Patch available
Fix from $2,300 2026-07-20
Xrdp CRITICAL 9.1
CVE-2026-41521

xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within …

Fix: 0.10.6.1+
Fix from $2,300 2026-07-20
Xrdp CRITICAL 9.8
CVE-2026-41252

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when o…

Fix: 0.10.6.1+
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-35048

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configurat…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.9
CVE-2026-51027

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

Mitigation only
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.1
CVE-2026-46428

lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` inte…

Patch available
Fix from $2,300 2026-07-20
Unclassified CRITICAL 10.0
CVE-2026-46412

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UT…

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.0
CVE-2026-35198

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a l…

Patch available
Fix from $2,300 2026-07-20
Wazuh CRITICAL 9.1
CVE-2026-28220

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distribu…

Fix: 4.14.5+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-63071

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can crea…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-62183

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user wor…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-57308

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-53421

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code ex…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20