Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Linux Kernel CRITICAL 9.8
CVE-2026-63800

In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RE…

Fix: 5.5 / 5.10.260+
Fix from $2,300 2026-07-19
Linux Kernel CRITICAL 10.0
CVE-2026-63795

In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() i…

Fix: 6.1.177 / 6.6.144+
Fix from $2,300 2026-07-19
Linux Kernel CRITICAL 9.8
CVE-2026-53399

In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the n…

Fix: 5.10.261 / 5.15.212+
Fix from $2,300 2026-07-19
Linux Kernel CRITICAL 9.8
CVE-2026-53398

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() c…

Fix: 5.10.260 / 5.15.211+
Fix from $2,300 2026-07-19
Linux Kernel CRITICAL 9.8
CVE-2026-53384

In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_p…

Fix: 6.1.177 / 6.6.144+
Fix from $2,300 2026-07-19
Fastify\/http Proxy CRITICAL 10.0
CVE-2026-16117

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's …

Fix: 11.6.0+
Fix from $2,300 2026-07-18
Fastify\/reply From CRITICAL 10.0
CVE-2026-16158

Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and …

Fix: 12.6.4+
Fix from $2,300 2026-07-18
Fastify\/http Proxy CRITICAL 10.0
CVE-2026-15631

Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the confi…

Fix: 11.6.0+
Fix from $2,300 2026-07-18
Vmware Avi Load Balancer CRITICAL 9.8
CVE-2026-47865

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control …

Fix: 22.1.7 / 30.2.7+
Fix from $2,300 2026-07-18
Unclassified CRITICAL 9.6
CVE-2026-55518

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_…

Patch available
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-52348

cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 10.0
CVE-2026-54159

PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected s…

Patch available
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-48062

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php check…

Patch available
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-13446

IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound aut…

Fix: 1.10.2+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8859

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validat…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8635

IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute a…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-8505

IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the exec…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8481

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/va…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-8476

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache …

Fix: 1.10.1+
Fix from $2,300 2026-07-17
WordPress CRITICAL 9.8
CVE-2026-63030 KEVEPSS 98%

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…

Fix: 6.9.5 / 7.0.2+
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.1
CVE-2026-52199

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

Mitigation only
Fix from $2,300 2026-07-17
Setup Php CRITICAL 9.8
CVE-2026-46420

setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivamma…

Fix: 2.37.1+
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.1
CVE-2026-42168

django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passe…

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-36669

An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious…

No fix yet
Fix from $2,300 2026-07-17
Agentics CRITICAL 9.8
CVE-2026-14501

IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to th…

Fix: 1.1.3+
Fix from $2,300 2026-07-17
Engineering Ai Hub CRITICAL 9.3
CVE-2026-15091

IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input dur…

Fix: 1.3.0+
Fix from $2,300 2026-07-17
Storage Protect CRITICAL 9.8
CVE-2026-13473

IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer o…

Fix: 8.2.1.2+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-13448

IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint (…

Fix: 1.10.2+
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.1
CVE-2025-51677

An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead t…

No fix yet
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.9
CVE-2026-9135

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulner…

Fix: 1.10.1+
Fix from $2,300 2026-07-17