Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Langflow CRITICAL 9.8
CVE-2026-9103

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/a…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-9202

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_A…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-9198 KEVEPSS 37%

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.3
CVE-2026-9586

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning…

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-8297

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laborato…

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.3
CVE-2026-54496

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.…

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.1
CVE-2026-12694

Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This…

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.4
CVE-2026-12693

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly…

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-12692

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Vide…

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-60024

Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0…

No fix yet
Fix from $2,300 2026-07-17
Libpve Storage Perl CRITICAL 9.8
CVE-2026-51080

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.1
CVE-2024-23564

HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server …

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-9810

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator …

Mitigation only
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-15982

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in al…

Mitigation only
Fix from $2,300 2026-07-17
Clawvet CRITICAL 9.1
CVE-2026-62241EPSS 7%

clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as t…

Fix: 0.7.5+
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-14956

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper val…

No fix yet
Fix from $2,300 2026-07-17
Enterprise Gateway CRITICAL 10.0
CVE-2026-44182

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In v…

Fix: 3.3.0+
Fix from $2,300 2026-07-16
Enterprise Gateway CRITICAL 10.0
CVE-2026-44181

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In v…

Fix: 3.3.0+
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.1
CVE-2026-57075

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in t…

Patch available
Fix from $2,300 2026-07-16
Workplace Desktop CRITICAL 9.8
CVE-2026-53412

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthentica…

Fix: 6.5.18 / 6.6.15+
Fix from $2,300 2026-07-16
Enterprise Gateway CRITICAL 9.8
CVE-2026-44180

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Vers…

Fix: 3.3.0+
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-38158

A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database inform…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-63089

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows un…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.1
CVE-2026-15422

The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chu…

Patch available
Fix from $2,300 2026-07-16
Argo Workflows CRITICAL 9.9
CVE-2026-54526

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow…

Fix: 3.7.15 / 4.0.6+
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-46515

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pin…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.9
CVE-2026-46512

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, de…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 10.0
CVE-2026-45336

HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier,…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.1
CVE-2026-57074

XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter stri…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.1
CVE-2026-57073

HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter str…

Patch available
Fix from $2,300 2026-07-16