Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-63087

Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sen…

No fix yet
Fix from $2,300 2026-07-16
Yamcs CRITICAL 9.1
CVE-2026-46621

Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated us…

Fix: 5.12.7+
Fix from $2,300 2026-07-16
Yamcs CRITICAL 9.8
CVE-2026-46562

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-cor…

Fix: 5.12.7+
Fix from $2,300 2026-07-16
Zrok CRITICAL 9.1
CVE-2026-45568

zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an ab…

Fix: 2.0.3+
Fix from $2,300 2026-07-16
Yamcs CRITICAL 9.1
CVE-2026-44632

Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine or…

Fix: 5.12.7+
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-3031

Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated …

No fix yet
Fix from $2,300 2026-07-16
Yamcs CRITICAL 9.8
CVE-2026-44596

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/jav…

Fix: 5.12.7+
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-59866

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceNa…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-59865

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.d…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-59864

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.3
CVE-2026-54733

The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0…

Patch available
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-45695

Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, an…

Patch available
Fix from $2,300 2026-07-16
Sglang CRITICAL 9.1
CVE-2026-14890

SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authenticatio…

Fix: after 0.5.14
Fix from $2,300 2026-07-16
Dfxanalytics CRITICAL 9.8
CVE-2026-56453

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents o…

Fix: after 3.0
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.0
CVE-2026-11386

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT so…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2023-49900

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2023-49899

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channe…

Mitigation only
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.6
CVE-2026-22752

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Serv…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.2
CVE-2026-15925

Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacke…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-12492

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authent…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-15013

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all version…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-55652

Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLogi…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-55445

Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in bac…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.6
CVE-2026-54458

WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin.…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.2
CVE-2026-52893

Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into …

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.9
CVE-2026-52891

Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passe…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-30623

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP serv…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-30618

xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker …

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.1
CVE-2026-26718

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2025-65720

An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted H…

Mitigation only
Fix from $2,300 2026-07-15