Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-51380

Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially e…

Mitigation only
Fix from $2,300 2026-07-15
N8n Mcp CRITICAL 9.9
CVE-2026-54052

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with…

Fix: 2.56.1+
Fix from $2,300 2026-07-15
Unclassified CRITICAL 10.0
CVE-2026-52887

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-49352

9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in s…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 10.0
CVE-2026-46339

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, a…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.5
CVE-2026-46684

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() …

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.0
CVE-2026-45534

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-control…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-46421

The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL da…

Mitigation only
Fix from $2,300 2026-07-15
Openwrt CRITICAL 9.6
CVE-2026-62948

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odh…

Fix: 25.12.5+
Fix from $2,300 2026-07-15
Better Auth\/sso CRITICAL 9.6
CVE-2026-53513

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST…

Fix: 1.6.11+
Fix from $2,300 2026-07-15
Better Auth CRITICAL 9.1
CVE-2026-53512

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth toke…

Fix: 1.6.11+
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-50562

FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted …

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-14960

Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.0
CVE-2026-62378

RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/prev…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-52843

Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached sessi…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-52842

Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of on…

Patch available
Fix from $2,300 2026-07-15
Roomos CRITICAL 9.8
CVE-2026-20157

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte…

Fix: 11.32.6.0 / 11.39.1.1+
Fix from $2,300 2026-07-15
Roomos CRITICAL 9.8
CVE-2026-20156

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte…

Fix: 11.32.6.0 / 11.39.1.1+
Fix from $2,300 2026-07-15
Metabase CRITICAL 9.1
CVE-2026-50148

Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10,…

Fix: 1.54.24 / 1.55.24+
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.9
CVE-2026-44986

Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from …

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-61740

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUN…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.3
CVE-2026-61736

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentia…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.1
CVE-2026-43637

Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache dire…

Patch available
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.6
CVE-2026-61451

The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 10.0
CVE-2026-56699

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to in…

Mitigation only
Fix from $2,300 2026-07-15
Open Webui CRITICAL 9.6
CVE-2026-56400

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated …

Fix: 0.3.14+
Fix from $2,300 2026-07-15
Open Webui CRITICAL 9.0
CVE-2026-56398

Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type i…

Fix: 0.9.5+
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.5
CVE-2026-13385

An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(M…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-5270

An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-5269

In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operation…

No fix yet
Fix from $2,300 2026-07-14