Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 1607 CRITICAL 9.8
CVE-2026-50694

Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-50522 KEVEPSS 85%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.3
CVE-2026-49798

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-49181

Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-49172

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-49164

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
365 Copilot CRITICAL 9.6
CVE-2026-48561

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …

Mitigation only
Fix from $2,300 2026-07-14
Windows 10 1607 CRITICAL 9.8
CVE-2026-42990

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-15701

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.…

Mitigation only
Fix from $2,300 2026-07-14
Webmail CRITICAL 9.8
CVE-2026-62644

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session …

Fix: 1.6.17 / 1.7.2+
Fix from $2,300 2026-07-14
Webmail CRITICAL 10.0
CVE-2026-62643

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to…

Fix: 1.6.17 / 1.7.2+
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-60082

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source …

Patch available
Fix from $2,300 2026-07-14
Forticlientems CRITICAL 9.8
CVE-2026-59836

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.…

Fix: 7.4.6+
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-55954

Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.…

Patch available
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.2
CVE-2025-11698

A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a m…

Mitigation only
Fix from $2,300 2026-07-14
Sustainable Irrigation Platform CRITICAL 9.8
CVE-2026-58479

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allow…

Fix: after 5.2.16
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-15265

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intende…

Mitigation only
Fix from $2,300 2026-07-14
Zephyr CRITICAL 9.1
CVE-2026-10672

subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PA…

Patch available
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.2
CVE-2025-12012

A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file dat…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.2
CVE-2025-12011

A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, caus…

Mitigation only
Fix from $2,300 2026-07-14
Kylin CRITICAL 9.8
CVE-2026-62392

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…

Fix: 5.0.4+
Fix from $2,300 2026-07-14
Kylin CRITICAL 9.8
CVE-2026-62390

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…

Fix: 5.0.4+
Fix from $2,300 2026-07-14
Unclassified CRITICAL 10.0
CVE-2026-10577

A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce…

Mitigation only
Fix from $2,300 2026-07-14
Youtrack CRITICAL 9.8
CVE-2026-62422

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct…

Fix: 2024.2.148429 / 2024.3.148430+
Fix from $2,300 2026-07-14
Doris CRITICAL 9.1
CVE-2026-58319

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access …

Fix: 3.1.0+
Fix from $2,300 2026-07-14
Unclassified CRITICAL 10.0
CVE-2026-56451

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in t…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-3014

Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. …

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-15043

DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engin…

Patch available
Fix from $2,300 2026-07-14
Tomcat CRITICAL 9.1
CVE-2026-59084

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clea…

Fix: after 11.0.23
Fix from $2,300 2026-07-14
Tomcat CRITICAL 9.1
CVE-2026-59083

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configura…

Fix: after 11.0.23
Fix from $2,300 2026-07-14