Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Crawl4ai CRITICAL 9.1
CVE-2026-56260

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path param…

Fix: 0.8.7+
Fix from $2,300 2026-07-12
Unclassified CRITICAL 10.0
CVE-2026-61447

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without…

Mitigation only
Fix from $2,300 2026-07-11
Unclassified CRITICAL 9.9
CVE-2026-61445

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation a…

Mitigation only
Fix from $2,300 2026-07-11
Unclassified CRITICAL 9.8
CVE-2026-60090

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() …

Patch available
Fix from $2,300 2026-07-11
Imagemagick CRITICAL 9.1
CVE-2026-56372

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory…

Fix: 7.1.2-19+
Fix from $2,300 2026-07-11
Rsfiles\! CRITICAL 9.8
CVE-2026-57827

Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unaut…

Fix: 1.17.12+
Fix from $2,300 2026-07-11
Unclassified CRITICAL 9.1
CVE-2026-15089

vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.

No fix yet
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-20744

The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.

Mitigation only
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.9
CVE-2026-14480

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application store…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-11913

vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.

No fix yet
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.2
CVE-2026-55884

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on…

Patch available
Fix from $2,300 2026-07-10
Formatter Field CRITICAL 9.8
CVE-2026-12535

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This …

Fix: 2.0.0+
Fix from $2,300 2026-07-10
Localgov Workflows CRITICAL 9.8
CVE-2026-10768

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0…

Fix: 1.6.0+
Fix from $2,300 2026-07-10
Alternativecommerce CRITICAL 9.8
CVE-2026-9726

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Obj…

Fix: 2.1.17+
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-57807

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Cli…

Mitigation only
Fix from $2,300 2026-07-10
Rabbitmq Server CRITICAL 10.0
CVE-2026-57216

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication c…

Fix: 4.2.6+
Fix from $2,300 2026-07-10
Rabbitmq Server CRITICAL 10.0
CVE-2026-57211

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm…

Fix: 4.2.6+
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.3
CVE-2026-55879

OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page…

Patch available
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-12761

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to …

Mitigation only
Fix from $2,300 2026-07-10
Freerdp CRITICAL 9.1
CVE-2026-57158

FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incompl…

Fix: 3.28.0+
Fix from $2,300 2026-07-10
Freerdp CRITICAL 9.8
CVE-2026-57156

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in upd…

Fix: 3.28.0+
Fix from $2,300 2026-07-10
Mcp Server Kubernetes CRITICAL 9.8
CVE-2026-61459

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) t…

Fix: 3.9.0+
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-5801

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Lt…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.6
CVE-2026-59151

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when de…

Patch available
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-2397

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.2
CVE-2026-58492

grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a…

Patch available
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.1
CVE-2026-51119

An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components

Mitigation only
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.9
CVE-2026-55500

9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, …

Patch available
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.3
CVE-2026-15143

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Sc…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.1
CVE-2026-61444

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated int…

Mitigation only
Fix from $2,300 2026-07-10