Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.4
CVE-2026-23561

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure d…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2026-23560

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure d…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2026-23559

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2026-23556

When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the …

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2025-58151

varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mappi…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2025-58146

There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notification using the unsanitised in…

No fix yet
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2025-27464

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drive…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2025-27463

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drive…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.4
CVE-2025-27462

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV dri…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.1
CVE-2026-14261

A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, e…

Patch available
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-12116

A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PH…

Patch available
Fix from $2,300 2026-07-09
Forms CRITICAL 9.8
CVE-2026-56291 KEVEPSS 15%

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to…

Fix: 2.4.1+
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-5955

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticare…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.3
CVE-2026-2342

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp al…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-15158

The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachmen…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-14245

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Acc…

Mitigation only
Fix from $2,300 2026-07-09
Bosh Cli CRITICAL 9.1
CVE-2026-47826

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.…

Fix: 7.10.4+
Fix from $2,300 2026-07-09
Unclassified CRITICAL 10.0
CVE-2026-54782

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0…

Patch available
Fix from $2,300 2026-07-08
Chrome CRITICAL 9.6
CVE-2026-15113

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via …

Fix: 150.0.7871.115+
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-52200

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint …

Mitigation only
Fix from $2,300 2026-07-08
Hl7 Fhir Core CRITICAL 9.1
CVE-2026-55471

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.Xslt…

Fix: 6.9.10+
Fix from $2,300 2026-07-08
Fluentd CRITICAL 9.8
CVE-2026-44024

Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allo…

Fix: 1.19.3+
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-31309

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to…

Patch available
Fix from $2,300 2026-07-08
Jupyterlab Git CRITICAL 9.0
CVE-2026-54527

JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames direct…

Fix: 0.54.0+
Fix from $2,300 2026-07-08
Moveit Transfer CRITICAL 9.8
CVE-2026-8801

Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.…

Fix: 2025.0.8 / 2025.1.4+
Fix from $2,300 2026-07-08
Moveit Transfer CRITICAL 9.8
CVE-2026-8649

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affec…

Fix: 2025.0.7 / 2025.1.3+
Fix from $2,300 2026-07-08
U Boot CRITICAL 9.8
CVE-2026-29009

U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowin…

Fix: 2026.04+
Fix from $2,300 2026-07-08
Api Connect CRITICAL 9.8
CVE-2026-9074

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset…

Fix: 10.0.8.10 / 12.1.1.0+
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.3
CVE-2026-59702

repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary o…

Patch available
Fix from $2,300 2026-07-08
Api Connect CRITICAL 9.8
CVE-2026-3144

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application befor…

Fix: 12.1.1.0+
Fix from $2,300 2026-07-08