Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.6
CVE-2026-15062

SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-58480

Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upl…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.1
CVE-2026-54061

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on th…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-8307

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Inje…

Mitigation only
Fix from $2,300 2026-07-08
Imager CRITICAL 9.8
CVE-2026-14454

Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating …

Fix: 1.033+
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.1
CVE-2026-41042

Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's …

Mitigation only
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-9695

An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged ac…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-12153

The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugi…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-9701

The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.1
CVE-2026-14487

The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDi…

Mitigation only
Fix from $2,300 2026-07-08
Openssh CRITICAL 9.4
CVE-2026-60002

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the cl…

Fix: 10.4+
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.9
CVE-2026-56843

Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they d…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-59705

mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers to read, write, and delete arb…

Patch available
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.8
CVE-2026-37271

Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands wit…

Mitigation only
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.8
CVE-2026-37270

Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence…

Mitigation only
Fix from $2,300 2026-07-07
Dbi CRITICAL 9.1
CVE-2026-14740

DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL …

Fix: 1.650+
Fix from $2,300 2026-07-07
Dbi CRITICAL 9.8
CVE-2026-14739

DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-…

Fix: 1.650+
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.3
CVE-2026-59706

mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request forgery via attacker-controlle…

Patch available
Fix from $2,300 2026-07-07
Coder CRITICAL 9.1
CVE-2026-46354

Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2,…

Fix: 2.24.5 / 2.29.13+
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.1
CVE-2026-58473

Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider conf…

Patch available
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.8
CVE-2026-59800

9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route i…

Mitigation only
Fix from $2,300 2026-07-07
Portal For Arcgis CRITICAL 9.8
CVE-2026-13020

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes…

Fix: after 12.1
Fix from $2,300 2026-07-07
Portal For Arcgis CRITICAL 9.8
CVE-2026-13019

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability a…

Fix: after 12.1
Fix from $2,300 2026-07-07
Data Domain Operating System CRITICAL 9.8
CVE-2026-53483

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug…

Fix: 7.13.1.80 / 8.3.1.40+
Fix from $2,300 2026-07-07
Data Domain Operating System CRITICAL 9.8
CVE-2026-53481

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug…

Fix: 7.13.1.80 / 8.3.1.40+
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.8
CVE-2011-10043

Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to …

Mitigation only
Fix from $2,300 2026-07-07
Airflow CRITICAL 9.8
CVE-2026-33264

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server …

Fix: 3.3.0+
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.0
CVE-2026-4375

The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are a…

Mitigation only
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.8
CVE-2026-14345

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all ve…

Mitigation only
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.8
CVE-2026-12375

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plug…

Mitigation only
Fix from $2,300 2026-07-07