Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-34048

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket boots…

Patch available
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.9
CVE-2026-34047

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket boots…

Patch available
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.9
CVE-2026-34037

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire a…

Patch available
Fix from $2,300 2026-07-07
Crawl4ai CRITICAL 10.0
CVE-2026-57572

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra…

Fix: 0.9.0+
Fix from $2,300 2026-07-06
Crawl4ai CRITICAL 9.6
CVE-2026-57571

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename w…

Fix: 0.9.0+
Fix from $2,300 2026-07-06
Traefik CRITICAL 10.0
CVE-2026-54763

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewa…

Fix: 2.11.51 / 3.6.22+
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.2
CVE-2026-42341

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerab…

Mitigation only
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.9
CVE-2026-34038

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote …

Patch available
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.8
CVE-2026-11405

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains …

Mitigation only
Fix from $2,300 2026-07-06
Arcgis Server CRITICAL 9.8
CVE-2026-9182

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted fi…

Fix: after 12.0
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.9
CVE-2026-48614

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in …

Mitigation only
Fix from $2,300 2026-07-06
Coldfusion CRITICAL 10.0
CVE-2026-48316

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-07-06
Privileged Remote Access CRITICAL 9.9
CVE-2026-40141

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the process…

Fix: 25.3.3+
Fix from $2,300 2026-07-06
Privileged Remote Access CRITICAL 9.8
CVE-2026-40139

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authenticati…

Fix: 25.3.3+
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.1
CVE-2026-5268

An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allo…

Mitigation only
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.1
CVE-2025-53830

Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for …

Mitigation only
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.1
CVE-2025-53827

ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15…

Mitigation only
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.3
CVE-2026-12686

An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted …

Mitigation only
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-56140

Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-s…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-53913

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48205

Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operatio…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-48204

Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs produce…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-48203

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-46456

Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Ca…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-46455

Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAnd…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-46454

Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers in…

Fix: 4.14.8 / 4.18.3+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.8
CVE-2026-43867

Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetada…

Fix: 4.18.3 / 4.21.0+
Fix from $2,300 2026-07-06
Camel CRITICAL 9.1
CVE-2026-40047

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-doclin…

Fix: 4.18.3+
Fix from $2,300 2026-07-06
Iotdb CRITICAL 9.8
CVE-2026-24014

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici…

Fix: 2.0.8+
Fix from $2,300 2026-07-06
Iotdb CRITICAL 9.1
CVE-2026-24013

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter.…

Fix: 2.0.8+
Fix from $2,300 2026-07-06