Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Langflow CRITICAL 9.8
CVE-2026-7663

IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t…

Fix: 1.10.0+
Fix from $2,300 2026-06-30
Websphere Extreme Scale CRITICAL 10.0
CVE-2026-13773EPSS 6%

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme Scale's ogclient.jar call ORB.…

Fix: after 8.6.1.6
Fix from $2,300 2026-06-30
Websphere Extreme Scale CRITICAL 9.9
CVE-2026-13772

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and in…

Fix: after 8.6.1.6
Fix from $2,300 2026-06-30
Business Automation Manager CRITICAL 9.1
CVE-2026-13449

IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML …

Fix: 9.5.0+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.8
CVE-2026-11714

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.

Fix: 26.0.0.8+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11712

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console help system.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.3
CVE-2026-11708

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console's integrated help sys…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-06-30
Websphere Application Server CRITICAL 9.8
CVE-2026-11546

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulnerability with the adminCenter-…

Fix: 26.0.0.8+
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.1
CVE-2026-10560

IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenti…

Fix: after 1.9.6
Fix from $2,300 2026-06-30
Langflow CRITICAL 9.6
CVE-2026-10140

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. A…

Fix: after 1.10.0
Fix from $2,300 2026-06-30
Langflow CRITICAL 10.0
CVE-2026-10134

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversat…

Fix: after 1.9.3
Fix from $2,300 2026-06-30
Db2 CRITICAL 9.8
CVE-2026-10109

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

Fix: after 12.1.4
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-58138EPSS 9%

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitra…

Patch available
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.1
CVE-2026-58172

Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based ac…

Patch available
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.1
CVE-2026-58166

OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write…

Patch available
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 9.3
CVE-2026-48315

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 9.3
CVE-2026-48313

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Mitigation only
Fix from $2,300 2026-06-30
Campaign CRITICAL 10.0
CVE-2026-48286

Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbi…

Fix: after 7.4.3
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 10.0
CVE-2026-48283

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in…

Mitigation only
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 10.0
CVE-2026-48281

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 10.0
CVE-2026-48277

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 10.0
CVE-2026-48276

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in…

Mitigation only
Fix from $2,300 2026-06-30
Coldfusion CRITICAL 10.0
CVE-2026-48282 KEVEPSS 42%

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Mitigation only
Fix from $2,300 2026-06-30
Firefox CRITICAL 9.8
CVE-2026-14241

Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of…

Mitigation only
Fix from $2,300 2026-06-30
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2026-8655

Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service …

Fix: 13.1-37.272 / 13.1-63.18+
Fix from $2,300 2026-06-30
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2026-8452

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the applian…

Fix: 13.1-37.272 / 13.1-63.18+
Fix from $2,300 2026-06-30
Fastify\/express CRITICAL 9.1
CVE-2026-6556

@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string …

Fix: 4.0.7+
Fix from $2,300 2026-06-30
Enterprise Linux CRITICAL 9.1
CVE-2026-58016

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malfo…

Fix: 2.88.1+
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-8402

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer In…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.3
CVE-2026-53690

An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The ap…

Mitigation only
Fix from $2,300 2026-06-30