Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kotlin CRITICAL 9.8
CVE-2026-53914

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

Fix: 2.4.20+
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.1
CVE-2025-64152

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from …

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.1
CVE-2025-55017

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from …

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57881

An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabil…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57880

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabili…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57879

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabili…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57878

An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabi…

Mitigation only
Fix from $2,300 2026-06-26
Api Manager CRITICAL 10.0
CVE-2026-2053

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled inpu…

Fix: 3.1.0.360 / 3.2.0.465+
Fix from $2,300 2026-06-26
Node.js CRITICAL 9.8
CVE-2026-48930

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolve…

Patch available
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.4
CVE-2026-40702

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit th…

Mitigation only
Fix from $2,300 2026-06-25
Flowise CRITICAL 9.8
CVE-2025-71338

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write …

Fix: after 3.1.3
Fix from $2,300 2026-06-25
Flowise CRITICAL 9.8
CVE-2025-71336

Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feat…

Fix: 3.0.6+
Fix from $2,300 2026-06-25
Flowise CRITICAL 9.8
CVE-2025-71334

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflo…

Fix: 3.0.6+
Fix from $2,300 2026-06-25
Flowise CRITICAL 9.8
CVE-2025-71333

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to …

Fix: after 2.2.4
Fix from $2,300 2026-06-25
Flowise CRITICAL 9.1
CVE-2025-71327

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to…

No fix yet
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.1
CVE-2026-56445

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitizatio…

Mitigation only
Fix from $2,300 2026-06-25
Wolfssl CRITICAL 9.8
CVE-2026-7531

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server…

Fix: 5.9.2+
Fix from $2,300 2026-06-25
Unclassified CRITICAL 10.0
CVE-2026-57700

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n…

Mitigation only
Fix from $2,300 2026-06-25
Rtklib CRITICAL 9.8
CVE-2026-56786

RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buf…

Fix: after 2.4.3
Fix from $2,300 2026-06-25
Seaweedfs CRITICAL 10.0
CVE-2026-54917

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceber…

Fix: 4.30+
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.1
CVE-2026-54089

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting wit…

Mitigation only
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.3
CVE-2026-54088

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Mitigation only
Fix from $2,300 2026-06-25
Cursor CRITICAL 9.8
CVE-2026-50549

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the…

Fix: 3.0+
Fix from $2,300 2026-06-25
Cursor CRITICAL 9.8
CVE-2026-50548

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox gra…

Fix: 3.0+
Fix from $2,300 2026-06-25
Wolfssl CRITICAL 9.1
CVE-2026-6094

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supp…

Fix: 5.9.2+
Fix from $2,300 2026-06-25
Socat CRITICAL 9.8
CVE-2026-56123

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite ad…

Fix: 1.8.1.2+
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.4
CVE-2026-55413

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts…

Mitigation only
Fix from $2,300 2026-06-25
Librechat CRITICAL 9.3
CVE-2026-54030

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implementation does not validate th…

Fix: after 0.8.4
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.3
CVE-2026-54849

Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.

Mitigation only
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.3
CVE-2026-54843

Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

Mitigation only
Fix from $2,300 2026-06-25