Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-54836

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue af…

Mitigation only
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.9
CVE-2026-54823

Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

Mitigation only
Fix from $2,300 2026-06-25
Wyse Management Suite CRITICAL 9.8
CVE-2026-41120

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low …

Fix: 5.5+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53260

In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req(). syzbot re…

Fix: 7.0.13+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53247

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown mtk_fre…

Fix: 6.6.143 / 6.12.94+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53246

In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing When a l…

Fix: 6.18.36 / 7.0.13+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53228

In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() cach…

Fix: 5.10.259 / 5.15.210+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.1
CVE-2026-53225

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup()…

Fix: 5.10.259 / 5.15.210+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.1
CVE-2026-53224

In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpa…

Fix: 6.18.36 / 7.0.13+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53221

In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(…

Fix: 5.10.259 / 5.15.210+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53216

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer mvpp2 has short and long BM p…

Fix: 5.15.210 / 6.1.176+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53215

In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns t…

Fix: 5.8 / 5.15.210+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.1
CVE-2026-53186

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() cop…

Fix: 5.10.259 / 5.15.210+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53176

In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband…

Fix: 5.10.259 / 5.15.210+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53175

In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns t…

Fix: 6.18.36 / 7.0.13+
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.8
CVE-2026-53151

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table for parsing Fix modificatio…

Fix: 6.6.144 / 6.12.95+
Fix from $2,300 2026-06-25
Unclassified CRITICAL 10.0
CVE-2026-46752

Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are r…

Mitigation only
Fix from $2,300 2026-06-25
Linux Kernel CRITICAL 9.4
CVE-2026-53131

In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt…

Fix: 5.15.210 / 6.1.176+
Fix from $2,300 2026-06-25
Unclassified CRITICAL 9.4
CVE-2026-41566

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are re…

Mitigation only
Fix from $2,300 2026-06-25
Insightconnect Traceroute CRITICAL 9.8
CVE-2026-8666

OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute ar…

Fix: 1.0.3+
Fix from $2,300 2026-06-25
Insightconnect Translate CRITICAL 9.8
CVE-2026-8665

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary O…

Fix: 2.0.3+
Fix from $2,300 2026-06-25
Insightconnect Ping CRITICAL 9.8
CVE-2026-8660

OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS c…

Fix: 1.0.4+
Fix from $2,300 2026-06-25
Insightconnect Awk CRITICAL 9.8
CVE-2026-8592

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbit…

Fix: 1.2.2+
Fix from $2,300 2026-06-25
Cacti CRITICAL 9.8
CVE-2026-40079

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sani…

Fix: 1.2.31+
Fix from $2,300 2026-06-25
Cacti CRITICAL 9.8
CVE-2026-39955

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FI…

Fix: 1.2.31+
Fix from $2,300 2026-06-24
Cacti CRITICAL 9.8
CVE-2026-39948

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the …

Fix: 1.2.31+
Fix from $2,300 2026-06-24
Cacti CRITICAL 9.8
CVE-2026-39938

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtoo…

Fix: 1.2.31+
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.3
CVE-2026-55666

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.0
CVE-2026-55570

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, descri…

Mitigation only
Fix from $2,300 2026-06-24
Appsmith CRITICAL 9.1
CVE-2026-55455

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (…

Fix: 2.1+
Fix from $2,300 2026-06-24