Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Appsmith CRITICAL 9.9
CVE-2026-55454

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has n…

Fix: 2.1+
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.9
CVE-2026-54158

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolate…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.2
CVE-2026-54069

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server unconditionally trusts all chrome-ext…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.9
CVE-2026-54067

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <st…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.9
CVE-2026-50551

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in t…

Mitigation only
Fix from $2,300 2026-06-24
Cacti CRITICAL 9.8
CVE-2026-39893

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into …

Fix: 1.2.31+
Fix from $2,300 2026-06-24
Unclassified CRITICAL 10.0
CVE-2026-52813

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, a…

Patch available
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.0
CVE-2026-52811

Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload tar…

Patch available
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.9
CVE-2026-52806EPSS 8%

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server…

Patch available
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.3
CVE-2026-46423

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-45689

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-45688

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.3
CVE-2026-33543

FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/creat…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.6
CVE-2026-53943

Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being sh…

Mitigation only
Fix from $2,300 2026-06-24
Rclone CRITICAL 9.8
CVE-2026-49980

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --…

Fix: 1.74.3+
Fix from $2,300 2026-06-24
Chrome CRITICAL 9.6
CVE-2026-13032

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 149.0.7827.197+
Fix from $2,300 2026-06-24
Chrome CRITICAL 9.6
CVE-2026-13028

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a c…

Fix: 149.0.7827.197+
Fix from $2,300 2026-06-24
Concurrent Ruby CRITICAL 9.8
CVE-2026-54906

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling…

Fix: 1.3.7+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-53088

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb The write_ptr points to the …

Fix: 3.17 / 5.10.258+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-53086

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmgenet_timeout handler tries to…

Fix: 6.1.175 / 6.6.141+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-53055

In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-free for sec During packet tran…

Fix: 6.18.33 / 7.0.10+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-53049

In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing …

Fix: 5.15.209 / 6.1.175+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-53046

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine ksmbd_cry…

Fix: 5.15.209 / 6.1.175+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-53045

In the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change check The code checking whether the specif…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.1
CVE-2026-53043

In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regions() Patch series "ocfs2/dl…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-53010

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durable reconnect In smb2_open, t…

Fix: 6.7 / 6.18.33+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-53002

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffe…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-53006

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching saddr and daddr before pskb_pull…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.1
CVE-2026-52999

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching In nf_osf_m…

Fix: 4.20 / 5.0+
Fix from $2,300 2026-06-24
Linux Kernel CRITICAL 9.8
CVE-2026-52993

In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_msg_validate() can potentially …

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-24