Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-52989 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers Currentl… Linux Kernel 5.11 / 5.16+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-52986 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strtoul Replace unsafe port parsi… Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-52982 In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a… Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-52958 In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding os… Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-52955 In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crush_decode() A message of type… Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-56121 Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code exe… Patch available Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-56111 Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-bounds write vulnerability in… Patch available Fix from $2,3002026-06-24 CRITICAL 9.6 CVE-2026-56351 n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inje… N8n 2.4.0+ Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-56237 Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, … Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-52931 In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender vars batadv_tp_recv_ack() and … Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-52924 In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only… Linux Kernel 5.10.259 / 5.15.210+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-52914 In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a runnin… Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-12417 The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in ver… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-12416 The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is … Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-12851 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-12850 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-12849 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network… Mitigation only Fix from $2,3002026-06-24 CRITICAL 10.0 CVE-2026-12848 GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru… Mitigation only Fix from $2,3002026-06-24 CRITICAL 10.0 CVE-2026-12847 GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru… Mitigation only Fix from $2,3002026-06-24 CRITICAL 10.0 CVE-2026-12846 GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-12486 Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network… Mitigation only Fix from $2,3002026-06-24 CRITICAL 10.0 CVE-2026-12485 GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is a service ru… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.6 CVE-2026-54588 Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` requ… Mitigation only Fix from $2,3002026-06-23 CRITICAL 9.6 CVE-2026-11807 A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not v… Mitigation only Fix from $2,3002026-06-23 CRITICAL 10.0 CVE-2026-53622 Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration se… Traefik 3.7.3+ Fix from $2,3002026-06-23 CRITICAL 10.0 CVE-2026-48491 Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting prote… Traefik 3.7.3+ Fix from $2,3002026-06-23 CRITICAL 10.0 CVE-2026-48020 Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPre… Traefik 2.11.48 / 3.6.19+ Fix from $2,3002026-06-23 CRITICAL 10.0 CVE-2026-53753 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature us… Crawl4ai 0.8.7+ Fix from $2,3002026-06-23 CRITICAL 9.1 CVE-2026-54316 Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the We… Claude Code 2.1.163+ Fix from $2,3002026-06-23 CRITICAL 9.3 CVE-2026-54257 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs inc… Mitigation only Fix from $2,3002026-06-23