Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-9006 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an a… Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-22 CRITICAL 9.8 CVE-2026-9072 IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-i… I after 7.6 Fix from $2,3002026-06-22 CRITICAL 9.1 CVE-2026-8646 IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request … Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-22 CRITICAL 9.8 CVE-2026-7664 IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due t… Langflow after 1.8.4 Fix from $2,3002026-06-22 CRITICAL 9.1 CVE-2026-12628 IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker… Storage Protect 8.2.1.1+ Fix from $2,3002026-06-22 CRITICAL 9.2 CVE-2026-7166 Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘em… Mitigation only Fix from $2,3002026-06-22 CRITICAL 9.4 CVE-2026-7165 The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of othe… Mitigation only Fix from $2,3002026-06-22 CRITICAL 9.8 CVE-2026-6653 Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service … Libxml2 after 2.11.0 Fix from $2,3002026-06-22 CRITICAL 10.0 CVE-2026-10561 IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass tha… Langflow after 1.9.3 Fix from $2,3002026-06-22 CRITICAL 9.4 CVE-2026-56422 Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreig… Patch available Fix from $2,3002026-06-22 CRITICAL 9.1 CVE-2026-11373 Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is… Patch available Fix from $2,3002026-06-22 CRITICAL 9.4 CVE-2026-11746 A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication… Mitigation only Fix from $2,3002026-06-22 CRITICAL 9.6 CVE-2026-56397 SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ar… Mitigation only Fix from $2,3002026-06-21 CRITICAL 9.6 CVE-2026-56395 SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject ar… Mitigation only Fix from $2,3002026-06-21 CRITICAL 9.1 CVE-2026-56367 ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coder… Imagemagick 6.9.13-40 / 7.1.2-15+ Fix from $2,3002026-06-21 CRITICAL 9.8 CVE-2026-56265 Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers … Crawl4ai 0.8.7+ Fix from $2,3002026-06-21 CRITICAL 9.8 CVE-2026-12773 A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_s… Litellm 1.59.9+ Fix from $2,3002026-06-21 CRITICAL 9.9 CVE-2026-5366 Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class.… Prefect Mitigation only Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2024-58351 Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the fro… Mitigation only Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2022-50972 WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands thro… Mitigation only Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2019-25763 WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized acces… Mitigation only Fix from $2,3002026-06-20 CRITICAL 9.5 CVE-2026-48909 SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to … Mitigation only Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2026-48939 KEVEPSS 20% A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP… Icagenda 3.9.15 / 4.0.8+ Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2026-48908 KEVEPSS 15% A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and executio… Sp Page Builder 6.6.2+ Fix from $2,3002026-06-20 CRITICAL 9.1 CVE-2026-9265 Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRI… Patch available Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2026-11551 The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due … Mitigation only Fix from $2,3002026-06-20 CRITICAL 9.1 CVE-2026-56081 Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address … Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.4 CVE-2026-56073 Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modi… Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.6 CVE-2026-48582 Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Exchange Online Mitigation only Fix from $2,3002026-06-19 CRITICAL 10.0 CVE-2026-45480 Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. Azure Active Directory No fix yet Fix from $2,3002026-06-19