Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-48773 ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vu… Proxysql 3.0.9+ Fix from $2,3002026-06-19 CRITICAL 10.0 CVE-2026-48772 ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY U… Proxysql 3.0.9+ Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-51846 In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to rem… Ac7 Firmware Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-51845 Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter. Ac7 Firmware Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-51844 Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. Ac7 Firmware Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-51843 Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. Ac7 Firmware Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.1 CVE-2026-9142 There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopbac… Instrumentstudio 2.18.0+ Fix from $2,3002026-06-19 CRITICAL 9.3 CVE-2026-49871 Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manag… Apisix 3.17.0+ Fix from $2,3002026-06-19 CRITICAL 9.1 CVE-2026-49230 Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to aut… Apisix 3.17.0+ Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-48137 There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary… Instrumentstudio 2.18.0+ Fix from $2,3002026-06-19 CRITICAL 9.1 CVE-2026-44087 Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack s… Apisix 3.17.0+ Fix from $2,3002026-06-19 CRITICAL 9.1 CVE-2026-39999 Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configur… Apisix 3.17.0+ Fix from $2,3002026-06-19 CRITICAL 9.1 CVE-2025-62821 Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the report… Heif Image Extension No fix yet Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-56141 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable rest… Hub 2024.2.148429 / 2024.3.148430+ Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-50242 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct data… Hub 2024.2.148429 / 2024.3.148430+ Fix from $2,3002026-06-19 CRITICAL 9.4 CVE-2026-44939 A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitiz… Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.1 CVE-2026-8713 The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete… Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-7515 The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. … Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-54414 FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitr… No fix yet Fix from $2,3002026-06-19 CRITICAL 9.8 CVE-2026-40624 Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary c… Mitigation only Fix from $2,3002026-06-19 CRITICAL 9.0 CVE-2026-12046 Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/updat… Pgadmin 4 9.16+ Fix from $2,3002026-06-19 CRITICAL 9.9 CVE-2026-47647 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. Dynamics 365 Mitigation only Fix from $2,3002026-06-18 CRITICAL 9.1 CVE-2026-49454 Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures becaus… Patch available Fix from $2,3002026-06-18 CRITICAL 10.0 CVE-2026-49257 mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to… Patch available Fix from $2,3002026-06-18 CRITICAL 9.9 CVE-2026-49252 deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vul… Patch available Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-43994 Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_g… Coturn 4.10.0+ Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-47846 Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via … Mitigation only Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-54390 JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicio… Mitigation only Fix from $2,3002026-06-18 CRITICAL 9.1 CVE-2026-55203 HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer … Haproxy after 3.4.0 Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-54103 The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic D… Mitigation only Fix from $2,3002026-06-18