Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-38717 InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability… Ir915l Fq39 S Firmware 1.0.0.r20044+ Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-38716 InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability… Ir915l Fq39 S Firmware 1.0.0.r20044+ Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-38715 InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability… Ir915l Fq39 S Firmware 1.0.0.r20044+ Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-38714 InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability… Ir915l Fq39 S Firmware 1.0.0.r20044+ Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-9158 In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling poin… 4diac Forte after 3.1.0 Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-8024 A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access t… Mitigation only Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-54419 claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) conta… Mitigation only Fix from $2,3002026-06-18 CRITICAL 9.1 CVE-2026-11718 An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the … Mcp Toolbox For Databases after 1.3.0 Fix from $2,3002026-06-18 CRITICAL 9.1 CVE-2026-11717 An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When veri… Mcp Toolbox For Databases after 1.3.0 Fix from $2,3002026-06-18 CRITICAL 9.3 CVE-2025-10560 Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. … Mitigation only Fix from $2,3002026-06-18 CRITICAL 9.6 CVE-2026-55742 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admi… Mitigation only Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-55740 Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulner… Mitigation only Fix from $2,3002026-06-18 CRITICAL 9.8 CVE-2026-12569 KEVEPSS 41% A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t… Flexplm 11.0m030+ Fix from $2,3002026-06-18 CRITICAL 9.3 CVE-2026-48768 TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses uns… Mitigation only Fix from $2,3002026-06-18 CRITICAL 9.1 CVE-2026-54388 Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forward… Patch available Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-54387 Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding b… Patch available Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-48814 Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MC… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-55196 Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote att… Patch available Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-53805 NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /… Patch available Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-3894 Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects Connext Professional: from 7… Connext Professional 7.7.0+ Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-30803 Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connext Micro: … Connext Micro 4.3.0+ Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-20266 In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splun… Ai Toolkit 5.7.4+ Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-53874 picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval call… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-53873 picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing… Mitigation only Fix from $2,3002026-06-17 CRITICAL 10.0 CVE-2026-3490 picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function th… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-36418 JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSel… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-20181EPSS 9% A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating syst… Identity Services Engine 3.3.0+ Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-71325 picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments … Patch available Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-71323 picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and access… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-71321 picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.… Mitigation only Fix from $2,3002026-06-17