Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-50886 Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted … Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.6 CVE-2026-50883 An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a craft… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-50880 An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted req… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-50873 An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via upload… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-50872 An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensit… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-50871 An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to … Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-50869 An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.1 CVE-2026-49952 Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain … Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-48114 Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticate… Patch available Fix from $2,3002026-06-15 CRITICAL 9.1 CVE-2026-45390 In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired be… No fix yet Fix from $2,3002026-06-15 CRITICAL 9.1 CVE-2026-45388 In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation w… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-39196 Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition f… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-39006 An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38812 RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an aut… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38329 Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.p… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38065 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38064 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38063 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38062 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38061 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-38060 Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-36537 ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-s… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.1 CVE-2026-30121 remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability. Remotion Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-30120 remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability. Remotion Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-9862 Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker w… Core Privileged Access Manager Server 8.1.0.23 / 9.0.0.5+ Fix from $2,3002026-06-15 CRITICAL 10.0 CVE-2026-52704 Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. … Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2018-25436 WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.3 CVE-2026-5482 Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, … Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.2 CVE-2026-49757 Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. As… Patch available Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-8935 The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any fro… Mitigation only Fix from $2,3002026-06-15