Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-0274 An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticate… Cortex Xsiam Commvaultsecurityiq Marketplace Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.1 CVE-2026-50638 Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such … Metrics\ 0.04+ Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-50566 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-50564 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-50563 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-50545 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 CRITICAL 9.8 CVE-2026-46614 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 CRITICAL 9.8 CVE-2026-20253 KEVEPSS 97% In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files throug… Splunk 10.0.7 / 10.2.4+ Fix from $2,3002026-06-10 CRITICAL 9.6 CVE-2026-53476 A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal… Assisted Migration Agent 2026-06-07+ Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-45558 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoi… Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-45556 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>… Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-45552 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares … Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.1 CVE-2026-45550 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smo… Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.8 CVE-2025-6254 The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat… Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.1 CVE-2026-9067 The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and… Mitigation only Fix from $2,3002026-06-10 CRITICAL 9.1 CVE-2026-26241 A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory … File Station 5.5.6.5243+ Fix from $2,3002026-06-10 CRITICAL 9.1 CVE-2026-26240 A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory … File Station 5.5.6.5243+ Fix from $2,3002026-06-10 CRITICAL 9.8 CVE-2025-66276 QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later Qts 5.2.7.3256+ Fix from $2,3002026-06-10 CRITICAL 9.4 CVE-2026-44963 A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. Mitigation only Fix from $2,3002026-06-09 CRITICAL 10.0 CVE-2026-48303 Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbi… Campaign 7.4.3+ Fix from $2,3002026-06-09 CRITICAL 10.0 CVE-2026-47938 Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could resu… Campaign after 7.4.2 Fix from $2,3002026-06-09 CRITICAL 9.6 CVE-2026-47928 ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.1 CVE-2026-36727 An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged … Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-36721 A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a f… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-30141 An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of serv… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-10045 Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has tel… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.3 CVE-2026-34691 Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that coul… Experience Manager after 6.5.24.0 Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-49841 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.11.1+ Fix from $2,3002026-06-09 CRITICAL 9.1 CVE-2026-49840 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.11.1+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-47643 External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. Azure Stack Edge 3.3.2604.3097+ Fix from $2,3002026-06-09