Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-47291EPSS 23% Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-45657EPSS 15% Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. Windows 11 23h2 10.0.20348.5256 / 10.0.22631.7219+ Fix from $2,3002026-06-09 CRITICAL 9.6 CVE-2026-47281 Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. Visual Studio Code 1.123.1+ Fix from $2,3002026-06-09 CRITICAL 9.1 CVE-2026-45602 No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-44815 Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $2,3002026-06-09 CRITICAL 9.6 CVE-2026-42904 Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network. Windows 10 21h2 10.0.19044.7417 / 10.0.19045.7417+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-38615 DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.1 CVE-2026-34182 Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of Au… OpenSSL 3.0.21 / 3.4.6+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-26142 Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. Nuance Powerscribe 360 Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-8025 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-25089 KEVEPSS 76% A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0… Fortisandbox 4.4.9 / 5.0.6+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-10523EPSS 52% An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated at… Standalone Sentry 10.5.2 / 10.6.2+ Fix from $2,3002026-06-09 CRITICAL 10.0 CVE-2026-10520 KEVEPSS 100% An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie… Standalone Sentry 10.5.2 / 10.6.2+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-7486 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injectio… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-46325 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE The current … Linux Kernel 6.18.14 / 6.19.4+ Fix from $2,3002026-06-09 CRITICAL 9.3 CVE-2026-46316 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased e… Linux Kernel 6.12.93 / 6.18.35+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2017-20251 WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitra… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-46749 A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation … Sinec Ins after 1.0 Fix from $2,3002026-06-09 CRITICAL 9.3 CVE-2026-10731 SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.1 CVE-2025-10263 Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Corte… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.1 CVE-2009-10007 Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does… Patch available Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-9698 DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleEr… Dbi 1.648+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-44083 An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vuln… Qumagie 2.9.0+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-5067 A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sending a crafted Sec-WebSocket-Ke… Zephyr after 4.3.0 Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-41855 In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.conver… Spring Framework 5.3.49 / 6.1.28+ Fix from $2,3002026-06-09 CRITICAL 9.9 CVE-2026-44748 SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and … Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.0 CVE-2026-40128 SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates fil… Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-27671 Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated … Mitigation only Fix from $2,3002026-06-09 CRITICAL 9.6 CVE-2026-11697 Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox … Chrome 149.0.7827.103+ Fix from $2,3002026-06-09 CRITICAL 9.6 CVE-2026-11671 Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted… Chrome 149.0.7827.103+ Fix from $2,3002026-06-09