Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-11659 Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a craf… Chrome 149.0.7827.103+ Fix from $2,3002026-06-09 CRITICAL 9.6 CVE-2026-11654 Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via… Chrome 149.0.7827.103+ Fix from $2,3002026-06-09 CRITICAL 9.6 CVE-2026-11651 Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted… Chrome 149.0.7827.103+ Fix from $2,3002026-06-09 CRITICAL 9.6 CVE-2026-11638 Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted H… Chrome 149.0.7827.103+ Fix from $2,3002026-06-09 CRITICAL 9.6 CVE-2026-11634 Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a… Chrome 149.0.7827.103+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-52778 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcFie… Patch available Fix from $2,3002026-06-08 CRITICAL 9.0 CVE-2026-11393 Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote … Mitigation only Fix from $2,3002026-06-08 CRITICAL 9.8 CVE-2026-46289 In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract_kvec_to_sg Patch series "Fi… Linux Kernel 6.6.140 / 6.12.88+ Fix from $2,3002026-06-08 CRITICAL 9.4 CVE-2026-41448 AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full… Mitigation only Fix from $2,3002026-06-08 CRITICAL 9.8 CVE-2026-25555 OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticate… Mitigation only Fix from $2,3002026-06-08 CRITICAL 9.9 CVE-2026-46442EPSS 36% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function la… Flowise 3.1.2+ Fix from $2,3002026-06-08 CRITICAL 9.6 CVE-2026-46441 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis… Flowise 3.1.2+ Fix from $2,3002026-06-08 CRITICAL 9.1 CVE-2026-46440 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validate… Flowise 3.1.2+ Fix from $2,3002026-06-08 CRITICAL 9.8 CVE-2026-44631 Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: fr… HTTP Server 2.4.68+ Fix from $2,3002026-06-08 CRITICAL 9.6 CVE-2026-42861 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis… Flowise 3.1.2+ Fix from $2,3002026-06-08 CRITICAL 9.1 CVE-2026-42535 A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases… HTTP Server 2.4.68+ Fix from $2,3002026-06-08 CRITICAL 9.8 CVE-2026-29167 Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 th… HTTP Server 2.4.68+ Fix from $2,3002026-06-08 CRITICAL 9.3 CVE-2026-50751 KEVEPSS 84% A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote att… Gaia Os Patch available Fix from $2,3002026-06-08 CRITICAL 9.8 CVE-2026-11499EPSS 7% A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of the file /boaform/formDOMAINBLK… Mitigation only Fix from $2,3002026-06-08 CRITICAL 9.8 CVE-2024-58349 WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by … Mitigation only Fix from $2,3002026-06-08 CRITICAL 9.8 CVE-2024-58348 WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticated attackers to upload arbitra… Mitigation only Fix from $2,3002026-06-08 CRITICAL 9.8 CVE-2023-54352 WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading ma… Mitigation only Fix from $2,3002026-06-08 CRITICAL 10.0 CVE-2026-11429 Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied fi… Mitigation only Fix from $2,3002026-06-05 CRITICAL 9.4 CVE-2026-11423 A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in th… Mitigation only Fix from $2,3002026-06-05 CRITICAL 9.8 CVE-2026-45779 OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3… Open Xdmod 10.0.3+ Fix from $2,3002026-06-05 CRITICAL 9.8 CVE-2026-45777 OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remot… Open Xdmod 11.0.3+ Fix from $2,3002026-06-05 CRITICAL 9.6 CVE-2026-45758 Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malic… Guardrails Ai Mitigation only Fix from $2,3002026-06-05 CRITICAL 9.8 CVE-2026-11420 Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to… On Prem Enterprise Server 8.1.1+ Fix from $2,3002026-06-05 CRITICAL 9.8 CVE-2026-11414 A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical acro… On Prem Enterprise Server 8.1.1+ Fix from $2,3002026-06-05 CRITICAL 9.3 CVE-2026-46496 HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26… Mitigation only Fix from $2,3002026-06-05