Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-50225 The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database. Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.8 CVE-2026-50214 The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost networ… Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.8 CVE-2026-50211 Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to int… Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.4 CVE-2026-50208 High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Mi… Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.8 CVE-2026-49191 The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages. Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.8 CVE-2026-49188 The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execu… Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.8 CVE-2026-49186 The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +… Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.8 CVE-2026-49185 The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection. Connect M6e 5g Firmware Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.9 CVE-2026-41283 OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which… Mitigation only Fix from $2,3002026-06-04 CRITICAL 9.1 CVE-2026-46266 In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reporte… Linux Kernel 6.6.128 / 6.12.75+ Fix from $2,3002026-06-03 CRITICAL 9.1 CVE-2026-46244 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), wh… Linux Kernel 6.6.142 / 6.12.92+ Fix from $2,3002026-06-03 CRITICAL 9.0 CVE-2026-36748 RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile. Mitigation only Fix from $2,3002026-06-03 CRITICAL 9.8 CVE-2026-36576 An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arb… Mitigation only Fix from $2,3002026-06-03 CRITICAL 9.6 CVE-2026-5241 A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execu… Transformers Patch available Fix from $2,3002026-06-03 CRITICAL 9.8 CVE-2026-35075 An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices. Universal Gateway Firmware 6_00_07+ Fix from $2,3002026-06-03 CRITICAL 9.8 CVE-2026-47065 ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the seri… Mina Mitigation only Fix from $2,3002026-06-03 CRITICAL 9.9 CVE-2025-14771 Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24. T Mac Plus Mitigation only Fix from $2,3002026-06-03 CRITICAL 9.1 CVE-2026-35482 alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox esca… Alf 2.0-M5-2606+ Fix from $2,3002026-06-02 CRITICAL 9.6 CVE-2026-32625 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) s… Librechat 0.8.4+ Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-49448 authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an em… Authentik 2025.12.6 / 2026.2.4+ Fix from $2,3002026-06-02 CRITICAL 9.3 CVE-2026-42849 authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow … Authentik 2025.12.5 / 2026.2.3+ Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-5076 The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plug… Mitigation only Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-38967 CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values. Patch available Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-42074 OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableS… Openclaude 0.5.1+ Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-0611 Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability thro… Mitigation only Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-47117 OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used … Patch available Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-7198 CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access… Sitefinity 15.4.8630+ Fix from $2,3002026-06-02 CRITICAL 10.0 CVE-2026-10611 An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with … Misp 2.5.39+ Fix from $2,3002026-06-02 CRITICAL 9.3 CVE-2026-42684 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection.… Mitigation only Fix from $2,3002026-06-02 CRITICAL 9.3 CVE-2026-34906 Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoin… Mitigation only Fix from $2,3002026-06-02