Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-53209 Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from … Mitigation only Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-8206 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in al… Mitigation only Fix from $2,3002026-06-02 CRITICAL 9.8 CVE-2026-25879 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM… Mitigation only Fix from $2,3002026-06-01 CRITICAL 10.0 CVE-2026-40965 Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic… Mitigation only Fix from $2,3002026-06-01 CRITICAL 9.8 CVE-2018-25427 Arm Whois 3.11 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by supplying oversized inp… Mitigation only Fix from $2,3002026-06-01 CRITICAL 9.0 CVE-2026-9319 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS en… Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 CRITICAL 9.0 CVE-2026-9311 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 CRITICAL 9.1 CVE-2026-8644 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $2,3002026-06-01 CRITICAL 9.8 CVE-2026-49121 AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function … Aiter after 0.1.14 Fix from $2,3002026-06-01 CRITICAL 9.1 CVE-2026-22872 Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantR… Capsule 0.13.0+ Fix from $2,3002026-06-01 CRITICAL 10.0 CVE-2026-45132 CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) expose… Patch available Fix from $2,3002026-06-01 CRITICAL 10.0 CVE-2026-45131 CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes … Patch available Fix from $2,3002026-06-01 CRITICAL 9.6 CVE-2026-44211 Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijac… Cline after 2.13.0 Fix from $2,3002026-06-01 CRITICAL 9.3 CVE-2026-42672 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind … Mitigation only Fix from $2,3002026-06-01 CRITICAL 9.4 CVE-2026-8931 A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3. Mitigation only Fix from $2,3002026-06-01 CRITICAL 9.8 CVE-2026-48879 Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17. No fix yet Fix from $2,3002026-06-01 CRITICAL 9.6 CVE-2026-48866 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal… Mitigation only Fix from $2,3002026-06-01 CRITICAL 9.1 CVE-2026-42682 Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue aff… Mitigation only Fix from $2,3002026-06-01 CRITICAL 9.8 CVE-2026-42680 Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This is… Mitigation only Fix from $2,3002026-06-01 CRITICAL 9.2 CVE-2026-0826EPSS 32% In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote co… Mitigation only Fix from $2,3002026-06-01 CRITICAL 9.8 CVE-2026-7858 A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Colla… Mitigation only Fix from $2,3002026-06-01 CRITICAL 9.8 CVE-2026-44825 Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a … Solr after 9.10.1 Fix from $2,3002026-06-01 CRITICAL 9.1 CVE-2026-42252 Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(b… Airflow 3.2.2+ Fix from $2,3002026-06-01 CRITICAL 9.1 CVE-2026-48188 An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which … Otrs 2026.4.1+ Fix from $2,3002026-06-01 CRITICAL 9.8 CVE-2026-10187EPSS 7% A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.s… Mitigation only Fix from $2,3002026-05-31 CRITICAL 9.8 CVE-2018-25412 Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST reque… Deltasql Mitigation only Fix from $2,3002026-05-30 CRITICAL 9.8 CVE-2026-45697 Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (wi… Patch available Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-45700 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write whe… Freerdp 3.26.0+ Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45372 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming reque… Cpp Httplib 0.44.0+ Fix from $2,3002026-05-29 CRITICAL 9.1 CVE-2026-9051 There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attack… Mitigation only Fix from $2,3002026-05-29