Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-47744 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.1 CVE-2026-44650 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-44649 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines,… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-7786 Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials … Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.1 CVE-2026-5386 The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset th… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.3 CVE-2026-45668 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malic… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45661 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45633 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /dock… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45632 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. … Mitigation only Fix from $2,3002026-05-29 CRITICAL 10.0 CVE-2026-45631 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-se… Patch available Fix from $2,3002026-05-29 CRITICAL 9.0 CVE-2026-45630 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTra… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45629 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment We… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.6 CVE-2026-45628 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template lit… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45625 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endp… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.1 CVE-2026-48501 GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF … Cli 2.93.0+ Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45663 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upl… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-44962 Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into X… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-10064 A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Perfor… Tew 432brp Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.1 CVE-2026-4290 The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoin… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-10063 A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manip… Tew 432brp Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-10062 A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSe… Tew 432brp Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-10042 manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle… Patch available Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-46376 FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP)… Freepbx 16.0.45 / 17.0.7+ Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-10061EPSS 5% A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argum… Tew 432brp Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-10060EPSS 5% A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulat… Tew 432brp Firmware Mitigation only Fix from $2,3002026-05-29 CRITICAL 10.0 CVE-2026-9508 Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly expo… Mitigation only Fix from $2,3002026-05-29 CRITICAL 10.0 CVE-2026-8326 Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories a… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45312 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (ra… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.3 CVE-2026-45043 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoi… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.8 CVE-2026-10071 DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web she… Mitigation only Fix from $2,3002026-05-29