Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-46839 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerabili… Rest Data Services after 26.1.0 Fix from $2,3002026-05-28 CRITICAL 9.0 CVE-2026-46833 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit … Database Server after 23.26.2 Fix from $2,3002026-05-28 CRITICAL 9.9 CVE-2026-46824 Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported … Universal Work Queue after 12.2.15 Fix from $2,3002026-05-28 CRITICAL 9.9 CVE-2026-46822 Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12… Iassets after 12.2.15 Fix from $2,3002026-05-28 CRITICAL 9.1 CVE-2026-46819 Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions t… E Business Suite after 12.2.15 Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-46817 KEVEPSS 13% Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.… E Business Suite after 12.2.15 Fix from $2,3002026-05-28 CRITICAL 9.9 CVE-2026-46775 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerabili… Rest Data Services after 26.1.0 Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-45288 Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-suppl… Patch available Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-34311 Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions … Hospitality Opera 5 Property Services Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.3 CVE-2026-9037 A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device'… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-45039 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.1 CVE-2026-45787 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero… Electerm 3.9.5+ Fix from $2,3002026-05-28 CRITICAL 9.6 CVE-2026-45374 CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure de… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.6 CVE-2026-45323 MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-… Meshcore Card 0.3.3+ Fix from $2,3002026-05-28 CRITICAL 9.6 CVE-2026-45311 CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalR… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.4 CVE-2026-45058 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code ex… Mitigation only Fix from $2,3002026-05-28 CRITICAL 10.0 CVE-2026-43898 SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover th… Sandboxjs 0.9.6+ Fix from $2,3002026-05-28 CRITICAL 9.1 CVE-2026-9098 In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs witho… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-9097 Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-9094 Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-9093 In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertion… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.1 CVE-2026-9092 Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByB… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.1 CVE-2026-9090 Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certi… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.3 CVE-2026-45261 GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in t… Mitigation only Fix from $2,3002026-05-28 CRITICAL 9.9 CVE-2026-44477 CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG met… Cloudnativepg 1.28.3 / 1.29.1+ Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-38707 A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware… Ir315 Firmware 1.0.121 / 3.5.112+ Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-38704 A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firm… Ir315 Firmware 1.0.121 / 3.5.112+ Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-38703 A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmw… Ir315 Firmware 1.0.121 / 3.5.112+ Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-38702 A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmw… Ir315 Firmware 1.0.121 / 3.5.112+ Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-24444 SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interfa… Mitigation only Fix from $2,3002026-05-28