Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.4 CVE-2026-44326 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-influence API without inbound … Free5gc 4.2.2+ Fix from $2,3002026-05-27 CRITICAL 9.4 CVE-2026-44315 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAu… Free5gc 4.2.2+ Fix from $2,3002026-05-27 CRITICAL 9.4 CVE-2026-49103 Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detacha… Patch available Fix from $2,3002026-05-27 CRITICAL 9.6 CVE-2026-45570 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remot… Go Git 5.19.1+ Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-8175 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I… Aspera High Speed Transfer Endpoint after 4.4.6 Fix from $2,3002026-05-27 CRITICAL 9.1 CVE-2026-7876 IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage … Aspera High Speed Transfer Server For Cloud Pak For Integration 1.5.20+ Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-7524 IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction. Langflow after 1.9.1 Fix from $2,3002026-05-27 CRITICAL 9.1 CVE-2026-46043 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv rxe_rcv() curr… Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-46039 In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length check Fix potential integer over… Linux Kernel 6.17 / 6.18.27+ Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-45988 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a RESPONSE packet gets a tempor… Linux Kernel 6.6.140 / 6.12.86+ Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-45972 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in smb2_open_file() Zero out @er… Linux Kernel 6.1.165 / 6.6.128+ Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-45898 In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by removing work_list The commit e1168… Linux Kernel 6.12.75 / 6.18.14+ Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-35090 In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can connect to the modem via a telepho… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-35087 Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter login credentials by executi… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2024-40684 IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.… Operations Analytics Log Analysis Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-42761 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommer… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-42758 Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affe… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.9 CVE-2026-42757 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-igni… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.9 CVE-2026-42756 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Imag… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-42755 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn posts-table-filterable allow… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.9 CVE-2026-42748 Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web Shell to a Web Server.This issue… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-42747 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-buil… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-42740 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows Blind SQL Inj… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-42731 Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This i… Mitigation only Fix from $2,3002026-05-27 CRITICAL 9.3 CVE-2026-42727 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommer… Mitigation only Fix from $2,3002026-05-27 CRITICAL 10.0 CVE-2026-8054 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and… Patch available Fix from $2,3002026-05-27 CRITICAL 9.1 CVE-2026-49002 Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system dat… No fix yet Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2025-13392 Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-… Diskstation Manager 7.2.2-72806-5+ Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2025-12686 Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allo… Beestation Os 1.3.2+ Fix from $2,3002026-05-27 CRITICAL 9.8 CVE-2026-8760 The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplet… Mitigation only Fix from $2,3002026-05-27