Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-20223 A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to acces… Secure Workload 3.10.8.3 / 4.0.3.17+ Fix from $2,3002026-05-20 CRITICAL 9.1 CVE-2026-8598 An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not require authentication and expose… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.5 CVE-2026-8467 Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpol… Patch available Fix from $2,3002026-05-20 CRITICAL 9.9 CVE-2026-24425 Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with te… Twig 3.26.0+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-3593 A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 thr… Bind 9.20.23 / 9.21.22+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2025-31973 HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images … Bigfix Service Management Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.0 CVE-2026-22314 Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component en… Mitigation only Fix from $2,3002026-05-20 CRITICAL 10.0 CVE-2026-42960 NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSet… Unbound 1.25.1+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-33278 NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible … Unbound 1.25.1+ Fix from $2,3002026-05-20 CRITICAL 9.3 CVE-2026-9065 SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'model_id', 'integration_id', 'p… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.3 CVE-2026-9059 NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the REST API endpoints '/imagely/… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-7637 The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input i… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-24214 NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit o… Triton Inference Server 26.03+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-24213 NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit… Triton Inference Server 26.03+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-24207 NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerab… Triton Inference Server 26.03+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-24206 NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerab… Triton Inference Server 26.03+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-24163 NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful explo… Tensorrt Llm 1.2+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-24142 NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability m… Tensorrt Llm 1.2+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2025-33255 NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit… Tensorrt Llm 1.2+ Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-7284 The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all … Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-6555 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an arra… Mitigation only Fix from $2,3002026-05-20 CRITICAL 9.8 CVE-2026-8495 Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.0.0 before 4.0.15. Date Ical 4.0.15+ Fix from $2,3002026-05-19 CRITICAL 10.0 CVE-2026-34234 CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (public/installer/index.php) is… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-33642 Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds… Kitty 0.47.0+ Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-8605 In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin. Scadabr Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-8603 In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system. Scadabr Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-8602 In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET req… Scadabr Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-36829 An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-37281 An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbit… Patch available Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-31072 The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via In… Mitigation only Fix from $2,3002026-05-19