Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-31071 API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-31070 The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an admin… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-30118 scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. T… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-30117 scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpo… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-8711EPSS 10% NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example,… Njs 0.9.9+ Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-44159 Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment.… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.6 CVE-2026-2587 A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget hand… Glassfish 8.0.2+ Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-2586 An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can … Glassfish 8.0.2+ Fix from $2,3002026-05-19 CRITICAL 9.6 CVE-2026-8959 Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, … Firefox 140.11 / 140.11.0+ Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-8956 Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird … Firefox 140.11 / 140.11.0+ Fix from $2,3002026-05-19 CRITICAL 9.6 CVE-2026-8953 Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefo… Firefox 115.36.0 / 140.11+ Fix from $2,3002026-05-19 CRITICAL 9.3 CVE-2026-8950 Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Th… Firefox 140.11 / 140.11.0+ Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-8948 Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-47323 Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHe… Camel 4.14.6 / 4.18.2+ Fix from $2,3002026-05-19 CRITICAL 10.0 CVE-2026-43633 HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch betwe… Patch available Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-4883 The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_buil… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-43493 In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can … Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-05-19 CRITICAL 9.2 CVE-2026-46725 The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated att… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-45434EPSS 22% Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBi… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-41919 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz:… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 CRITICAL 9.1 CVE-2026-31986 Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgra… Ofbiz 24.09.06+ Fix from $2,3002026-05-19 CRITICAL 9.6 CVE-2026-2611 In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a r… Mlflow 3.10.0+ Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-4885 The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_aja… Mitigation only Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-47314 Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce… Escargot Patch available Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-47311 Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da85… Escargot Patch available Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-47310 Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6… Escargot Patch available Fix from $2,3002026-05-19 CRITICAL 9.8 CVE-2026-8838 Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue serve… Mitigation only Fix from $2,3002026-05-18 CRITICAL 9.9 CVE-2026-27130 Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 c… Patch available Fix from $2,3002026-05-18 CRITICAL 9.8 CVE-2026-25244 WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 cont… Webdriverio 9.24.0+ Fix from $2,3002026-05-18 CRITICAL 9.8 CVE-2026-8836 A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the componen… Patch available Fix from $2,3002026-05-18