Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-45495 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Edge Chromium 148.0.3967.70+ Fix from $2,3002026-05-18 CRITICAL 9.1 CVE-2026-45230 DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allow… Patch available Fix from $2,3002026-05-18 CRITICAL 10.0 CVE-2026-42822 Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. Azure Local 2604.2.25645+ Fix from $2,3002026-05-18 CRITICAL 9.1 CVE-2023-24215 Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator cred… Mitigation only Fix from $2,3002026-05-18 CRITICAL 10.0 CVE-2026-45829EPSS 12% A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run… Mitigation only Fix from $2,3002026-05-18 CRITICAL 9.4 CVE-2026-41948EPSS 7% Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin D… Dify after 1.14.1 Fix from $2,3002026-05-18 CRITICAL 9.1 CVE-2026-41947EPSS 6% Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configuratio… Dify after 1.14.1 Fix from $2,3002026-05-18 CRITICAL 9.8 CVE-2026-7304 SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabl… Sglang Mitigation only Fix from $2,3002026-05-18 CRITICAL 9.1 CVE-2026-7302 SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files… Sglang Mitigation only Fix from $2,3002026-05-18 CRITICAL 9.8 CVE-2026-7301 SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming… Sglang Mitigation only Fix from $2,3002026-05-18 CRITICAL 9.3 CVE-2026-4320 Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulat… Mitigation only Fix from $2,3002026-05-18 CRITICAL 9.8 CVE-2026-8721 Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in PKCS12.xs are declared char *,… Mitigation only Fix from $2,3002026-05-17 CRITICAL 9.8 CVE-2026-8507 Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING… Patch available Fix from $2,3002026-05-17 CRITICAL 9.1 CVE-2026-8757 A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.… Hive after 0.11.0 Fix from $2,3002026-05-17 CRITICAL 9.8 CVE-2018-25335 WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by… Mitigation only Fix from $2,3002026-05-17 CRITICAL 9.8 CVE-2018-25332 GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting we… Gitbucket 4.24.0+ Fix from $2,3002026-05-17 CRITICAL 9.8 CVE-2018-25320 ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands … Mitigation only Fix from $2,3002026-05-17 CRITICAL 9.8 CVE-2026-8751 A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Mod… H2o after 7402 Fix from $2,3002026-05-17 CRITICAL 9.8 CVE-2021-47952 python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing ma… Mitigation only Fix from $2,3002026-05-16 CRITICAL 9.8 CVE-2020-37239 libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature ove… Mitigation only Fix from $2,3002026-05-16 CRITICAL 9.8 CVE-2020-37228 iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting … Mitigation only Fix from $2,3002026-05-16 CRITICAL 9.8 CVE-2026-44566 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp,… Open Webui 0.1.124+ Fix from $2,3002026-05-15 CRITICAL 9.8 CVE-2026-8696 radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cau… Radare2 after 6.1.4 Fix from $2,3002026-05-15 CRITICAL 9.1 CVE-2026-44551 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint d… Open Webui 0.9.0+ Fix from $2,3002026-05-15 CRITICAL 9.1 CVE-2026-8686 Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a c… Coremqtt Mitigation only Fix from $2,3002026-05-15 CRITICAL 9.8 CVE-2026-46364 phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha()… Patch available Fix from $2,3002026-05-15 CRITICAL 9.1 CVE-2026-45010 phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/check endpoint, which accepts… Mitigation only Fix from $2,3002026-05-15 CRITICAL 9.8 CVE-2021-47965 WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers … Mitigation only Fix from $2,3002026-05-15 CRITICAL 9.8 CVE-2026-8695 radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption b… Radare2 after 6.1.4 Fix from $2,3002026-05-15 CRITICAL 9.8 CVE-2026-44717 MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mat… Mitigation only Fix from $2,3002026-05-15