Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-44774 Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant wi… Traefik 2.11.46 / 3.6.17+ Fix from $2,3002026-05-15 CRITICAL 9.1 CVE-2026-44699 LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parameter as the verification key f… Mitigation only Fix from $2,3002026-05-15 CRITICAL 9.3 CVE-2026-42155 Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community Edition e-commerce platfo… Mitigation only Fix from $2,3002026-05-15 CRITICAL 9.1 CVE-2026-41258 OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateC… Mitigation only Fix from $2,3002026-05-15 CRITICAL 9.8 CVE-2026-45772 Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arb… Turborepo 2.9.14+ Fix from $2,3002026-05-15 CRITICAL 10.0 CVE-2026-2031 An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remo… Mitigation only Fix from $2,3002026-05-15 CRITICAL 9.2 CVE-2026-7182 Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the ht… Mitigation only Fix from $2,3002026-05-15 CRITICAL 10.0 CVE-2026-41553 PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. … Pdf Export Module 0.7.6+ Fix from $2,3002026-05-15 CRITICAL 9.8 CVE-2026-8398 KEV A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distrib… Daemon Tools Mitigation only Fix from $2,3002026-05-15 CRITICAL 9.8 CVE-2026-5229 The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trustin… Patch available Fix from $2,3002026-05-15 CRITICAL 9.2 CVE-2026-0481 Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to … Mitigation only Fix from $2,3002026-05-15 CRITICAL 9.3 CVE-2026-44666 HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.3 CVE-2026-44212 PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the … Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.1 CVE-2026-8634 Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a malicious or compromised repo… Patch available Fix from $2,3002026-05-14 CRITICAL 9.6 CVE-2026-8580 Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML … Chrome 148.0.7778.168+ Fix from $2,3002026-05-14 CRITICAL 9.6 CVE-2026-8511 Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pa… Chrome 148.0.7778.168+ Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-26191 Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafte… Fleet 4.81.0+ Fix from $2,3002026-05-14 CRITICAL 9.0 CVE-2026-45375 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version f… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.4 CVE-2026-44670 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTM… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.4 CVE-2026-44592 Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone … Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.4 CVE-2026-44588 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-l… Mitigation only Fix from $2,3002026-05-14 CRITICAL 10.0 CVE-2026-44523 Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value.… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-41315 mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to… Mdserver Web after 0.18.4 Fix from $2,3002026-05-14 CRITICAL 9.1 CVE-2026-46470 An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function d… Gst Plugins Good 1.28.2+ Fix from $2,3002026-05-14 CRITICAL 9.1 CVE-2026-44542 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined wi… Filebrowser Quantum 1.3.1 / 1.3.9+ Fix from $2,3002026-05-14 CRITICAL 9.1 CVE-2026-42555 Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case … Mitigation only Fix from $2,3002026-05-14 CRITICAL 10.0 CVE-2026-20182 KEVEPSS 92% May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed … Catalyst Sd Wan Manager 20.9.9.1 / 20.12.5.4+ Fix from $2,3002026-05-14 CRITICAL 9.4 CVE-2026-42596 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webho… Gotenberg 8.31.0+ Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-42589 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON… Gotenberg 8.31.0+ Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-44484 PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent … Pytorch Lightning No fix yet Fix from $2,3002026-05-14