Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-44482 soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.0 CVE-2026-42457 vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-2347 Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hi… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2025-11024 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. … Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.1 CVE-2026-6512 The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin … Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-6510 The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. … Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-6271 The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7 via the CV upload handler. T… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-8181EPSS 15% The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypas… Mitigation only Fix from $2,3002026-05-14 CRITICAL 9.8 CVE-2026-8500 Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpass… Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-45158 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configu… Opnsense 26.1.8+ Fix from $2,3002026-05-13 CRITICAL 9.9 CVE-2026-44442 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks… Erpnext 16.9.1+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-44194EPSS 6% OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsens… Opnsense 26.1.8+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-44193 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user … Opnsense 26.1.7+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-45714 CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple m… Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-45053 CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager … Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-44377 CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple m… Patch available Fix from $2,3002026-05-13 CRITICAL 9.3 CVE-2025-27851 The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU … Empirbus Wireless Display Unit Firmware Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.3 CVE-2026-44364 MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerabilit… Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-44351 fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-re… Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-42584 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound res… Netty 4.1.133 / 4.2.13+ Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-42581 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting… Netty 4.1.133 / 4.2.13+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-42579 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC… Netty 4.1.133 / 4.2.13+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-42032 CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastor… Ckan 2.10.10 / 2.11.5+ Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-42031 CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastor… Ckan 2.10.10 / 2.11.5+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-0258 A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attac… Pan Os 10.2.7 / 10.2.10+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-0257 KEVEPSS 94% Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass se… Pan Os 10.2.7+ Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-45411 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async g… Vm2 3.11.3+ Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-44009 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2. Vm2 3.11.2+ Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-44008 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but … Vm2 3.11.2+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-44007 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require(… Vm2 3.11.1+ Fix from $2,3002026-05-13