Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-44006 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary… Vm2 3.11.0+ Fix from $2,3002026-05-13 CRITICAL 10.0 CVE-2026-44005 vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and… Vm2 3.11.0+ Fix from $2,3002026-05-13 CRITICAL 9.9 CVE-2026-43999 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (includi… Vm2 3.11.0+ Fix from $2,3002026-05-13 CRITICAL 10.0 CVE-2026-43997 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Objec… Vm2 3.11.0+ Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-0264 A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker wi… Pan Os 10.2.7 / 10.2.10+ Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-0263 A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to ex… Pan Os 11.1.4 / 11.1.6+ Fix from $2,3002026-05-13 CRITICAL 9.6 CVE-2026-42557 jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, Jupyt… Jupyterlab 4.5.7 / 7.5.6+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-41225 A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration obj… Big Ip Access Policy Manager after 17.5.1 Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2020-37168 Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production s… Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-42062 ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arb… Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-40621 ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without aut… Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.9 CVE-2026-41050 Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored… Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-32661 Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker … Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.6 CVE-2026-44547 ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged a… Patch available Fix from $2,3002026-05-12 CRITICAL 10.0 CVE-2026-42288 ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code ex… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.0 CVE-2026-41901 Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists i… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.4 CVE-2026-44262EPSS 6% Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and val… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.3 CVE-2026-44258 efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targets for path traversal and hom… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.3 CVE-2026-44257 efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk using new File(baseDir, zipEntry.… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.9 CVE-2026-44015 Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF)… Nginx Ui after 2.3.4 Fix from $2,3002026-05-12 CRITICAL 9.9 CVE-2026-43948 wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a … Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-42854 arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer m… Arduino Esp32 3.3.8+ Fix from $2,3002026-05-12 CRITICAL 9.9 CVE-2026-42196 django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal … Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-45185 Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a c… Exim 4.99.3+ Fix from $2,3002026-05-12 CRITICAL 9.3 CVE-2026-44225 Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every … Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.0 CVE-2026-44221 ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tokens scoped to a specific data… Patch available Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-42889 Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebS… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.3 CVE-2026-34660 Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code… Connect Desktop Application after 2025.9.15 Fix from $2,3002026-05-12 CRITICAL 9.6 CVE-2026-34659 Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbit… Connect Desktop Application after 2025.8.157 Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-44343 WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allo… Wgdashboard 4.3.2+ Fix from $2,3002026-05-12