Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-44277 A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, Forti… Fortiauthenticator 6.5.7 / 6.6.9+ Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-44196 Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows … Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-44183 Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Pri… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.9 CVE-2026-42898 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over … Dynamics 365 9.1.45.11+ Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-42833 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over … Dynamics 365 9.1.45.11+ Fix from $2,3002026-05-12 CRITICAL 9.9 CVE-2026-42823 Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. Azure Logic Apps Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.3 CVE-2026-42300 DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware accepts a client-supplied X-Admi… Patch available Fix from $2,3002026-05-12 CRITICAL 9.6 CVE-2026-42048 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowle… Langflow 1.9.0+ Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-41103EPSS 5% Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate pri… Confluence Saml Sso 1.3.3 / 7.4.0+ Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-41096 Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. Windows 11 23h2 10.0.22631.7079 / 10.0.25398.2330+ Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-41089EPSS 80% Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. Windows Server 2012 10.0.14393.9140 / 10.0.17763.8755+ Fix from $2,3002026-05-12 CRITICAL 9.3 CVE-2026-40402 Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. Windows 11 23h2 10.0.20348.5074 / 10.0.22631.7079+ Fix from $2,3002026-05-12 CRITICAL 9.9 CVE-2026-33821 Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. Dynamics 365 Customer Insights Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-33117 The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag com… Azure Sdk For Java 4.10.6+ Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-31242 The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via the DELETE /memories endpoin… Mem0 Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31239 The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hu… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31238 The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server wit… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31237 The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset fil… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31236 The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. This argument is intended to… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31235 The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31234 Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. The KVStore server, used for d… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31233 Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packag… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31231 Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to e… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31230 The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_e… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-31229 The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model l… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.1 CVE-2026-29204 Insufficient ownership check in `clientarea.php` allows an authenticated client area user to submit requests using another user’s `addonId` without a… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-26083 A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 throug… Fortisandbox 4.4.9 / 5.0.2+ Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2026-43992 JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate… Patch available Fix from $2,3002026-05-12 CRITICAL 9.3 CVE-2026-20794 Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an… Mitigation only Fix from $2,3002026-05-12 CRITICAL 9.8 CVE-2025-65719 An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted H… Mitigation only Fix from $2,3002026-05-12