Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.4 CVE-2026-42882 oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path inte… Patch available Fix from $2,3002026-05-11 CRITICAL 10.0 CVE-2026-42869 SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a … Patch available Fix from $2,3002026-05-11 CRITICAL 9.9 CVE-2026-42864 FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reacha… Mitigation only Fix from $2,3002026-05-11 CRITICAL 9.8 CVE-2026-8305 A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions… Openclaw 2026.2.12+ Fix from $2,3002026-05-11 CRITICAL 9.8 CVE-2026-43995 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly impor… Flowise 3.1.0+ Fix from $2,3002026-05-11 CRITICAL 9.1 CVE-2026-43639 Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organizati… Server 2026.4.0+ Fix from $2,3002026-05-11 CRITICAL 9.9 CVE-2026-42858 Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allo… Openedx 2026-04-24+ Fix from $2,3002026-05-11 CRITICAL 9.8 CVE-2026-38567 HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries witho… Mitigation only Fix from $2,3002026-05-11 CRITICAL 9.9 CVE-2026-7813 Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. M… Pgadmin 4 9.15+ Fix from $2,3002026-05-11 CRITICAL 10.0 CVE-2026-44643 Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious e… Angular Expressions 1.5.2+ Fix from $2,3002026-05-11 CRITICAL 9.4 CVE-2026-42613 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attacker-controlled groups and acc… Patch available Fix from $2,3002026-05-11 CRITICAL 9.1 CVE-2026-42608 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash core component. By manipulatin… Grav 2.0.0+ Fix from $2,3002026-05-11 CRITICAL 9.1 CVE-2026-42607 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE… Patch available Fix from $2,3002026-05-11 CRITICAL 9.8 CVE-2026-35157 Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutralization of formula elements in … Elastic Cloud Storage 4.3.0.0+ Fix from $2,3002026-05-11 CRITICAL 9.8 CVE-2026-8263 A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtr… Ac10u Firmware Mitigation only Fix from $2,3002026-05-11 CRITICAL 9.8 CVE-2021-47940 WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers t… Mitigation only Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2021-47936 OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by uploading malici… Mitigation only Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2021-47933 WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending… Mitigation only Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2021-47932 WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts … Mitigation only Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2021-47923 OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting arbitrary values into the OCSES… Mitigation only Fix from $2,3002026-05-10 CRITICAL 9.1 CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() … PHP 8.4.21 / 8.5.6+ Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2026-7261 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSIS… PHP 8.2.31 / 8.3.31+ Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2026-6722 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mech… PHP 8.2.31 / 8.3.31+ Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL… PHP 8.2.31 / 8.3.31+ Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2026-42601 ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts … Archivebox 0.8.6+ Fix from $2,3002026-05-09 CRITICAL 9.0 CVE-2026-42571 Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.2… Patch available Fix from $2,3002026-05-09 CRITICAL 9.4 CVE-2026-42569 phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access… Patch available Fix from $2,3002026-05-09 CRITICAL 9.8 CVE-2026-42257 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::… Net\ 0.4.24 / 0.5.14+ Fix from $2,3002026-05-09 CRITICAL 9.1 CVE-2026-42560 auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provide… Patch available Fix from $2,3002026-05-09 CRITICAL 9.8 CVE-2026-6665 The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-… Pgbouncer 1.25.2+ Fix from $2,3002026-05-09