Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-44313 Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-… Mitigation only Fix from $2,3002026-05-09 CRITICAL 9.0 CVE-2026-42556 Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store ar… Postiz Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.9 CVE-2026-42454 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker cont… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-42354 Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered i… Sentry 26.4.1+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-42302 FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to una… Patch available Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-42298 Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflo… Postiz 2.21.7+ Fix from $2,3002026-05-08 CRITICAL 10.0 CVE-2026-42287 Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attack… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2026-42193 Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification pa… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-44400 MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers … Mailenable 10.56+ Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2026-44694 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before vers… N8n Mcp 2.50.2+ Fix from $2,3002026-05-08 CRITICAL 10.0 CVE-2026-42160 Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before v… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-42072 Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-… Patch available Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-41889 pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar… Pgx 5.9.2+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-38360EPSS 6% Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash… Patch available Fix from $2,3002026-05-08 CRITICAL 10.0 CVE-2026-41070 openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version … Patch available Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2026-44497 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 int… Zebra Script 4.4.0 / 6.0.0+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-43465 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ XDP multi-buf pr… Linux Kernel 6.7 / 6.13+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-43414 In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free In qla24xx_els_dcmd_iocb() sp-… Linux Kernel 5.16 / 6.2+ Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2026-43407 In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() This pa… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2026-43406 In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in process_message_header() If t… Linux Kernel 5.15.203 / 6.1.167+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-43402 In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit paths to prevent use-after-free Guillaume rep… Linux Kernel 6.18.19 / 6.19.9+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-43384 In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, M… Linux Kernel 6.12.78 / 6.18.19+ Fix from $2,3002026-05-08 CRITICAL 9.4 CVE-2026-43383 In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, … Linux Kernel 5.10.253 / 6.1.167+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-43379 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() opinfo pointer… Linux Kernel 6.6.130 / 6.12.78+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-43376 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by using call_rcu() for oplock_info ksmbd currently f… Linux Kernel 6.6.130 / 6.12.78+ Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2026-41583 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra fai… Zebra Script 4.3.1 / 5.0.2+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-41574 Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existi… Nhost\/auth 0.49.1+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-37431 Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.6 CVE-2026-44336 PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers fou… Praisonai 4.6.34+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-44335 PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by at… Praisonaiagents 1.6.32+ Fix from $2,3002026-05-08