Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2026-44128 SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes atta… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.2 CVE-2026-44126 SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow u… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.3 CVE-2026-44125 SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthe… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-43341 In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema length wraparound in trace fill ioam6_fill_trac… Linux Kernel 6.1.168 / 6.6.134+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-43304 In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When decoding the key, verify that… Linux Kernel 5.15.202 / 6.1.165+ Fix from $2,3002026-05-08 CRITICAL 9.9 CVE-2026-41512 ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerab… 0din Scanner 1.4.1+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-41509 CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there i… Cross Implementation 2026-03-23+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-41507 math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim i… Math Codegen 0.4.3+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-41497 PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or arg… Praisonai 4.6.9+ Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2026-25199 Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudSt… Cloudstack 4.22.0.1+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-8153 OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthenticated attacker to craft co… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.3 CVE-2026-8076 Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentic… Mitigation only Fix from $2,3002026-05-08 CRITICAL 10.0 CVE-2026-6213 A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code exec… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2013-10075 Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Sto… Apache\ after 1.94 Fix from $2,3002026-05-08 CRITICAL 9.9 CVE-2025-69691 Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only … Pfsense Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2025-69690 Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_rebo… Pfsense No fix yet Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2025-69599 RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: th… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2025-67887 1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and exec… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2023-46453 Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both… Mitigation only Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2024-51092EPSS 7% LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), Settings… Librenms 24.10.0+ Fix from $2,3002026-05-08 CRITICAL 9.6 CVE-2026-43944 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerabl… Electerm 3.8.15+ Fix from $2,3002026-05-08 CRITICAL 9.6 CVE-2026-43941 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink… Electerm after 3.8.15 Fix from $2,3002026-05-08 CRITICAL 9.1 CVE-2026-42264 Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL… Axios 1.15.2+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-42208 KEVEPSS 89% LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query… Litellm 1.83.7+ Fix from $2,3002026-05-08 CRITICAL 10.0 CVE-2026-41900 OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was… Openlearnx Patch available Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-41501 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability e… Electerm 3.3.8+ Fix from $2,3002026-05-08 CRITICAL 9.8 CVE-2026-41500 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability e… Electerm 3.3.8+ Fix from $2,3002026-05-08 CRITICAL 9.6 CVE-2026-42880 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a … Argo Cd 3.2.11 / 3.3.9+ Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-8034 A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access … Enterprise Server 3.16.18 / 3.17.15+ Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-7891 A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not adequately describe the special … Mitigation only Fix from $2,3002026-05-07