Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-35435 Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.6 CVE-2026-35428 Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s… Azure Cloud Shell Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.0 CVE-2026-33844 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Azure Managed Instance For Apache Cassandra Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.9 CVE-2026-33109 Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. Azure Managed Instance For Apache Cassandra Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-41691 Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag… I18next Http Backend 3.0.5+ Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-42284 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list,… Gitpython 3.1.47+ Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-41902 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts … Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-37709 Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to … Snipe It 8.4.1+ Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-7415 The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on th… Lawn Mower Firmware Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-7414 Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all device… Lawn Mower Firmware Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-7413 A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged… Lawn Mower Firmware Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-7821 Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a … Endpoint Manager Mobile 12.6.1.1+ Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-5788 An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitra… Endpoint Manager Mobile 12.6.1.1+ Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-5787 An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impers… Endpoint Manager Mobile 12.6.1.1+ Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2025-63704 NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2025-63703 npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js(). Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-36458 ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injec… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2025-63706 NPM package next-npm-version1.0.1 is vulnerable to Command injection. Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.6 CVE-2026-6795 URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. … Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.6 CVE-2026-41589 Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wis… Wish No fix yet Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-30496 The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that allows full unauthenticated … Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-8094 Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2. Firefox 140.10.2+ Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-8091 Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.1… Firefox 115.35.2 / 140.10.1+ Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-6508 Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Proper… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2026-42010 A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch… Hardened Images Mitigation only Fix from $2,3002026-05-07 CRITICAL 10.0 CVE-2026-33587 Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the dock… Open Notebook 1.8.4+ Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2025-1978 Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G3… Virtual Storage One Block Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.8 CVE-2025-9661 OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28. This… Virtual Storage One Block Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.3 CVE-2026-41586 Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-44603 Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007. Tor 0.4.9.7+ Fix from $2,3002026-05-07