Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-42217 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From… Openexr 3.2.9 / 3.3.11+ Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-42216 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From… Openexr 3.2.9 / 3.3.11+ Fix from $2,3002026-05-07 CRITICAL 9.4 CVE-2026-41203 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.4 CVE-2026-41202 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-41201 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In vers… Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-40982 Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or … Spring Cloud Config 3.1.14 / 4.1.10+ Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-44597 Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011. Tor 0.4.9.7+ Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-40281 Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for co… Gotenberg 8.31.0+ Fix from $2,3002026-05-06 CRITICAL 9.6 CVE-2026-44112 OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirec… Openclaw 2026.4.22+ Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-44109 OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated re… Openclaw 2026.4.15+ Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-43585 OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. G… Openclaw 2026.4.15+ Fix from $2,3002026-05-06 CRITICAL 9.6 CVE-2026-43581 OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol o… Openclaw 2026.4.10+ Fix from $2,3002026-05-06 CRITICAL 9.1 CVE-2026-43578 OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local back… Openclaw 2026.4.10+ Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-43575 OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactiv… Openclaw 2026.4.10+ Fix from $2,3002026-05-06 CRITICAL 9.6 CVE-2026-7910 Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site iso… Chrome 148.0.7778.96+ Fix from $2,3002026-05-06 CRITICAL 9.6 CVE-2026-7908 Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted … Chrome 148.0.7778.96+ Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-41930 Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthentica… Patch available Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-0300 KEVEPSS 32% A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an un… Pan Os Mitigation only Fix from $2,3002026-05-06 CRITICAL 9.1 CVE-2026-5081 Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (ad… Apache\ after 1.94 Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-43208 In the Linux kernel, the following vulnerability has been resolved: net: do not pass flow_id to set_rps_cpu() Blamed commit made the assumption tha… Linux Kernel 6.18.16 / 6.19.6+ Fix from $2,3002026-05-06 CRITICAL 9.1 CVE-2026-43197 In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole… Linux Kernel 6.18.16 / 6.19.6+ Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-43198 In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock(… Linux Kernel 6.18.16 / 6.19.6+ Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-43186 In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receiv… Linux Kernel 5.15.202 / 6.1.165+ Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-43185 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() smb_direct_prep… Linux Kernel 6.18.16 / 6.19.6+ Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2026-43125 In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_n… Linux Kernel 6.12.75 / 6.18.16+ Fix from $2,3002026-05-06 CRITICAL 9.1 CVE-2025-59852 HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encrypt… Dfxanalytics 4.1+ Fix from $2,3002026-05-06 CRITICAL 9.8 CVE-2025-59851 HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-componen… Dfxanalytics 4.1+ Fix from $2,3002026-05-06 CRITICAL 9.1 CVE-2026-43117 In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file(… Linux Kernel 6.6.136 / 6.12.83+ Fix from $2,3002026-05-06 CRITICAL 9.4 CVE-2026-43114 In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New t… Linux Kernel 6.6.136 / 6.12.83+ Fix from $2,3002026-05-06 CRITICAL 9.1 CVE-2026-43083 In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (tra… Linux Kernel 6.18.24 / 6.19.14+ Fix from $2,3002026-05-06