Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-5722 The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the gues… Mitigation only Fix from $2,3002026-05-05 CRITICAL 9.8 CVE-2026-42238 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) tha… Nginx Ui 2.3.8+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42222 Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the init… Nginx Ui Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42221 Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim … Nginx Ui 2.3.8+ Fix from $2,3002026-05-04 CRITICAL 9.3 CVE-2026-41926 WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cgi binary across five request … Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.3 CVE-2026-41925 WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi binary's reboot_time function th… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.3 CVE-2026-41924 WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest.cgi binary that allows unaut… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.3 CVE-2026-41923 WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cgi binary that allows unauthen… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.3 CVE-2026-41922 WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cgi binary that allows unauthen… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.6 CVE-2026-42235 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a mali… N8n 1.123.32 / 2.17.4+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42233 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select opera… N8n 1.123.32 / 2.17.4+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42796 Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins que… Arelle 2.39.10+ Fix from $2,3002026-05-04 CRITICAL 9.6 CVE-2026-42087 OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before … Cosmos 7.0.0+ Fix from $2,3002026-05-04 CRITICAL 9.4 CVE-2026-41571 Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("nu… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42812 In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to re… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42811 In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or tabl… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42810 Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table acc… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.9 CVE-2026-42809 Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been val… Polaris 1.4.1+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42376 D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init… Dir 456u Firmware Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.6 CVE-2026-42090 Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Androi… Notesnook Desktop 3.3.15 / 3.3.20+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42076 Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function… Mitigation only Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-42027 Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M… Opennlp 2.5.9+ Fix from $2,3002026-05-04 CRITICAL 9.1 CVE-2026-40682 XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0… Opennlp 2.5.9+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-26956 vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker cod… Vm2 3.10.5+ Fix from $2,3002026-05-04 CRITICAL 10.0 CVE-2026-26332 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code.… Vm2 3.11.0+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-25293 Buffer overflow due to incorrect authorization in PLC FW Qca7005 Firmware No fix yet Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-24120 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing at… Vm2 3.10.5+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-24118 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to wr… Vm2 3.11.0+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-24781 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function… Vm2 3.11.0+ Fix from $2,3002026-05-04 CRITICAL 9.3 CVE-2025-13605 3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands … Mitigation only Fix from $2,3002026-05-04