Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-7037 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstec… Mitigation only Fix from $2,3002026-04-26 CRITICAL 9.8 CVE-2026-7036 A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP… I9 Firmware Mitigation only Fix from $2,3002026-04-26 CRITICAL 9.8 CVE-2026-6987 A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher … Picoclaw after 0.2.4 Fix from $2,3002026-04-25 CRITICAL 9.4 CVE-2026-31685 In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header for all packets `eui64_mt6()` … Linux Kernel 6.6.136 / 6.12.83+ Fix from $2,3002026-04-25 CRITICAL 9.1 CVE-2026-31682 In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND options br_nd_send() parses… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-04-25 CRITICAL 9.8 CVE-2026-6951 Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://… Simple Git 3.36.0+ Fix from $2,3002026-04-25 CRITICAL 9.9 CVE-2026-41478 Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability … Saltcorn 1.4.6 / 1.5.6+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41473 CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated … Cyberpanel 2.4.4+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41248 Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro c… Mitigation only Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41475 BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-sta… Bacnet Stack 1.4.3+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41428 Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-a… Budibase 3.35.4+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-41492 Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/v… Dgraph 25.3.3+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41415 PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a mal… Pjsip 2.17+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41328 Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attack… Dgraph 25.3.3+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41327 Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attack… Dgraph 25.3.3+ Fix from $2,3002026-04-24 CRITICAL 10.0 CVE-2026-42043 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axio… Axios 0.31.1 / 1.15.1+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-42044 Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollutio… Axios 1.15.1+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41677 rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validat… Rust Openssl 0.10.78+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-6911 Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to… Patch available Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-39920 BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints wit… Mitigation only Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31669 In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table loo… Linux Kernel 5.15.203 / 6.1.169+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31668 In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths in seg6 lwtunnel The seg6 l… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31659 In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buffers batadv_tt_prepare_tvlv_… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31657 In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() ca… Linux Kernel 6.1.169 / 6.6.135+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31649 In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode The jumbo_frm() chain-mode imp… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31637 In the Linux kernel, the following vulnerability has been resolved: rxrpc: reject undecryptable rxkad response tickets rxkad_decrypt_ticket() decry… Linux Kernel 6.6.135 / 6.12.82+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-31636 In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read rxgk_verify_authenticator() c… Linux Kernel 6.18.23 / 6.19.13+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31633 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In rxgk_verify_response()… Linux Kernel 6.18.23 / 6.19.13+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31609 In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flus… Linux Kernel 6.18.24 / 6.19.14+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31608 In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush… Linux Kernel 6.18.24 / 6.19.14+ Fix from $2,3002026-04-24