Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-31607 In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP clie… Linux Kernel 6.6.136 / 6.12.83+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31589 In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directly in folio_unmap_invalidate() We can only call f… Linux Kernel 6.19.14 / 7.0.1+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-31536 In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion without IB_SEND_SIGNALED With sm… Linux Kernel 6.18.11 / 6.19.1+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-25660 CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs … Codechecker 6.27.4+ Fix from $2,3002026-04-24 CRITICAL 9.9 CVE-2026-21515 Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. Azure Iot Central No fix yet Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-1951 Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability. As320t Firmware 1.12+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-1950 Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability. As320t Firmware 1.16+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-1949 Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service. As320t Firmware 1.16+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-41323 Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiC… Kyverno 1.16.4 / 1.17.2+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-33078 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability i… Roxy Wi 8.2.6.4+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-33076 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p… Roxy Wi 8.2.6.4+ Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-40630 A vulnerability in  SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access… X3500 Firmware Mitigation only Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-40620 A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authenticat… X3500 Firmware Mitigation only Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-35503 A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on har… X3500 Firmware Mitigation only Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-27843 A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient … X3500 Firmware Mitigation only Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-25775 A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication… Mitigation only Fix from $2,3002026-04-24 CRITICAL 9.8 CVE-2026-41274 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-pr… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 10.0 CVE-2026-35431 Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. Entra Id Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-33819 Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. Bing Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.3 CVE-2026-33102 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 365 Copilot Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-26210 KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a… Ktransformers after 0.5.3 Fix from $2,3002026-04-23 CRITICAL 10.0 CVE-2026-26150 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. Purview Ediscovery Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.6 CVE-2026-24303 Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. Partner Center No fix yet Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41276EPSS 7% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers t… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41268EPSS 14% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41267 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41265 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41264 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-25874EPSS 16% LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize da… Lerobot after 0.5.1 Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-6074 Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debu… Mitigation only Fix from $2,3002026-04-23