Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-35431 Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. Entra Id Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-33819 Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. Bing Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.3 CVE-2026-33102 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 365 Copilot Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-26210 KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a… Ktransformers after 0.5.3 Fix from $2,3002026-04-23 CRITICAL 10.0 CVE-2026-26150 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. Purview Ediscovery Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.6 CVE-2026-24303 Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. Partner Center No fix yet Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41276EPSS 7% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers t… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41268EPSS 14% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41267 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41265 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41264 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth… Flowise 3.1.0+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-25874EPSS 16% LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize da… Lerobot after 0.5.1 Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-6074 Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debu… Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41247 elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulner… Elfinder 2.1.67+ Fix from $2,3002026-04-23 CRITICAL 9.6 CVE-2026-6920 Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to p… Chrome 147.0.7727.116+ Fix from $2,3002026-04-23 CRITICAL 9.6 CVE-2026-6919 Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially… Chrome 147.0.7727.116+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-31533 In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption The -EBUS… Linux Kernel 5.15.203 / 6.1.169+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-31181 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunServerAddr p… A3300r Firmware Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-31178 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxAlive par… A3300r Firmware Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-31177 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinAlive par… A3300r Firmware Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-31175 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable param… A3300r Firmware Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.9 CVE-2026-40472 In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sanitization, enabling stored Cro… Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.6 CVE-2026-40471 hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage s… Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.9 CVE-2026-40470 A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the docum… Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-23751 Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel … Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2025-62373 Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a v… Pipecat 0.0.94+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2025-50229 Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module. Jizhicms Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41460 SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input p… Socialengine after 7.8.0 Fix from $2,3002026-04-23 CRITICAL 9.9 CVE-2026-39440 Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue aff… Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-6887 Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing unauthenticated remote attac… Mitigation only Fix from $2,3002026-04-23