Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-6886 Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remo… Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-6885 Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability, allowing unauthenticated rem… Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-3960 A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior… H2o 3.46.0.10+ Fix from $2,3002026-04-23 CRITICAL 9.1 CVE-2026-41229 Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quo… Froxlor 2.3.6+ Fix from $2,3002026-04-23 CRITICAL 9.9 CVE-2026-41228 Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does… Froxlor 2.3.6+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-3844EPSS 28% The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote'… Mitigation only Fix from $2,3002026-04-23 CRITICAL 10.0 CVE-2026-41679 Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated a… Paperclipai 2026.416.0+ Fix from $2,3002026-04-23 CRITICAL 10.0 CVE-2026-41211 Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` … Vite\+ 0.1.17+ Fix from $2,3002026-04-23 CRITICAL 9.3 CVE-2026-41197 Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode … Mitigation only Fix from $2,3002026-04-23 CRITICAL 10.0 CVE-2026-41196 Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can… Minetest 5.15.2+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-5935 IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary comma… Total Storage Service Console Mitigation only Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41179EPSS 9% Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to… Rclone 1.73.5+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-41176EPSS 33% Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is expose… Rclone 1.73.5+ Fix from $2,3002026-04-23 CRITICAL 9.8 CVE-2026-29198 In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover o… Rocket.chat 7.10.9 / 7.11.6+ Fix from $2,3002026-04-23 CRITICAL 9.1 CVE-2026-41167 Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by in… Patch available Fix from $2,3002026-04-22 CRITICAL 9.1 CVE-2026-33656 EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing … Espocrm 9.3.4+ Fix from $2,3002026-04-22 CRITICAL 9.6 CVE-2026-33471 nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len… Nimiq Proof Of Stake 1.3.0+ Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-34415 Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to… Patch available Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-26354 Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 t… Powerprotect Dp Series Appliance 2.7.9 / 7.13.1.60+ Fix from $2,3002026-04-22 CRITICAL 9.1 CVE-2026-32885 DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction … Ddev 1.25.2+ Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2018-25272 ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with S… Mitigation only Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2018-25270 ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functi… Thinkphp 5.0.23+ Fix from $2,3002026-04-22 CRITICAL 9.6 CVE-2026-6356 A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipul… Augmentt 2025-10-02+ Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-33608 An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its confi… Authoritative 4.9.14 / 5.0.4+ Fix from $2,3002026-04-22 CRITICAL 9.1 CVE-2026-33598 A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet c… Dnsdist 1.9.13 / 2.0.4+ Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-31501 In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use-after-free of CPPI descriptor in RX path cppi5_h… Linux Kernel 6.19.11+ Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-31478 In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() in smb2_calc_max_out_buf_len()… Linux Kernel 5.15.203 / 6.1.168+ Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-31463 In the Linux kernel, the following vulnerability has been resolved: iomap: fix invalid folio access when i_blkbits differs from I/O granularity Com… Linux Kernel 6.19.11+ Fix from $2,3002026-04-22 CRITICAL 9.4 CVE-2026-31448 In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, whe… Linux Kernel 6.1.168 / 6.6.131+ Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-31444 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_grant_oplock() smb_grant_oplock… Linux Kernel 6.12.80 / 6.18.21+ Fix from $2,3002026-04-22