Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-31436 In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() … Linux Kernel 6.12.80 / 6.18.21+ Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-6235 The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up … Mitigation only Fix from $2,3002026-04-22 CRITICAL 9.1 CVE-2026-4119 The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin… Mitigation only Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-6023 In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when resto… Telerik Ui For Asp.net Ajax 2026.1.421+ Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-41304 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shel… Avideo after 29.0 Fix from $2,3002026-04-22 CRITICAL 9.8 CVE-2026-41144 F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, … Fprime Patch available Fix from $2,3002026-04-22 CRITICAL 9.3 CVE-2026-41064 WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` f… Avideo after 29.0 Fix from $2,3002026-04-22 CRITICAL 9.1 CVE-2026-40575 OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-For… Oauth2 Proxy 7.15.2+ Fix from $2,3002026-04-22 CRITICAL 9.6 CVE-2026-5845 An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an authenticated attac… Enterprise Server 3.14.26 / 3.15.21+ Fix from $2,3002026-04-21 CRITICAL 9.2 CVE-2026-40946 Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in t… Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.9 CVE-2026-40933EPSS 13% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio command… Flowise 3.1.0+ Fix from $2,3002026-04-21 CRITICAL 10.0 CVE-2026-40911 WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON messa… Avideo after 29.0 Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-40910 frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used… Frp 0.68.1+ Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-40892 PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_crea… Pjsip 2.17+ Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-34287 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte… Identity Manager Connector Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-34286 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte… Identity Manager Connector Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-34285 Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte… Identity Manager Connector Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-34279 Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions … Enterprise Manager Base Platform Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-34275 Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions … Advanced Inbound Telephony after 12.2.15 Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-33519 An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly… Portal For Arcgis Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-40903 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB… Goshs 2.0.0+ Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-40887 Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL… Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-40884 goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username bas… Goshs 2.0.0+ Fix from $2,3002026-04-21 CRITICAL 9.3 CVE-2026-40872 mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover logs r… Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-40372EPSS 11% Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. Asp.net Core 10.0.7+ Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-41193 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives… Patch available Fix from $2,3002026-04-21 CRITICAL 9.0 CVE-2026-5652 An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform … Crafty Controller 4.10.4+ Fix from $2,3002026-04-21 CRITICAL 9.4 CVE-2026-40576 excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions u… Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.0 CVE-2026-40569 FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connectio… Patch available Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-40050 CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-40050) in LogScale. This vulne… Mitigation only Fix from $2,3002026-04-21