Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-75843 ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated … No fix yet Fix from $5,7502026-08-18 CRITICAL 9.1 CVE-2026-75837 Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admi… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-75627 Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication fil… Patch available Fix from $5,7502026-08-18 CRITICAL 9.3 CVE-2026-75626 SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject … No fix yet Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-34884 SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking M… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-15748 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.1 CVE-2026-75094 A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-67919 An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginAppli… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-42164 Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to rec… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-42162 Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-38165 A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers t… Patch available Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67960 An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, C… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.6 CVE-2026-71424 Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} end… Patch available Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67868 A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67854 SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code No fix yet Fix from $5,7502026-08-17 CRITICAL 9.3 CVE-2026-64849 KEVEPSS 8% MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated… Mlflow 3.15.0+ Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-51977 An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-42163 Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain c… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-75110 MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, d… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-75106 OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attack… Patch available Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67967 Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-448… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67966 Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell acces… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67965 An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67926 An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67917 zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` comma… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-66795 A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSR… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.9 CVE-2026-65974 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permissio… Patch available Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-47698 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Funct… Patch available Fix from $5,7502026-08-17 CRITICAL 9.9 CVE-2026-47686 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedE… Patch available Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-39255 Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_… No fix yet Fix from $5,7502026-08-17