Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-38835 Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName… W30e Firmware Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.3 CVE-2019-25714 Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to… Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-40498 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system … Freescout 1.8.213+ Fix from $2,3002026-04-21 CRITICAL 9.3 CVE-2025-41029 SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, create, update, and delete da… Mitigation only Fix from $2,3002026-04-21 CRITICAL 10.0 CVE-2025-15638 Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before 0.14 includes versions of Dr… Net\ 0.14+ Fix from $2,3002026-04-21 CRITICAL 10.0 CVE-2017-20230 Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class name into a signed integer bu… Storable 3.05+ Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-6771 Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 1… Firefox 140.10.0 / 150.0+ Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-6768 Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-6760 Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-6748 Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and … Firefox 140.10.0 / 150.0+ Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-5965 NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands an… Mitigation only Fix from $2,3002026-04-21 CRITICAL 9.1 CVE-2026-40496 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using a weak and pre… Freescout 1.8.213+ Fix from $2,3002026-04-21 CRITICAL 10.0 CVE-2026-39861 Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks poin… Claude Code 2.1.64+ Fix from $2,3002026-04-21 CRITICAL 9.9 CVE-2026-41329 OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and sen… Openclaw 2026.3.31+ Fix from $2,3002026-04-21 CRITICAL 9.8 CVE-2026-5450 Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width spec… Glibc after 2.43 Fix from $2,3002026-04-20 CRITICAL 9.1 CVE-2026-33432 Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authenticat… Roxy Wi after 8.2.8.2 Fix from $2,3002026-04-20 CRITICAL 9.9 CVE-2026-32613 Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to proce… Spinnaker 2025.3.2 / 2025.4.2+ Fix from $2,3002026-04-20 CRITICAL 9.9 CVE-2026-32604 Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor c… Spinnaker 2025.3.2 / 2025.4.2+ Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-29646 In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enabl… Patch available Fix from $2,3002026-04-20 CRITICAL 9.1 CVE-2026-6257 Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing return statement in the file … Patch available Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-32311 Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a u… Flowsint Patch available Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-29649 NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectly masked/… Nemu Patch available Fix from $2,3002026-04-20 CRITICAL 9.4 CVE-2026-39109 SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the lo… Mitigation only Fix from $2,3002026-04-20 CRITICAL 9.9 CVE-2026-30269 Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role vi… Doorman Mitigation only Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-39918 Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parameter is written unsanitized in… Patch available Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-24467 OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in ve… Openaev 2.0.13+ Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-5760 SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious tokenizer.chat_template is load… Sglang 0.5.11+ Fix from $2,3002026-04-20 CRITICAL 9.1 CVE-2026-33557 A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set… Kafka 4.1.2+ Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-5964 EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to r… Easyflow .net after 6.6.17 Fix from $2,3002026-04-20 CRITICAL 9.8 CVE-2026-5963 EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to r… Easyflow .net after 6.6.17 Fix from $2,3002026-04-20