Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-6443 All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a ma… Mitigation only Fix from $2,3002026-04-17 CRITICAL 9.8 CVE-2026-34018 An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product. Cubecart 6.6.0+ Fix from $2,3002026-04-17 CRITICAL 9.0 CVE-2026-40322 SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "… Siyuan 3.6.4+ Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-33122 DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API dat… Dataease 2.10.21+ Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-33082 DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export f… Dataease 2.10.21+ Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-27820 zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer ove… Zlib 3.0.1 / 3.1.2+ Fix from $2,3002026-04-16 CRITICAL 9.1 CVE-2026-5426 Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent… Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.1 CVE-2026-37347 SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php. Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-37345 SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php. Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-37340 SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php. Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-37339 SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php. Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.4 CVE-2026-37338 SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php. Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.1 CVE-2026-33804 @fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. … Fastify\/middie 9.3.2+ Fix from $2,3002026-04-16 CRITICAL 9.1 CVE-2026-6270 @fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instances. When a Fastify application… Fastify\/middie 9.3.2+ Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-31843 The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthent… Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.1 CVE-2024-2374 The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entiti… Api Manager 2.0.0.328 / 2.0.0.348+ Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-3596 The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin regis… Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.9 CVE-2026-22619 Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an… Intelligent Power Protector 2.00+ Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-6350 MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the p… Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-6349 The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS command… Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-40962 FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c. Ffmpeg 8.1+ Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-40504 Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bou… Patch available Fix from $2,3002026-04-16 CRITICAL 9.3 CVE-2026-40959 Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod. Patch available Fix from $2,3002026-04-16 CRITICAL 9.8 CVE-2026-4880 The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege … Mitigation only Fix from $2,3002026-04-16 CRITICAL 9.1 CVE-2026-6388 A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a m… Mitigation only Fix from $2,3002026-04-15 CRITICAL 9.4 CVE-2026-40173 Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where… Dgraph 25.3.2+ Fix from $2,3002026-04-15 CRITICAL 9.6 CVE-2026-6296 Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafte… Chrome 147.0.7727.101+ Fix from $2,3002026-04-15 CRITICAL 9.1 CVE-2025-41118 Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (CO… Pyroscope 1.15.2+ Fix from $2,3002026-04-15 CRITICAL 9.2 CVE-2026-5189 CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with net… Mitigation only Fix from $2,3002026-04-15 CRITICAL 9.1 CVE-2026-6290 Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token… Velociraptor 0.76.3+ Fix from $2,3002026-04-15