Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-30993 Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnera… Mitigation only Fix from $2,3002026-04-15 CRITICAL 9.9 CVE-2026-20186EPSS 6% A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying… Identity Services Engine 3.2.0+ Fix from $2,3002026-04-15 CRITICAL 9.8 CVE-2026-20184 A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote att… Mitigation only Fix from $2,3002026-04-15 CRITICAL 9.9 CVE-2026-20180EPSS 6% A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying… Identity Services Engine 3.2.0+ Fix from $2,3002026-04-15 CRITICAL 9.9 CVE-2026-20147EPSS 12% A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operatin… Identity Services Engine Passive Identity Connector 3.1.0+ Fix from $2,3002026-04-15 CRITICAL 9.3 CVE-2025-15610 The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploited if the service is exposed… Mitigation only Fix from $2,3002026-04-15 CRITICAL 9.3 CVE-2026-5387 The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator D… Mitigation only Fix from $2,3002026-04-15 CRITICAL 9.8 CVE-2026-30625 Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define M… Patch available Fix from $2,3002026-04-15 CRITICAL 9.1 CVE-2026-33808 Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router normalization options… Fastify\/express 4.0.5+ Fix from $2,3002026-04-15 CRITICAL 9.1 CVE-2026-33807 @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when inherited… Fastify\/express 4.0.5+ Fix from $2,3002026-04-15 CRITICAL 9.8 CVE-2026-3461 The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to… Mitigation only Fix from $2,3002026-04-15 CRITICAL 9.9 CVE-2026-39842 OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulnerabilities in the rules engin… Openremote 1.22.0+ Fix from $2,3002026-04-15 CRITICAL 9.8 CVE-2026-1555 The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all v… Mitigation only Fix from $2,3002026-04-15 CRITICAL 9.6 CVE-2026-39399 NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec fi… Patch available Fix from $2,3002026-04-14 CRITICAL 9.3 CVE-2026-35589 nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability exists in the bridge's Web… Nanobot 0.1.5+ Fix from $2,3002026-04-14 CRITICAL 9.1 CVE-2026-35033 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpe… Jellyfin 10.11.7+ Fix from $2,3002026-04-14 CRITICAL 9.1 CVE-2026-34457 OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authe… Oauth2 Proxy 7.15.2+ Fix from $2,3002026-04-14 CRITICAL 10.0 CVE-2026-39907 Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts un… Webperfect Image Suite Mitigation only Fix from $2,3002026-04-14 CRITICAL 10.0 CVE-2026-39906 Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthentic… Webperfect Image Suite Mitigation only Fix from $2,3002026-04-14 CRITICAL 9.3 CVE-2026-27304 ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-04-14 CRITICAL 9.3 CVE-2026-5752 Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain trave… Mitigation only Fix from $2,3002026-04-14 CRITICAL 9.3 CVE-2026-34615 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod… Connect 12.11 / 2025.9.15+ Fix from $2,3002026-04-14 CRITICAL 9.8 CVE-2026-33824 KEVEPSS 73% Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $2,3002026-04-14 CRITICAL 9.6 CVE-2026-27303 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary cod… Connect 12.11 / 2025.9.15+ Fix from $2,3002026-04-14 CRITICAL 9.3 CVE-2026-27246 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this… Connect 12.11 / 2025.9.15+ Fix from $2,3002026-04-14 CRITICAL 9.3 CVE-2026-27245 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this… Connect 12.11 / 2025.9.15+ Fix from $2,3002026-04-14 CRITICAL 9.3 CVE-2026-27243 Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this… Connect 12.11 / 2025.9.15+ Fix from $2,3002026-04-14 CRITICAL 9.0 CVE-2026-26149 Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ… Power Apps 3.26032.10.0+ Fix from $2,3002026-04-14 CRITICAL 9.8 CVE-2025-70023 An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6. Mitigation only Fix from $2,3002026-04-14 CRITICAL 9.8 CVE-2026-39813EPSS 23% A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to esc… Fortisandbox 4.4.9 / 5.0.6+ Fix from $2,3002026-04-14