Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-22563 A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access to the UniFi Play network. A… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-22562 A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on t… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-31048 An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message. Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-40044 Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serializ… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-40042 Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsa… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6195EPSS 14% A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setPasswordCfg of the fil… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2025-31991 Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brute-force attacks past the unsu… Devops Velocity 5.1.7+ Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-31283 In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Ema… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-31282 Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to reveal the login form. An attacker… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-31414 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper Use expect->helper in ctnetl… Linux Kernel 6.1.168 / 6.6.134+ Fix from $2,3002026-04-13 CRITICAL 9.3 CVE-2026-4810 A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.1 CVE-2026-0234 An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft T… Cortex Xsiam 1.5.52+ Fix from $2,3002026-04-13 CRITICAL 9.1 CVE-2026-5085 Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method returns an MD5 digest seeded by the… Solstice\ Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-5936 An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. Thi… Pdf Services Api 2026-04-07+ Fix from $2,3002026-04-13 CRITICAL 9.1 CVE-2026-34865 Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentialit… Harmonyos No fix yet Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-40446 Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.This issue af… Escargot Patch available Fix from $2,3002026-04-13 CRITICAL 9.1 CVE-2026-25209 Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a… Escargot Patch available Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-25208 Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71… Escargot Patch available Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-25207 Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689… Escargot Patch available Fix from $2,3002026-04-13 CRITICAL 9.1 CVE-2026-25206 Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a… Escargot Patch available Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-25205 Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows out-of-bounds write.This issue affects Escargot:commit hash  97e8115a… Escargot Patch available Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6156 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosRules of the file /cgi-bin/cst… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6155 A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6154 A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setWizardCfg of the file /cgi-bin/… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6140 A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of … Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6139 A vulnerability has been found in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6138 A flaw has been found in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.… Mitigation only Fix from $2,3002026-04-13 CRITICAL 9.8 CVE-2026-6132 A vulnerability was determined in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setLedCfg of the file /cgi-bin/cstecg… Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-6131 A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setTracerouteCfg of the file /cgi-… Mitigation only Fix from $2,3002026-04-12 CRITICAL 9.8 CVE-2026-40393 In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an … Mesa 25.3.6+ Fix from $2,3002026-04-12