Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-40088 PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are exposed to user-controlled i… Praisonai 4.5.121+ Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Nati… Tomcat 1.3.7 / 2.0.14+ Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2025-13926 An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls B… Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-39912 V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the … Patch available Fix from $2,3002026-04-09 CRITICAL 9.9 CVE-2026-34987 Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler back… Wasmtime 36.0.7 / 42.0.2+ Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-31170 An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-pass parame… A3300r Firmware Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-28205 OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to th… Openplc V3 Firmware Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5971 A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/action… Metagpt after 0.8.1 Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5970 A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MB… Metagpt after 0.8.1 Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-39987 KEVEPSS 97% marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks au… Marimo 0.23.0+ Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5962 A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The ma… Ch22 Firmware Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.6 CVE-2026-39962 MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in Apa… Misp 2.5.36+ Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-39958 oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repositories (topics) named "Topic… Patch available Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-30479 A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted execut… Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2025-15480 In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a use… Ubuntu Desktop Provision Patch available Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-5445 An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The lookup-table decoding logic used f… Orthanc 1.12.11+ Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5443 A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication f… Orthanc 1.12.11+ Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5442 A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (U… Orthanc 1.12.11+ Fix from $2,3002026-04-09 CRITICAL 9.9 CVE-2025-62718 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization … Axios 0.31.0 / 1.15.0+ Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2025-50228 Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. Jizhicms Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2025-57735 When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was inte… Airflow 3.2.0+ Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-34184 AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and ev… Control System 9.8.5+ Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-34179 In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PU… Lxd after 6.7 Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-34178 In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates … Lxd after 6.7 Fix from $2,3002026-04-09 CRITICAL 9.1 CVE-2026-34177 Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omit… Lxd after 6.7 Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5854EPSS 18% A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cst… Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5853EPSS 14% A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is the function setIpv6LanCfg of … Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5852EPSS 14% A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the … Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5851EPSS 14% A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi o… Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5850EPSS 16% A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of … Mitigation only Fix from $2,3002026-04-09