Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-5849 A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component HTTP Handler. Executing a ma… I12 Firmware Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-5841 A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of the component HTTP Handler. E… I3 Firmware Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.8 CVE-2026-1830EPSS 8% The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insuffic… Mitigation only Fix from $2,3002026-04-09 CRITICAL 9.4 CVE-2026-3199 A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with ta… Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-5902 Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media … Chrome 147.0.7727.55+ Fix from $2,3002026-04-08 CRITICAL 9.6 CVE-2026-5874 Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures … Chrome 147.0.7727.55+ Fix from $2,3002026-04-08 CRITICAL 9.1 CVE-2026-40035 Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug conf… Unfurl after 2025.08 Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-39890 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files wit… Praisonai after 4.5.114 Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-39892 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contig… Cryptography 46.0.7+ Fix from $2,3002026-04-08 CRITICAL 9.9 CVE-2026-39888 PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", w… Praisonai 1.5.115+ Fix from $2,3002026-04-08 CRITICAL 9.1 CVE-2026-39429 kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cach… Kcp 0.29.3 / 0.30.3+ Fix from $2,3002026-04-08 CRITICAL 9.9 CVE-2026-35477 InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to u… Inventree after 1.2.6 Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-2942 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadP… Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-33466 Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code executi… Logstash 8.19.14 / 9.2.8+ Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2025-52221 Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters. Ac6 Firmware Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.1 CVE-2026-31017 A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frappe Framework v16.1.1, where us… Erpnext Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.1 CVE-2023-46945 QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request Qd after 20230821 Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-33229 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly p… Xwiki 17.4.8 / 17.10.1+ Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-31040 A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command… Stata Mcp 1.13.0+ Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-39394 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.4.0+ Fix from $2,3002026-04-08 CRITICAL 9.3 CVE-2025-14816 Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICON… Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.3 CVE-2025-14815 Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Sui… Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.1 CVE-2026-5300 Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data … Coolercontrold 4.0.0+ Fix from $2,3002026-04-08 CRITICAL 9.6 CVE-2026-39640 Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from… Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.6 CVE-2026-39620 Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affec… Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.6 CVE-2026-39619 Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Bus… Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.6 CVE-2026-39617 Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestr… Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-33088 Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute an arbitrary SQL statement. Movable Type 8.0.10 / 8.8.3+ Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-25776 Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script. Movable Type 8.0.10 / 8.8.3+ Fix from $2,3002026-04-08 CRITICAL 9.8 CVE-2026-3535 The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownl… Mitigation only Fix from $2,3002026-04-08