Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-58349 An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 14… Exynos 990 Firmware Mitigation only Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-35171 Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path to be set via the KEDRO_LOGGIN… Kedro 1.3.0+ Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-35052 D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale p… D Tale 3.22.0+ Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-35047 Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allows attackers to upload arbitr… Bravecms 2.0.6+ Fix from $2,3002026-04-06 CRITICAL 9.6 CVE-2026-35044 BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation… Bentoml 1.4.38+ Fix from $2,3002026-04-06 CRITICAL 9.1 CVE-2026-35039 fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not pro… Fast Jwt 6.1.0+ Fix from $2,3002026-04-06 CRITICAL 9.0 CVE-2026-35035 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.2.0+ Fix from $2,3002026-04-06 CRITICAL 9.1 CVE-2026-35030 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt… Litellm 1.83.0+ Fix from $2,3002026-04-06 CRITICAL 9.0 CVE-2026-34989 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-34977 Aperi'Solve is an open-source steganalysis web platform. In versions 3.1.3 through 3.2.0, when uploading a JPEG, a user can specify an optional passw… Aperisolve after 3.2.0 Fix from $2,3002026-04-06 CRITICAL 10.0 CVE-2026-34976 Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware… Dgraph after 25.3.0 Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-34841 Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised version… Bruno 3.2.1+ Fix from $2,3002026-04-06 CRITICAL 9.1 CVE-2026-34950 fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ an… Fast Jwt 6.2.0+ Fix from $2,3002026-04-06 CRITICAL 10.0 CVE-2026-34444 Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are acc… Lupa after 2.6 Fix from $2,3002026-04-06 CRITICAL 10.0 CVE-2026-34208 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), … Sandboxjs 0.8.36+ Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-5663 A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/a… Dcmtk after 3.7.0 Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-31151 An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the application 's resources. Yard Management Solutions Mitigation only Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-31059 A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to exec… 520w Firmware Mitigation only Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-26263EPSS 9% GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GL… Glpi 11.0.6+ Fix from $2,3002026-04-06 CRITICAL 9.8 CVE-2026-31405 In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-04-06 CRITICAL 9.1 CVE-2019-25704 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the fil… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25702 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25700 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sor… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25698 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25696 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the lan… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25694 Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25692 Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.1 CVE-2019-25688 Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code… Kados No fix yet Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2019-25687 Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitr… Pegasus Cms Mitigation only Fix from $2,3002026-04-05 CRITICAL 9.8 CVE-2019-25680 Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by … Advance Gift Shop Pro Script after 2.0.3 Fix from $2,3002026-04-05