Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-28798 ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a proxy endpoint (/v1/sys/prox… Zimaos 1.5.3+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-25726 Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator … Cloudreve 4.13.0+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-32186 Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network. Bing No fix yet Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-0545 In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` a… Mlflow Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.6 CVE-2026-28373 The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when proce… Stackfield 1.10.2+ Fix from $2,3002026-04-03 CRITICAL 9.0 CVE-2026-35216EPSS 12% Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Bud… Budibase 3.33.4+ Fix from $2,3002026-04-03 CRITICAL 9.9 CVE-2026-31818 Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST d… Budibase 3.33.4+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-31402 In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache u… Linux Kernel 5.10.253 / 6.1.167+ Fix from $2,3002026-04-03 CRITICAL 9.1 CVE-2026-23455 In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() In DecodeQ9… Linux Kernel 5.10.253 / 5.15.203+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-23450 In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller repo… Linux Kernel 5.15.203 / 6.1.167+ Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-5463 Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attackers to inject newline charact… Pymetasploit3 after 1.0.6 Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-33107 Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. Azure Databricks Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-33105 Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Azure Kubernetes Service Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-32213 Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. Azure Ai Foundry Mitigation only Fix from $2,3002026-04-03 CRITICAL 9.8 CVE-2026-35053 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow executio… Oneuptime 10.0.42+ Fix from $2,3002026-04-02 CRITICAL 9.3 CVE-2026-34932 hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is a stored XSS vulnerability that can lead to CSRF. This is… Hoppscotch 2026.3.0+ Fix from $2,3002026-04-02 CRITICAL 9.6 CVE-2026-34931 hoppscotch is an open source API development ecosystem. Prior to version 2026.3.0, there is an open redirect vulnerability that leads to token exfilt… Hoppscotch 2026.3.0+ Fix from $2,3002026-04-02 CRITICAL 9.9 CVE-2026-34838 Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.156, 25.0.90, and 26.0.12, a vulnerability i… Group Office 6.8.156 / 25.0.90+ Fix from $2,3002026-04-02 CRITICAL 9.8 CVE-2024-14034 Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauth… Mitigation only Fix from $2,3002026-04-02 CRITICAL 9.1 CVE-2026-34758 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Nu… Oneuptime 10.0.40+ Fix from $2,3002026-04-02 CRITICAL 9.1 CVE-2026-34745 Fireshare facilitates self-hosted media and link sharing. Prior to version 1.5.3, the fix for CVE-2026-33645 was applied to the authenticated /api/up… Fireshare 1.5.3+ Fix from $2,3002026-04-02 CRITICAL 9.8 CVE-2026-5368 A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the com… Car Rental Project Mitigation only Fix from $2,3002026-04-02 CRITICAL 9.8 CVE-2026-34877 An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session st… Mbed Tls 3.6.6+ Fix from $2,3002026-04-02 CRITICAL 9.4 CVE-2026-33950 Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnera… Signal K Server 2.24.0+ Fix from $2,3002026-04-02 CRITICAL 9.9 CVE-2026-25212 An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileges, an attacker with pmm-admi… Monitoring And Management 3.7.0+ Fix from $2,3002026-04-02 CRITICAL 9.8 CVE-2026-33746 Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWTService::decode() method did … Convoy 4.5.1+ Fix from $2,3002026-04-02 CRITICAL 9.8 CVE-2026-35002 Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arb… Agno 2.3.24+ Fix from $2,3002026-04-02 CRITICAL 10.0 CVE-2026-32871 FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP exposes internal APIs to MCP clien… Fastmcp 3.2.0+ Fix from $2,3002026-04-02 CRITICAL 9.8 CVE-2026-5334 A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=e… Online Enrollment System Mitigation only Fix from $2,3002026-04-02 CRITICAL 9.8 CVE-2026-5333 A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/to… Content Management System Mitigation only Fix from $2,3002026-04-02