Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-2699EPSS 60% Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to … Sharefile Storage Zones Controller 5.12.4+ Fix from $2,3002026-04-02 CRITICAL 9.1 CVE-2026-33615 An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization … Mbconnect24 after 2.19.4 Fix from $2,3002026-04-02 CRITICAL 9.1 CVE-2026-29143 SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an a… Secure Email Gateway 15.0.3+ Fix from $2,3002026-04-02 CRITICAL 9.8 CVE-2026-29139 SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password. Secure Email Gateway 15.0.3+ Fix from $2,3002026-04-02 CRITICAL 9.1 CVE-2026-29133 SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address. Secure Email Gateway 15.0.3+ Fix from $2,3002026-04-02 CRITICAL 9.8 CVE-2026-5244 A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS… Mongoose 7.21+ Fix from $2,3002026-04-02 CRITICAL 9.0 CVE-2026-34571 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34569 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34568 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34567 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34566 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34565 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34564 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34563 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34562 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34560 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34559 CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior t… Ci4ms 0.31.0.0+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-4101 IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Acces… Security Verify Access after 11.0.2.0 Fix from $2,3002026-04-01 CRITICAL 9.1 CVE-2026-34873 An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session. Mbed Tls 3.6.6 / 4.1.0+ Fix from $2,3002026-04-01 CRITICAL 9.0 CVE-2026-34529 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver… Filebrowser 2.62.2+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-34528 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver… Filebrowser 2.62.2+ Fix from $2,3002026-04-01 CRITICAL 9.1 CVE-2026-34520 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs)… Aiohttp 3.13.4+ Fix from $2,3002026-04-01 CRITICAL 9.1 CVE-2026-34872 An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to impr… Mbed Tls 3.6.6+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-34456 Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before … Reviactyl Patch available Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-34875 An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys. Mbed Tls 1.1.0 / 3.6.6+ Fix from $2,3002026-04-01 CRITICAL 9.1 CVE-2026-34751 Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and payload, a vulnerability in … Payload 3.79.1+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-34236 Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applications built with the Auth… Auth0 Php 8.19.0+ Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-34159 llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor() skips all bounds validation … Llama.cpp Patch available Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2026-34072 Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs. Prior to version 2.2.0, an … Cronmaster 2.2.0+ Fix from $2,3002026-04-01 CRITICAL 9.1 CVE-2026-33990 Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains a… Model Runner 1.1.25+ Fix from $2,3002026-04-01