Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-34359 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtil… Hl7 Fhir Core 6.9.4+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-24164 NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability migh… Bionemo Framework 2026-01-21+ Fix from $2,3002026-03-31 CRITICAL 9.4 CVE-2026-24148 NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization … Jetson Linux 35.6.4 / 36.5+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-34243 wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Action… Wenxian after 0.3.1 Fix from $2,3002026-03-31 CRITICAL 9.1 CVE-2026-34235 PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists … Pjsip 2.17+ Fix from $2,3002026-03-31 CRITICAL 9.1 CVE-2026-34221 MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototyp… Mikroorm 6.6.10 / 7.0.6+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-34220 MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a… Mikroorm 6.6.10 / 7.0.6+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30281 An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, … Neo.maru Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30276 An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file imp… Document Translator Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.1 CVE-2026-34532 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, … Parse Server 8.6.67 / 9.7.0+ Fix from $2,3002026-03-31 CRITICAL 10.0 CVE-2026-34162 FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exp… Fastgpt 4.14.9.5+ Fix from $2,3002026-03-31 CRITICAL 9.9 CVE-2026-33579 OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into th… Openclaw 2026.3.28+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30314 Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl… Auto Approval Module after 0.1.1 Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30312 DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism comple… Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30311 Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism compl… Auto Approval Module after 0.1.1 Fix from $2,3002026-03-31 CRITICAL 9.9 CVE-2026-34156EPSS 35% NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's … Nocobase 2.0.28+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30310 In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands. The description for… Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-32917 OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute … Openclaw 2026.3.13+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-32916 OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods throug… Openclaw 2026.3.11+ Fix from $2,3002026-03-31 CRITICAL 9.1 CVE-2025-15618 Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::OnlinePayment::StoredTransaction ge… Business\ Patch available Fix from $2,3002026-03-31 CRITICAL 9.3 CVE-2026-4317 SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated at… Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.1 CVE-2025-10559 A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Rele… 3dexperience Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-5183EPSS 7% A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the file /goform/addRouting. Exec… Tew 713re Firmware Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-34060 Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rub… Ruby Lsp 0.10.2 / 0.26.9+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-34041 act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env:: … Act 0.2.86+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-32714 SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL In… Scitokens Library 1.9.6+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-5176 A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi… A3300r Firmware Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-3300EPSS 41% The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12… Mitigation only Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-30880 baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability in the installer. This issue … Basercms 5.2.3+ Fix from $2,3002026-03-31 CRITICAL 9.8 CVE-2026-27697 baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog posts. This issue has been pa… Basercms 5.2.3+ Fix from $2,3002026-03-31