Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-33765 Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 … Web Interface 6.0+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33654 nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the email channel processing module … Nanobot 0.1.4+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-34387 Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software installer pipeline allows an … Fleet 4.81.1+ Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-34374 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by… Avideo after 26.0 Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-4965 A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/functions/ast_parsers.py of the… Letta Mitigation only Fix from $2,3002026-03-27 CRITICAL 10.0 CVE-2026-4963 A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the… Smolagents Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33770 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` con… Avideo after 26.0 Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-28369 A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-28368 A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed diffe… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-28367 A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-30533 A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter. Online Food Ordering System Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-30532 A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter. Online Food Ordering System Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-30530 A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer actio… Online Food Ordering System Mitigation only Fix from $2,3002026-03-27 CRITICAL 10.0 CVE-2026-30302 The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffec… Coderider after 2.3.6 Fix from $2,3002026-03-27 CRITICAL 9.6 CVE-2026-30304 In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute all commands. The description f… Ai Code after 3.12.4 Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-30303 The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective.… Axon Code after 4.123.1 Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-27876 A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a… Grafana 11.6.0 / 12.0.0+ Fix from $2,3002026-03-27 CRITICAL 9.3 CVE-2026-1496 Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an aut… Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-4622 OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network. Aterm Wg2600hs Firmware 1.3.2 / 1.4.2+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-4620 OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network. Aterm Wx3600hp Firmware 1.4.2 / 1.5.3+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-4619 Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network. Aterm Wx3600hp Firmware 1.5.3+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-25101 Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behav… Bludit 3.17.2+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33280 Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionali… Wcr 1166dhpl Firmware 1.01 / 2.53+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-32669 Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the pr… Wcr 1166dhpl Firmware 1.01 / 2.53+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-27650 OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be execut… Wcr 1166dhpl Firmware 1.01 / 2.53+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-22738 In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious a… Spring Ai 1.0.5 / 1.1.4+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-4908 A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /modstaffinfo.php of the… Simple Laundry System Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33890 MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitra… Mytube 1.8.71+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33747 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when … Buildkit 0.28.1+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33729 OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to… Openfga 1.13.1+ Fix from $2,3002026-03-27