Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-33728 dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI instrumentation registered a cus… Dd Trace Java 1.60.3+ Fix from $2,3002026-03-27 CRITICAL 9.9 CVE-2026-33718 OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in the `get_git_diff()` method a… Openhands 1.5.0+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-33701 OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.26.1, t… Opentelemetry Instrumentation For Java 2.26.1+ Fix from $2,3002026-03-27 CRITICAL 9.6 CVE-2026-33945 Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For container… Incus 6.23.0+ Fix from $2,3002026-03-27 CRITICAL 9.8 CVE-2026-34352 In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or cause an application crash, b… Tigervnc 1.16.2+ Fix from $2,3002026-03-26 CRITICAL 9.9 CVE-2026-33897 Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writ… Incus 6.23.0+ Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2026-33640 Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users not associated with an Identit… Outline 1.6.0+ Fix from $2,3002026-03-26 CRITICAL 9.1 CVE-2026-30458 An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack. Fuel Cms No fix yet Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2026-30457 An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code. Dwoo Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2026-26213EPSS 6% thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulnerability in the WiFi captive p… Thingino Firmware after 2026-03-15 Fix from $2,3002026-03-26 CRITICAL 10.0 CVE-2026-33494 ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versi… Oathkeeper 26.2.0+ Fix from $2,3002026-03-26 CRITICAL 9.1 CVE-2026-27816 EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_transfer_modes copies a variable… Everest 2026.02.0+ Fix from $2,3002026-03-26 CRITICAL 9.1 CVE-2026-27815 EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup copies a variable-length payment… Everest 2026.02.0+ Fix from $2,3002026-03-26 CRITICAL 9.9 CVE-2026-33396 OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can … Oneuptime 10.0.35+ Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2025-55261 HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise th… Aftermarket Cloud Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2025-55270 HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as XSS… Aftermarket Cloud Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2025-55269 HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force… Aftermarket Cloud Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2025-55267 HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicious scripts, gaining full cont… Aftermarket Cloud Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2018-25204 Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through … Library Cms Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2018-25201 School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authenticat… School Management System Cms Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2018-25195 Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authen… Hotel Cms Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2018-25185 Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting … Restaurant Cms Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2018-25183 Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code … Shipping System Cms Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2026-4809 plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a cli… Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2026-4850 A security flaw has been discovered in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checkregisitem.php of th… Simple Laundry System Mitigation only Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2014-125112 Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through … Plack\ 0.23+ Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2026-33942 Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAut… Saloon 4.0.0+ Fix from $2,3002026-03-26 CRITICAL 9.1 CVE-2026-33183 Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, fixture names were used to build file path… Saloon 4.0.0+ Fix from $2,3002026-03-26 CRITICAL 9.8 CVE-2026-30975 Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled au… Sonarr 4.0.16.2942+ Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2025-14917 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected secu… Websphere Application Server 26.0.0.4+ Fix from $2,3002026-03-25