Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-25646 Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code… Mailcarrier Mitigation only Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2019-25628 Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute … Mitigation only Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4755 CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. Android Imagemagick7 7.1.2-11+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-4753 Out-of-bounds Read vulnerability in slajerek RetroDebugger.This issue affects RetroDebugger: before v0.64.72. Patch available Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-4750 Out-of-bounds Read vulnerability in fabiangreffrath woof.This issue affects woof: before woof_15.3.0. Patch available Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-33854 Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10. Android Imagemagick7 7.1.2-10+ Fix from $2,3002026-03-24 CRITICAL 10.0 CVE-2026-4746 Out-of-bounds Write vulnerability in timeplus-io proton (base/poco/Foundation/src‎ modules). This vulnerability is associated with program files infl… Patch available Fix from $2,3002026-03-24 CRITICAL 10.0 CVE-2026-4745 Improper Control of Generation of Code ('Code Injection') vulnerability in dendibakh perf-ninja (labs/misc/pgo/lua modules). This vulnerability is as… Patch available Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-4283 The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to unauthorized account destruction in all versions up to, and including, 3.1.38. This i… Mitigation only Fix from $2,3002026-03-24 CRITICAL 9.3 CVE-2026-4744 Out-of-bounds Read vulnerability in rizonesoft Notepad3 (‎scintilla/oniguruma/src modules). This vulnerability is associated with program files regco… Patch available Fix from $2,3002026-03-24 CRITICAL 9.4 CVE-2026-4739 Integer Overflow or Wraparound vulnerability in InsightSoftwareConsortium ITK (‎Modules/ThirdParty/Expat/src/expat modules).This issue affects ITK: b… Patch available Fix from $2,3002026-03-24 CRITICAL 9.4 CVE-2026-4738 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulne… Patch available Fix from $2,3002026-03-24 CRITICAL 9.4 CVE-2026-4734 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in yoyofr modizer (libs/libopenmpt/openmpt-trunk/include/premak… Patch available Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-4001 The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via… Mitigation only Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-33286 Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary me… Graphiti 1.10.2+ Fix from $2,3002026-03-24 CRITICAL 9.1 CVE-2026-33202 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's … Rails 7.2.3.1 / 8.0.4.1+ Fix from $2,3002026-03-24 CRITICAL 9.6 CVE-2026-33211 Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3… Tekton Pipelines 1.3.3 / 1.6.1+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-33195 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's … Rails 7.2.3.1 / 8.0.4.1+ Fix from $2,3002026-03-24 CRITICAL 9.3 CVE-2026-4681 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through t… Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.1 CVE-2026-32913 OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across… Openclaw 2026.3.7+ Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-3055 KEVEPSS 87% Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread Netscaler Application Delivery Controller 13.1-37.262 / 13.1-62.23+ Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-30849 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authenti… Mantisbt 2.28.1+ Fix from $2,3002026-03-23 CRITICAL 9.4 CVE-2026-2298 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web … Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.4 CVE-2026-33716 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/stand… Avideo after 26.0 Fix from $2,3002026-03-23 CRITICAL 9.0 CVE-2026-0898 An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Micro… Mitigation only Fix from $2,3002026-03-23 CRITICAL 9.4 CVE-2026-4404 Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI. Harbor after 2.15.0 Fix from $2,3002026-03-23 CRITICAL 10.0 CVE-2026-33478EPSS 13% WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain toget… Avideo after 26.0 Fix from $2,3002026-03-23 CRITICAL 9.8 CVE-2026-33352 WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` … Avideo 26.0+ Fix from $2,3002026-03-23 CRITICAL 9.1 CVE-2026-33351 WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standA… Avideo 26.0+ Fix from $2,3002026-03-23 CRITICAL 9.1 CVE-2026-33297 WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administr… Avideo 26.0+ Fix from $2,3002026-03-23