Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-15031 A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically,… Mlflow after 3.10.1 Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-31972 SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been a… Samtools 1.21.1+ Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-25873 OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute ar… Patch available Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-31967 HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. In the… Htslib 1.21.1 / 1.22.2+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-31966 HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA sequence alignment data. As one… Htslib 1.21.1 / 1.22.2+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-32633 Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint r… Glances 4.5.2+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-32611 Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL injection in the TimescaleDB export… Glances 4.5.2+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-30704 The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) exposes an unprotected UART interface through accessible hardware pads on the PCB Mitigation only Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-30703 A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02). The adm.cgi e… Mitigation only Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-30702 The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login pa… Mitigation only Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-30701 The web interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) contains hardcoded credential disclosure mechanisms (in the form of S… Mitigation only Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-29859 An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file. Aapanel Mitigation only Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2025-67830 Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. Mura Cms 10.1.4+ Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2025-67829 Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. Mura Cms 10.1.4+ Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-25449 Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through… Mitigation only Fix from $2,3002026-03-18 CRITICAL 9.0 CVE-2026-33265 In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API. Librechat No fix yet Fix from $2,3002026-03-18 CRITICAL 9.6 CVE-2026-30884 mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customization via the web browser. P… Patch available Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-28500 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security con… Onnx after 1.20.1 Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-22171 OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpol… Openclaw 2026.2.19+ Fix from $2,3002026-03-18 CRITICAL 9.8 CVE-2026-27459 pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set… Pyopenssl 26.0.0+ Fix from $2,3002026-03-18 CRITICAL 9.1 CVE-2026-3856 IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an insecure mechanism used for … Db2 Recovery Expert Patch available Fix from $2,3002026-03-17 CRITICAL 9.8 CVE-2026-21994 Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop).… Okit Mitigation only Fix from $2,3002026-03-17 CRITICAL 9.8 CVE-2026-3207 Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access. Bpm Enterprise 4.3.5+ Fix from $2,3002026-03-17 CRITICAL 9.8 CVE-2026-4319 A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file … Simple Food Order System Mitigation only Fix from $2,3002026-03-17 CRITICAL 9.1 CVE-2026-32298 The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authenticated attacker to execute O… Es3 Kvm Firmware Mitigation only Fix from $2,3002026-03-17 CRITICAL 9.1 CVE-2026-25769EPSS 9% Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execut… Wazuh 4.14.3+ Fix from $2,3002026-03-17 CRITICAL 9.1 CVE-2026-25534 ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed th… Patch available Fix from $2,3002026-03-17 CRITICAL 9.0 CVE-2026-3564 A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to ob… Mitigation only Fix from $2,3002026-03-17 CRITICAL 9.8 CVE-2026-4312 GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly acces… Gcb\/fcb Government Financial Cybersecurity Configuration Audit Software Mitigation only Fix from $2,3002026-03-17 CRITICAL 9.1 CVE-2026-4177 YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML e… Yaml\ 1.37+ Fix from $2,3002026-03-16