Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-3916 Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a craf… Chrome 146.0.7680.71+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-32136 AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentic… Adguardhome 0.107.73+ Fix from $2,3002026-03-11 CRITICAL 9.1 CVE-2026-32133 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Prior to 6.1.0, a blind SSRF vulnerability … 2fauth 6.1.0+ Fix from $2,3002026-03-11 CRITICAL 9.9 CVE-2026-27591 Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS al… Winter 1.0.477 / 1.1.12+ Fix from $2,3002026-03-11 CRITICAL 9.0 CVE-2026-32118 OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scriptin… Openemr 8.0.0.1+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2025-70041 An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master. Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2025-70024 An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benkeen generatedata 4.0.14. Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.9 CVE-2025-66956 Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachme… Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31976 xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull … Xygeni Action after 6.4.0 Fix from $2,3002026-03-11 CRITICAL 10.0 CVE-2026-31957 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a conf… Himmelblau 3.1.0+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31900 Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject:… Black 26.3.0+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31896 WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. T… Wegia 3.6.6+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-27703 RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded de… Riot after 2026.01 Fix from $2,3002026-03-11 CRITICAL 9.1 CVE-2026-27478 Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Uni… Unitycatalog after 0.4.0 Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31881 Runtipi is a personal homeserver orchestrator. Prior to 4.8.0, an unauthenticated attacker can reset the operator (admin) password when a password-re… Runtipi 4.8.0+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31877 Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a certain endpoint could result i… Frappe 14.99.0 / 15.84.0+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31874 Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the application does not properly… Taskosaur Patch available Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2019-25487EPSS 8% SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands b… Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2019-25471 FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the… File Thingie after 2.5.7 Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2019-25468 NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by … Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2018-25159 Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated att… Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31975 Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection v… Cloud Cli 1.25.0+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31871 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL inje… Parse Server 8.6.31 / 9.6.0+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31856 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the P… Parse Server 8.6.29 / 9.6.0+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31852 Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execut… Jellyfin Patch available Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-31840 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacke… Parse Server 8.6.28 / 9.6.0+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2026-1524 An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following c… Neo4j 5.26.22 / 2026.02+ Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2025-70082 An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component Eds3016ps1ns Firmware Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.8 CVE-2025-67041 An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly saniti… Eds3016ps1ns Firmware Mitigation only Fix from $2,3002026-03-11 CRITICAL 9.1 CVE-2025-67039 An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to th… Eds3016ps1ns Firmware Mitigation only Fix from $2,3002026-03-11