Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-30832 Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the s… Soft Serve 0.11.4+ Fix from $2,3002026-03-07 CRITICAL 9.3 CVE-2026-29191 ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login V2 interface was discovered … Zitadel 4.12.0+ Fix from $2,3002026-03-07 CRITICAL 9.8 CVE-2026-29186 Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arb… Backstage Plugin Techdocs Node 1.14.3+ Fix from $2,3002026-03-07 CRITICAL 9.3 CVE-2026-29067 ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exists in ZITADEL's password rese… Zitadel 4.7.1+ Fix from $2,3002026-03-07 CRITICAL 9.8 CVE-2026-30824EPSS 36% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvid… Flowise 3.0.13+ Fix from $2,3002026-03-07 CRITICAL 9.8 CVE-2026-30821EPSS 15% Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId… Flowise 3.0.13+ Fix from $2,3002026-03-07 CRITICAL 9.8 CVE-2026-25072 XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogi… Zikestor Sks8310 8x Firmware after 1.04.b07 Fix from $2,3002026-03-07 CRITICAL 9.8 CVE-2026-25070 XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endp… Zikestor Sks8310 8x Firmware after 1.04.b07 Fix from $2,3002026-03-07 CRITICAL 9.8 CVE-2026-29063 Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immuta… Immutable 3.8.3 / 4.3.7+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-30831 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, an… Rocket.chat 7.10.8 / 7.11.5+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28514 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, an… Rocket.chat 7.8.6 / 7.9.8+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-29075 Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and pri… Mesa after 3.5.0 Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-26288 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent … Api.everon.io Mitigation only Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-26051 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent … Mobiliti E Mobi.hu Mitigation only Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2018-25199 OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious … Php Oop Cms Blog Mitigation only Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2018-25187 Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection a… Tina4 Stack Mitigation only Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-2331 An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to imprope… Mitigation only Fix from $2,3002026-03-06 CRITICAL 9.4 CVE-2026-2330 An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain direct… Mitigation only Fix from $2,3002026-03-06 CRITICAL 9.1 CVE-2026-29065 changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerability in the backup restore func… Changedetection 0.54.4+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-29058 AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by inj… Avideo Encoder 7.0+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-29042 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a … Nuclio 1.15.20+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28802 Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passi… Authlib 1.6.7+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28795 OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze, and visualize data through n… Openchatbi 0.2.2+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28438 CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify the configured table name befo… Cocoindex 0.3.34+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-2446 The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated use… Mitigation only Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28794 oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.13.6, a prototype pollution v… Orpc 1.13.6+ Fix from $2,3002026-03-06 CRITICAL 9.0 CVE-2026-28787 OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authentication implementation does no… Oneuptime after 10.0.11 Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28785 Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an attacker can execute arbitrary … Ghostfolio 2.244.0+ Fix from $2,3002026-03-06 CRITICAL 9.3 CVE-2026-28680 Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual asset import feature to perform… Ghostfolio 2.245.0+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-27005 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.3… Chartbrew 4.8.3+ Fix from $2,3002026-03-06