Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-27812 Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vulnerability in versions prior t… Sub2api 0.1.85+ Fix from $2,3002026-02-26 CRITICAL 9.1 CVE-2026-27809 psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed … Psd Tools 1.12.2+ Fix from $2,3002026-02-26 CRITICAL 9.1 CVE-2026-27804 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an… Parse Server 8.6.3 / 9.3.1+ Fix from $2,3002026-02-26 CRITICAL 9.8 CVE-2026-27613 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers … Tinyweb 2.01+ Fix from $2,3002026-02-25 CRITICAL 9.9 CVE-2026-27577EPSS 10% n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation o… N8n 1.123.22 / 2.9.3+ Fix from $2,3002026-02-25 CRITICAL 9.9 CVE-2026-27495 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or… N8n 1.123.22 / 2.9.3+ Fix from $2,3002026-02-25 CRITICAL 9.9 CVE-2026-27494 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or… N8n 1.123.22 / 2.9.3+ Fix from $2,3002026-02-25 CRITICAL 9.0 CVE-2026-27493 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability … N8n 1.123.22 / 2.9.3+ Fix from $2,3002026-02-25 CRITICAL 9.1 CVE-2026-27575 Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 123… Vikunja 2.0.0+ Fix from $2,3002026-02-25 CRITICAL 9.6 CVE-2026-27148 Storybook is a frontend workshop for building user interface components and pages in isolation. Prior to versions 7.6.23, 8.6.17, 9.1.19, and 10.2.10… Storybook 7.6.23 / 8.6.17+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-25997 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_clipboard_format_equal` reads freed `lastSentFormats` m… Freerdp 3.23.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-25959 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprdr_provide_data_` passes freed `pDstData` to `XCha… Freerdp 3.23.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-25955 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` wh… Freerdp 3.23.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-25953 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWi… Freerdp 3.23.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-25952 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow`… Freerdp 3.23.0+ Fix from $2,3002026-02-25 CRITICAL 9.2 CVE-2026-0542 ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an… Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.0 CVE-2026-22720 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be abl… Aria Operations 5.2.3 / 8.18.6+ Fix from $2,3002026-02-25 CRITICAL 9.2 CVE-2026-27739 The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-S… Patch available Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-21902EPSS 18% An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved… Junos Os Evolved Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27849 Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normall… Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27727 mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including suppo… Mchange Commons Java 0.4.0+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-20129 A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an … Catalyst Sd Wan Manager 20.9.8.2 / 20.12.5.3+ Fix from $2,3002026-02-25 CRITICAL 10.0 CVE-2026-20127 KEVEPSS 88% A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD… Catalyst Sd Wan Manager 20.9.8.2 / 20.12.5.3+ Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27848 Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as… Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27847 Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inj… Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.0 CVE-2026-27702 Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability i… Budibase 3.30.4+ Fix from $2,3002026-02-25 CRITICAL 9.6 CVE-2025-69771 Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execut… Asbplayer after 1.13.0 Fix from $2,3002026-02-25 CRITICAL 9.1 CVE-2025-1242 The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware revers… Mitigation only Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-3187 A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api… Sz Boot Parent after 0.9.0 Fix from $2,3002026-02-25 CRITICAL 9.8 CVE-2026-27699 The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` m… Basic Ftp 5.2.0+ Fix from $2,3002026-02-25