Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-49457 erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshak… No fix yet Fix from $5,7502026-08-14 CRITICAL 10.0 CVE-2026-19188 A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net… No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-73849 Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately … No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-48528 Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauth… No fix yet Fix from $5,7502026-08-14 CRITICAL 9.9 CVE-2026-19682 A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary co… Security Center 6.9.0+ Fix from $5,7502026-08-14 CRITICAL 9.9 CVE-2026-19681 An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by… Security Center 6.9.0+ Fix from $5,7502026-08-14 CRITICAL 9.9 CVE-2026-19626 A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user … Security Center 6.9.0+ Fix from $5,7502026-08-14 CRITICAL 9.3 CVE-2026-19871 Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to a… Patch available Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-72830 Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write schedu… No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-72829 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. … No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-72826 The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in … No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-72824 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-tog… No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-72822 The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlik… No fix yet Fix from $5,7502026-08-14 CRITICAL 10.0 CVE-2026-72811 SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates s… No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-12949 The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and i… No fix yet Fix from $5,7502026-08-14 CRITICAL 9.6 CVE-2026-73843 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-f… Patch available Fix from $2,3002026-08-13 CRITICAL 9.0 CVE-2026-73842 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go ex… Patch available Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-73665 FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socke… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-73663 FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted … Patch available Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-73421 NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for … Patch available Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-73420 NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by th… Patch available Fix from $2,3002026-08-13 CRITICAL 9.0 CVE-2026-73302 Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved a… Patch available Fix from $2,3002026-08-13 CRITICAL 10.0 CVE-2026-72851 Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers c… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-72850 Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are p… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.9 CVE-2026-72842 luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management r… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.9 CVE-2026-72841 luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal a… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-72839 filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthen… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-72776 AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arb… Patch available Fix from $2,3002026-08-13 CRITICAL 9.6 CVE-2026-8715 Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication conf… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-19297 IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of exce… No fix yet Fix from $2,3002026-08-13