Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-62878 Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9121+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-62815 Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. Windows 11 23h2 10.0.20348.5440 / 10.0.22631.7517+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-59124 Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. Windows App 2.0.1314.0+ Fix from $2,3002026-08-11 CRITICAL 9.6 CVE-2026-57104 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to ele… Azure Storage Explorer 1.45.0+ Fix from $2,3002026-08-11 CRITICAL 9.4 CVE-2026-50516 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo… Azure Kubernetes Service No fix yet Fix from $2,3002026-08-11 CRITICAL 10.0 CVE-2026-48362 ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu… Coldfusion No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-12571 An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. No fix yet Fix from $2,3002026-08-11 CRITICAL 9.3 CVE-2026-73080 SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supp… Patch available Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-73069 Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MOD… Patch available Fix from $2,3002026-08-11 CRITICAL 9.3 CVE-2025-31114 Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use… Patch available Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-72920 SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory auth… Patch available Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-47702 TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the … Patch available Fix from $2,3002026-08-11 CRITICAL 10.0 CVE-2026-17061 A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthen… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-51584 An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/route… No fix yet Fix from $2,3002026-08-11 CRITICAL 10.0 CVE-2026-48056 Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable pat… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.3 CVE-2026-48046 Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-46670 YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::creat… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-72748 AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to wri… Patch available Fix from $2,3002026-08-11 CRITICAL 10.0 CVE-2026-58115 A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED ins… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.6 CVE-2026-18972 An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.9 CVE-2026-72603 An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by inje… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-72599 An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. Th… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-72550 An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statement… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.2 CVE-2026-13738 CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to res… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.2 CVE-2026-13737 CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance … No fix yet Fix from $2,3002026-08-11 CRITICAL 10.0 CVE-2026-58231 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain function… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-10579 A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-19516 A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-13716 Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary path… Crafty Controller 4.10.8+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-19425 Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb… No fix yet Fix from $2,3002026-08-11