Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-58231 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain function… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-10579 A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-19516 A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-13716 Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary path… Crafty Controller 4.10.8+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-19425 Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-44758 SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected fu… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-34265 SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corr… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.3 CVE-2026-48161 react18-use is a React 19 use hook shim. Between 2026-05-19 01:07:01 and 2026-05-19 15:20:43, the default branch contained malicious commits 7b79148d… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72911 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls i… Patch available Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2026-72904 Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in … Patch available Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2026-48160 react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-18948 A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'd… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-14450 A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP head… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72902 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands o… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72901 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbi… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72886 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72882 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for … No fix yet Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72880 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the apiCreateCertificate schema in packages/server/src/db/schema/cer… Patch available Fix from $2,3002026-08-10 CRITICAL 9.4 CVE-2026-72879 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in packages/server/src/utils/clust… Patch available Fix from $2,3002026-08-10 CRITICAL 9.6 CVE-2026-72878 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline constructs shell commands by d… Patch available Fix from $2,3002026-08-10 CRITICAL 9.6 CVE-2026-72877 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell com… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72876 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getA… Patch available Fix from $2,3002026-08-10 CRITICAL 9.2 CVE-2025-15681 TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauth… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2025-13294 An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacke… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2025-13293 A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level acces… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72872 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider stores bitbucketOwner and bitbucke… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72869 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databa… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72868 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the acce… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72867 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/serve… Patch available Fix from $2,3002026-08-10 CRITICAL 9.9 CVE-2026-72865 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that … Patch available Fix from $2,3002026-08-10