Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-65507 Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-54489 Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. … Virtual Storage Integrator 10.11.1.0+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-53976 OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unau… Patch available Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-53975 OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands b… Patch available Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-34191 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora… Apr Util after 1.6.3 Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an… Apr Util 1.6.4+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-28139 Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-28005 Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. No fix yet Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-64993 Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker c… Rvtools 4.8.1+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-5134 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. C… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.6 CVE-2026-12605 In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled … Glassfish 8.0.4+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-68079 In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-65583 Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-63687 Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-61466 In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-66909 Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-64597 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt … No fix yet Fix from $2,3002026-08-06 CRITICAL 10.0 CVE-2026-5430 The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t… Api Control Plane 4.1.0.257 / 4.2.0.197+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-1728 Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitati… Api Control Plane 4.0.0.384 / 4.1.0.248+ Fix from $2,3002026-08-06 CRITICAL 9.4 CVE-2025-15039 The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a… Api Control Plane 1.4.0.137 / 1.4.0.143+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-16054 The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid no… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-12713 The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowin… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-67873 A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encod… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-67870 In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remo… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-52466 Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming requ… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.3 CVE-2026-67531 FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host … Patch available Fix from $2,3002026-08-06 CRITICAL 9.6 CVE-2026-71319 Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channe… Patch available Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2025-63823 My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentic… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.9 CVE-2026-70615 boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission … No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-17556 A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and dire… Enterprise Server 3.17.19 / 3.18.13+ Fix from $2,3002026-08-05