Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-67567 A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease cu… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-77148 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-66788 A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for r… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-66785 A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-19586EPSS 5% A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insuf… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.1 CVE-2026-73257 Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing … Patch available Fix from $5,7502026-08-20 CRITICAL 9.1 CVE-2026-73256 Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deploy… Patch available Fix from $5,7502026-08-20 CRITICAL 9.1 CVE-2026-73253 Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent d… Patch available Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-73251 Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configure… Patch available Fix from $5,7502026-08-20 CRITICAL 9.2 CVE-2026-63385 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_int… Patch available Fix from $5,7502026-08-20 CRITICAL 9.2 CVE-2026-63382 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Tra… Patch available Fix from $5,7502026-08-20 CRITICAL 9.1 CVE-2026-53424 Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.4 CVE-2026-2334 An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "I… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-77022 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?me… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-71428 The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, a… Patch available Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-55642 dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected … Patch available Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-18265 OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.1 CVE-2026-16926 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special el… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-15706 Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Appl… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.6 CVE-2026-28164 Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Eleme… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-74018 Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-74016 Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-74014 Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-74001 Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-73993 Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-73992 Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-68566 Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-66682 Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-66680 Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-66672 Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. No fix yet Fix from $5,7502026-08-20