Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-70552 MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access … No fix yet Fix from $2,3002026-08-04 CRITICAL 9.2 CVE-2026-70478 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.5 CVE-2026-70477 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using … Patch available Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-69703 Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated att… Mitigation only Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-49435 Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially cr… Mitigation only Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-0163 In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege w… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2017-20242 Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted pa… Mitigation only Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2017-20241 Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted pac… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.5 CVE-2026-70470 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in pa… Patch available Fix from $2,3002026-08-04 CRITICAL 9.4 CVE-2026-69264 Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that… Patch available Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-24254 NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successf… Dynamo after 1.1.0 Fix from $2,3002026-08-04 CRITICAL 9.4 CVE-2026-69259 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/c… Patch available Fix from $2,3002026-08-04 CRITICAL 9.4 CVE-2026-69256 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide P… Patch available Fix from $2,3002026-08-04 CRITICAL 9.2 CVE-2026-69255 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/ag… Patch available Fix from $2,3002026-08-04 CRITICAL 10.0 CVE-2026-64633 A vulnerability allowing remote unauthenticated code execution on the agent host. No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-63456 Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-63455 Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web… Mitigation only Fix from $2,3002026-08-04 CRITICAL 9.5 CVE-2026-58073 A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credenti… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.0 CVE-2026-58072 A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. Mitigation only Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2025-29296 H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.4 CVE-2026-69254 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-prov… Patch available Fix from $2,3002026-08-04 CRITICAL 9.0 CVE-2026-69253 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool compo… Patch available Fix from $2,3002026-08-04 CRITICAL 9.1 CVE-2026-69110 OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files wit… Patch available Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-69098 kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to … Mitigation only Fix from $2,3002026-08-04 CRITICAL 9.6 CVE-2026-25289 Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. Sm7550p Firmware No fix yet Fix from $2,3002026-08-04 CRITICAL 9.3 CVE-2026-18801 OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who ca… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.0 CVE-2026-69251 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory node… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-61515 Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execut… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-61514 Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access de… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.1 CVE-2026-10050 In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initi… Jetty 9.4.63 / 10.0.31+ Fix from $2,3002026-08-04