Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2026-58062 In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Cast… Patch available Fix from $2,3002026-08-03 CRITICAL 9.3 CVE-2026-8763 In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java… Patch available Fix from $2,3002026-08-03 CRITICAL 9.3 CVE-2026-59650 In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalidated peer value. This issue also affects Bouncy Castle for Java LTS b… Patch available Fix from $2,3002026-08-03 CRITICAL 9.3 CVE-2026-59638 In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bounc… Patch available Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-65321 PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper … Patch available Fix from $2,3002026-08-02 CRITICAL 9.6 CVE-2026-68579 FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows… Patch available Fix from $2,3002026-08-02 CRITICAL 9.8 CVE-2026-16256 The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated us… No fix yet Fix from $2,3002026-08-02 CRITICAL 9.8 CVE-2026-8457 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to … No fix yet Fix from $2,3002026-08-02 CRITICAL 9.8 CVE-2026-67342 ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoi… No fix yet Fix from $2,3002026-08-01 CRITICAL 9.8 CVE-2026-67341 ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with … No fix yet Fix from $2,3002026-08-01 CRITICAL 9.9 CVE-2026-67330 @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authoriza… No fix yet Fix from $2,3002026-08-01 CRITICAL 9.8 CVE-2026-67324 GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default … No fix yet Fix from $2,3002026-08-01 CRITICAL 9.3 CVE-2026-67308 Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submi… No fix yet Fix from $2,3002026-08-01 CRITICAL 9.4 CVE-2026-67305 FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONT… No fix yet Fix from $2,3002026-08-01 CRITICAL 9.8 CVE-2026-67289 FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetA… Patch available Fix from $2,3002026-08-01 CRITICAL 9.8 CVE-2026-66402 FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls… Patch available Fix from $2,3002026-08-01 CRITICAL 9.8 CVE-2026-15964 The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and … No fix yet Fix from $2,3002026-08-01 CRITICAL 9.1 CVE-2026-13596 The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL qu… Mitigation only Fix from $2,3002026-08-01 CRITICAL 9.1 CVE-2026-3141 The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/re… No fix yet Fix from $2,3002026-08-01 CRITICAL 9.8 CVE-2026-68771 ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to exec… Patch available Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-52134 An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured G… No fix yet Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-68770 sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logi… Patch available Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-51785 An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request No fix yet Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-38713 TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer… No fix yet Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-38708 TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer… Mitigation only Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2025-69948 SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. No fix yet Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2025-69946 SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_… No fix yet Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-38711 TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 wer… No fix yet Fix from $2,3002026-07-31 CRITICAL 9.6 CVE-2026-54725 vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in … Patch available Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-21662 Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affec… Fms Employee after 2025.3.1 Fix from $2,3002026-07-31