Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-69936 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69935 CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69934 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69933 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69930 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-65336 Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-67594 Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-67208 Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by … No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-66756 Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a… Tika No fix yet Fix from $2,3002026-07-30 CRITICAL 9.9 CVE-2026-12946 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input… Langflow 1.10.1+ Fix from $2,3002026-07-30 CRITICAL 9.5 CVE-2026-66066 Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not di… Patch available Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-51272 In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() character encoding conversion function. … No fix yet Fix from $2,3002026-07-30 CRITICAL 9.3 CVE-2026-48499 Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut… Patch available Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-15976 SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from… Sglang after 0.5.15 Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-15971 SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, ena… Sglang after 0.5.15 Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-15969 SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary comma… Sglang after 0.5.15 Fix from $2,3002026-07-30 CRITICAL 9.9 CVE-2026-13435 IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation. Langflow 1.10.2+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-12943 IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink)… Hardware Management Console 10.3.1064.1 / 11.1.1112.1+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-12118 IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d… Webmethods Integration No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-51291 sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.1 CVE-2026-51290 SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module. The program frees a BtLock structure wi… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.1 CVE-2026-13379 The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service cras… Openvpn 2.7.5+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-12940 IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model C… Langflow 1.10.2+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-52680 Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote … Kyuubi 1.12.0+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-4978 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL … No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-28812 UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende… Jspwiki 2.12.4+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-28323 SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to b… Web Help Desk 2026.2.1+ Fix from $2,3002026-07-30 CRITICAL 9.1 CVE-2026-53431 Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion… Patch available Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-15435 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy… App Connect Enterprise 12.0.12.28 / 13.0.8.0+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-14522 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due… App Connect Enterprise 12.0.12.28 / 13.0.8.0+ Fix from $2,3002026-07-30